Additional Microsoft Entra services and features related to identity, access, and network security
To regain access when being the only global administrator and locked out due to MFA, follow these supported recovery paths.
- Confirm no other admin or partner can help
- If there is any chance another global admin exists, that admin can reset MFA by signing in to the Azure portal → Microsoft Entra ID → Users → select the locked-out account → Authentication methods → Require re-register multifactor authentication. This forces MFA re-registration on next sign-in.
- If a Cloud Solution Provider (CSP) or partner manages the tenant and has granular delegated admin privileges (GDAP) with password/MFA reset roles, they should restore access directly for the tenant admin without involving Microsoft.
- Use Self-Service Password Reset (SSPR) if enabled
- If self-service password reset is enabled and security info is still accessible, go to the Self-Service Password Reset tool at https://passwordreset.microsoftonline.com/ and follow the wizard.
- If security info is lost but some methods still work, sign in to the Advanced security options page, add a new sign-in/verification method, verify it, then remove the old method.
- If all security info and MFA methods are lost When the password is known but MFA cannot be completed and there are no other admins:
- Begin sign-in to the work or school account.
- At the “Verify your identity” prompt, select I don't have any of these (if available) and follow the instructions to replace security info.
- If prompted that all security info is being replaced, note that access may be restricted for up to 30 days once replacement is submitted.
If password is also not usable and no security info is available:
- Use the Microsoft account recovery form as documented in Help with the Microsoft account recovery form, then submit via the recovery link.
- Escalate to Microsoft Data Protection / Tenant Recovery If there is truly only one global admin and no working MFA/security methods, Microsoft’s Data Protection team must verify identity and restore access:
- Call Microsoft customer service using the regional phone numbers listed under Customer service phone numbers - Microsoft Support or Support for Business Products.
- In the IVR/agent conversation, clearly state:
- The issue is with Authenticator / MFA for a Microsoft 365 for business / company account.
- The caller is the only global administrator on the tenant.
- There is no other admin who can reset MFA.
- A service request is needed and must be routed to the Data Protection team (or Microsoft 365 / Azure Data Protection team) for tenant admin MFA reset.
- Be prepared to provide business documentation, domain ownership proof, and tenant details so Data Protection can verify ownership and perform the MFA reset or security info replacement.
- Alternative path if unable to reach support from the locked tenant If direct phone support cannot be reached or agents cannot create a ticket:
- Optionally create a new trial Microsoft 365 tenant (separate from the locked one) using a trial subscription.
- Sign in to the new tenant’s Microsoft 365 admin center (https://admin.microsoft.com).
- Go to Support → Help & support and open a ticket explaining:
- The issue is with a different existing tenant where the caller is the only global admin.
- MFA/Auth methods are lost and access to the original tenant is blocked.
- Request escalation to the Data Protection team for tenant admin MFA reset.
- This trial tenant is only a channel to contact support; it does not give access to data in the locked tenant. Cancel the trial after resolution.
- If tenant access is lost more broadly If tenant access is lost due to admin departure, unknown credentials, or invalid contact email, recovery must still go through Microsoft 365 support:
- Go to the Microsoft 365 support page and choose I can't sign in or access my tenant.
- Provide required identity and ownership documentation (business registration, domain ownership, nonprofit registration, etc.) as requested.
These processes are required because Microsoft for Nonprofits and forum moderators cannot bypass identity verification or directly change tenant ownership or admin access.
References:
- Troubleshoot sign-in issues and account access problems
- I can't sign in to my Microsoft account
- Tenant access recovery
- Common problems with two-step verification for a work or school account
- Preventing tenant lockouts
- All about passwords
- Forgot password to sign in to Microsoft 365, Intune, or Azure
- Global Admin Locked out - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A