Foundry AI altered my tenant account and I can no longer sign in with my personal account

Kelson Olson 5 Reputation points
2026-05-21T16:59:44.66+00:00

I was going to use Microsoft Foundry to create a model, but decided not to part way through the process because I didn't want to worry about billing (or more like cleanup of the unknown amount of resources). After this, much to my shock, my personal account could no longer access my Azure tenant because the MFA that shows (even though I have MFA disabled for my account) only accepts 6 digits and whenever I setup Authenticator it only shows 8 digits. I originally setup my Azure and my tenant as a pay-as-you-go subscription that has never accrued any billing. I ended up using Azure CLI to run some queries and found that there were automated changes made to my Azure tenant by Foundry and the global administer user is no longer my account (but is a similar one, with my first and last name, that seems to have been pieced together from old data). When I try to login to Azure with my personal account sometimes it lets me through, however the tenant that loads is NOT mine and there are many popup errors (interaction required - user does not exist in tenant) that prevent me from doing anything. I am unable to switch the view back to my 'Default Directory' tenant when I am able to reach Azure with my personal account. I can try to login with the account automatically created but it also often runs into an auth code requesting 6 digits (which I can't give). Sometimes the automatic account is let through and it loads my tenant, although the 'signed in' user in the top right isn't my personal account.

Yesterday I used Azure CLI for my tenant to delete any resource groups that existed and I do not believe there are any billing issues at this time. I would like to be able to still use Azure under my account.

Foundry Tools
Foundry Tools

Formerly known as Azure AI Services or Azure Cognitive Services is a unified collection of prebuilt AI capabilities within the Microsoft Foundry platform


1 answer

Sort by: Newest
  1. AI answer

    2026-05-21T17:00:09+00:00

    The symptoms indicate a tenant/account sign‑in and MFA lockout scenario where the only effective resolution path is through Microsoft support and, if applicable, the Data Protection (DP) / Tenant Recovery process. The behavior isn’t something that can be fixed from the portal or CLI if there is no working admin account with valid MFA.

    Use the following recovery paths depending on whether there is any other global admin:

    1. Check if any other global admin exists in the tenant
      • If any other global administrator can still sign in to the tenant, that admin can reset the affected account’s MFA so it can be re‑registered:
        1. Sign in to the Microsoft Entra admin center.
        2. Go to Identity → Users → All users.
        3. Select the affected user (the original personal account or the new account that should own the tenant).
        4. Open Authentication methods.
        5. Select Require re‑register multifactor authentication.
        6. Sign out and sign in again as the affected user; the account will be prompted to set up MFA from scratch.
      • This is the standard remediation when at least one other global admin can access the tenant.
    2. If there is no other global admin or all admin accounts are blocked by MFA
      • This is treated as a tenant lockout. In this case, only Microsoft support (Data Protection / Tenant Recovery) can restore access:
        • Contact Microsoft support by phone using the regional customer service number (Customer service phone numbers – Microsoft Support) and clearly state that:
          • The tenant’s global admin account(s) are locked out due to MFA.
          • No other global admin exists with working access.
          • The tenant is a pay‑as‑you‑go Azure/Microsoft 365 tenant and business impact is high.
        • Ask the frontline agent to open a service request and escalate to the Data Protection or Tenant Recovery team for admin lockout/MFA reset.
        • Be prepared to provide verification information (tenant domain, admin UPNs, billing/identity details) so the DP team can validate ownership.
      • If direct support creation from the locked tenant is impossible, an alternative is to:
        1. Create a new, temporary Microsoft 365 or Azure trial tenant.
        2. In that new tenant, go to the admin center → Support → Help & support.
        3. Open a support ticket explicitly stating that the issue is with a different, existing tenant where the global admin is locked out by MFA.
        4. Provide the locked tenant’s domain, admin account details, and error messages.
        5. Work with the assigned engineer and DP team until MFA is reset and access to the original tenant is restored.
        6. After resolution, cancel the trial subscription for the temporary tenant to avoid charges.
    3. When support/DP team engages
      • For a tenant lockout like this, the DP team typically:
        • Verifies identity and ownership of the tenant.
        • Either resets MFA for an existing admin account or helps establish a new global admin account with working credentials and MFA.
        • Once a working global admin exists again, that admin can:
          • Fix user assignments (ensure the correct personal account is global admin).
          • Clean up any unintended accounts or roles created during the Foundry onboarding.
          • Confirm that the correct tenant is selected as the default directory for the personal account.
    4. About the 6‑digit vs 8‑digit code issue
      • The mismatch between 6‑digit codes expected by the sign‑in page and 8‑digit codes shown in the Authenticator app indicates that the MFA profile for the account is misconfigured or stuck.
      • This is another reason a global admin (or the DP team, if no admin can sign in) must reset MFA for the affected account so it can be re‑registered cleanly.

    Given that the tenant’s global admin appears to have changed and the personal account is being mapped to the wrong tenant with “user does not exist in tenant” errors, this is effectively a tenant lockout. The practical next step is to open a support case and have it escalated to the Data Protection/Tenant Recovery team so they can:

    • Restore a valid global admin account for the correct tenant.
    • Reset MFA for that admin and for the personal account.
    • Help correct any directory/account mapping issues introduced during the Foundry setup.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.