Formerly known as Azure AI Services or Azure Cognitive Services is a unified collection of prebuilt AI capabilities within the Microsoft Foundry platform
The symptoms indicate a tenant/account sign‑in and MFA lockout scenario where the only effective resolution path is through Microsoft support and, if applicable, the Data Protection (DP) / Tenant Recovery process. The behavior isn’t something that can be fixed from the portal or CLI if there is no working admin account with valid MFA.
Use the following recovery paths depending on whether there is any other global admin:
- Check if any other global admin exists in the tenant
- If any other global administrator can still sign in to the tenant, that admin can reset the affected account’s MFA so it can be re‑registered:
- Sign in to the Microsoft Entra admin center.
- Go to Identity → Users → All users.
- Select the affected user (the original personal account or the new account that should own the tenant).
- Open Authentication methods.
- Select Require re‑register multifactor authentication.
- Sign out and sign in again as the affected user; the account will be prompted to set up MFA from scratch.
- This is the standard remediation when at least one other global admin can access the tenant.
- If any other global administrator can still sign in to the tenant, that admin can reset the affected account’s MFA so it can be re‑registered:
- If there is no other global admin or all admin accounts are blocked by MFA
- This is treated as a tenant lockout. In this case, only Microsoft support (Data Protection / Tenant Recovery) can restore access:
- Contact Microsoft support by phone using the regional customer service number (Customer service phone numbers – Microsoft Support) and clearly state that:
- The tenant’s global admin account(s) are locked out due to MFA.
- No other global admin exists with working access.
- The tenant is a pay‑as‑you‑go Azure/Microsoft 365 tenant and business impact is high.
- Ask the frontline agent to open a service request and escalate to the Data Protection or Tenant Recovery team for admin lockout/MFA reset.
- Be prepared to provide verification information (tenant domain, admin UPNs, billing/identity details) so the DP team can validate ownership.
- Contact Microsoft support by phone using the regional customer service number (Customer service phone numbers – Microsoft Support) and clearly state that:
- If direct support creation from the locked tenant is impossible, an alternative is to:
- Create a new, temporary Microsoft 365 or Azure trial tenant.
- In that new tenant, go to the admin center → Support → Help & support.
- Open a support ticket explicitly stating that the issue is with a different, existing tenant where the global admin is locked out by MFA.
- Provide the locked tenant’s domain, admin account details, and error messages.
- Work with the assigned engineer and DP team until MFA is reset and access to the original tenant is restored.
- After resolution, cancel the trial subscription for the temporary tenant to avoid charges.
- This is treated as a tenant lockout. In this case, only Microsoft support (Data Protection / Tenant Recovery) can restore access:
- When support/DP team engages
- For a tenant lockout like this, the DP team typically:
- Verifies identity and ownership of the tenant.
- Either resets MFA for an existing admin account or helps establish a new global admin account with working credentials and MFA.
- Once a working global admin exists again, that admin can:
- Fix user assignments (ensure the correct personal account is global admin).
- Clean up any unintended accounts or roles created during the Foundry onboarding.
- Confirm that the correct tenant is selected as the default directory for the personal account.
- For a tenant lockout like this, the DP team typically:
- About the 6‑digit vs 8‑digit code issue
- The mismatch between 6‑digit codes expected by the sign‑in page and 8‑digit codes shown in the Authenticator app indicates that the MFA profile for the account is misconfigured or stuck.
- This is another reason a global admin (or the DP team, if no admin can sign in) must reset MFA for the affected account so it can be re‑registered cleanly.
Given that the tenant’s global admin appears to have changed and the personal account is being mapped to the wrong tenant with “user does not exist in tenant” errors, this is effectively a tenant lockout. The practical next step is to open a support case and have it escalated to the Data Protection/Tenant Recovery team so they can:
- Restore a valid global admin account for the correct tenant.
- Reset MFA for that admin and for the personal account.
- Help correct any directory/account mapping issues introduced during the Foundry setup.
References:
- Upgrade from Azure OpenAI to Microsoft Foundry
- How to configure Azure OpenAI in Microsoft Foundry Models with Microsoft Entra ID authentication (classic)
- Reset Personal Azure MFA - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A