Global admin locked out MFA no access to authenticator

Liene 0 Reputation points
2026-05-22T10:59:28.9933333+00:00

I am the only Global Admin of a Microsoft 365 tenant. After a device reinstall, Microsoft Authenticator stopped working. I can still sign in with: - PII But the actual Global Admin account: - PII requires MFA code from Authenticator. I no longer have access to the MFA codes. There are no other Global Admins in the tenant. I need Microsoft to reset MFA for the Global Admin account. Domain: PII

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-22T10:59:52.7166667+00:00

    Because the only Global Administrator is locked out and there are no other admins who can reset MFA, this is a tenant lockout scenario that must be handled by Microsoft Support/Data Protection.

    Follow these steps to regain access:

    1. Contact Microsoft Support by phone
      • Call the appropriate number listed under Customer service phone numbers - Microsoft Support.
      • When prompted by the IVR, clearly indicate:
        • The product is Office 365/Microsoft 365 for business.
        • The issue is with Microsoft Authenticator / MFA.
        • The account is a company/organization account.
        • Confirm being an administrator and that there is no other global admin in the tenant.
        • Request to create a service request and be routed to the Data Protection / Tenant Recovery team to reset MFA for the global admin account.
    2. Be prepared to verify tenant ownership
      • Support will require proof that control of the tenant and domain (luckypunch.lv) is held. Have business documentation and account details ready as requested by the support engineer.
    3. Work with the Data Protection team
      • After the ticket is created and escalated, the Data Protection team will contact via phone or email.
      • They will perform verification and, once satisfied, reset or clear the MFA registration for the global admin account so that a new MFA method (such as Microsoft Authenticator) can be configured at next sign-in.

    If initial contact attempts do not reach the correct team, explicitly ask the agent to open a ticket for tenant admin MFA reset / tenant lockout and escalate to the Data Protection team.

    Forum moderators and tools cannot perform this reset; only Microsoft Support/Data Protection can assist in this scenario.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.