Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
In this scenario, recovery options depend on whether there is another Global Administrator in the tenant.
- If another Global Administrator exists
Another Global Admin can reset the affected admin’s MFA so it can be re-registered:
- The other Global Admin signs in to the Microsoft Entra admin center (Azure portal).
- Go to Users → All users.
- Select the locked-out admin account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
At the next sign-in, the locked-out admin will be prompted to set up MFA again (for example, reconfigure Microsoft Authenticator) instead of being asked for the old, unavailable Authenticator approval.
This is the standard, supported way to clear and re-register MFA for a user when an admin is available.
- If there is no other Global Administrator
If the locked-out account is the only Global Administrator, self-service recovery is not available. Forum moderators and normal support channels cannot directly change MFA for tenant admins; this must go through Microsoft’s Data Protection / Tenant Recovery process.
The recommended process is:
Option A – Call Microsoft Support and request Data Protection team involvement
- Call Microsoft global customer service using the appropriate regional number from Customer service phone numbers - Microsoft Support.
- When navigating the IVR, clearly indicate:
- The issue is with Microsoft Authenticator / MFA.
- The product is Office 365 / Microsoft 365 for business.
- It is a company (not education, not personal) account.
- The caller is the only Global Administrator and is locked out due to MFA.
- A service request is needed and must be escalated to the Data Protection team to reset the admin’s MFA registration.
- The Data Protection team will follow identity-verification procedures (for example, tenant ownership checks) and, once satisfied, can reset MFA registration for the admin so that new methods (including a fresh Authenticator registration) can be configured.
Option B – Create a temporary trial tenant to open a support ticket
If reaching a live agent by phone is difficult, a workaround is to:
- Sign up for a new Microsoft 365 trial tenant (separate from the locked tenant).
- In the new tenant, go to the Microsoft 365 admin center → Support → Help & support.
- Open a support ticket explaining that:
- The issue is with a different, existing tenant.
- The admin for that tenant is locked out due to Microsoft Authenticator MFA.
- There are no other Global Admins.
- Ask for the case to be escalated to the Data Protection team for the original tenant so they can verify identity and reset MFA for the locked-out admin.
This trial tenant does not give access to the original tenant’s data; it is only a channel to reach Microsoft support.
- Self-service recovery options
For a business / work account where Microsoft Authenticator is the only registered MFA method and the device/app is lost or wiped, there is no self-service way for the admin to remove or reset MFA. Recovery requires either:
- Another Global Admin to reset MFA as described above, or
- Microsoft Support (Data Protection team) to verify identity and reset MFA for the sole Global Admin.
- Summary of answers to specific questions
- Can Microsoft remove or reset the MFA registration?
Yes. The Microsoft Data Protection / Tenant Recovery team can reset MFA registration for a Global Admin after verifying identity and tenant ownership, typically initiated via a support call or ticket. - Is there any self-service recovery method?
No self-service recovery exists when Microsoft Authenticator is the only MFA method and it is no longer accessible. Admin intervention (another Global Admin) or Microsoft Support is required. - If there are no other Global Administrators, what is the recommended recovery process?
Contact Microsoft Support via the global customer service phone numbers, clearly state that this is a tenant admin lockout with no other Global Admins, and request escalation to the Data Protection team. If direct phone escalation fails, create a new trial tenant and use its admin center to open a support ticket requesting Data Protection assistance for the original tenant.
References:
- Recover user authentication methods using Microsoft Entra Backup and Recovery (Preview)
- Account recovery overview
- Common problems with two-step verification for a work or school account
- Global Admin Locked out - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Restore account credentials from Microsoft Authenticator
- How to go passwordless with your Microsoft account
- Use a screen reader to set up and troubleshoot multifactor authentication