Global Administration Tenant Lockout

Severin Giger 0 Reputation points
2026-05-30T10:22:41.1633333+00:00

I am the only Global Administrator of my Microsoft 365 tenant.

Since recently, I have been unable to access any Microsoft 365 administrative services, including the Microsoft 365 Admin Center, Entra Admin Center, Azure Portal, and Microsoft Bookings.

During sign-in, Microsoft repeatedly prompts me to set up or protect my account with the Microsoft Authenticator app. Instead of receiving a normal MFA challenge, I am always presented with the message that my account needs to be protected and that I need to set up additional security measures.

After clicking “Next”, the process hangs on a white screen for an extended period and eventually fails with the error:

“Sign-in isn’t possible. Try again.”

This happens consistently across different browsers, including Edge and Chrome, and also in private/incognito mode.

I suspect that my account may be affected by an MFA lockout or a broken MFA registration state. The Microsoft Authenticator app is already installed on my mobile device, and I previously used MFA successfully. However, I never receive an MFA approval request, push notification, or verification challenge. Instead, Microsoft continuously redirects me to the “Let’s protect your account” registration flow, which ultimately fails and prevents me from signing in.

As I am the only Global Administrator, I currently have no way to reset my MFA settings, authentication methods, security information, Conditional Access policies, or authentication method policies from within the tenant.

Additionally, I am unable to create a support request through the Microsoft 365 Admin Center because I cannot sign in. I have also been unable to reach a Microsoft support representative by phone, and I do not have a support plan or eligible license that allows me to open a support case through the standard support channels.

At this point, I am completely locked out of the tenant administration despite being the sole Global Administrator.

Could Microsoft please investigate whether my account is stuck in an MFA registration loop or MFA lockout state and assist with restoring access or resetting the MFA/security registration associated with my account?

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-05-30T10:23:11.3333333+00:00

    The described symptoms match a tenant admin lockout caused by MFA/registration issues where the only Global Administrator cannot complete sign-in.

    Because there is no other Global Administrator available to reset MFA or adjust Conditional Access, recovery must be done by Microsoft’s Data Protection / Tenant Recovery teams. Forum moderators and community responders cannot directly modify accounts or tenants.

    Use the following recovery paths:

    1. Attempt any alternative verification methods
    • If any other security verification options were configured (for example, SMS, voice call, or another method), select Other verification options on the sign-in page and try those first.
    • If another admin account exists (even with limited access), that admin can:
      • Sign in to the Azure portal → Microsoft Entra IDUsers → select the affected account → Authentication methods → choose Require re-register multifactor authentication. This forces a fresh MFA registration on next sign-in.

    Given the description, this is likely not possible because there is only one Global Administrator and that account is locked in the registration loop.

    1. Engage Microsoft Data Protection / Tenant Recovery (only Global Admin, no portal access) When the only Global Administrator is locked out and cannot access the admin portals, Microsoft’s Data Protection team must verify identity and reset the authentication methods or restore access.

    Use these steps:

    1. Call Microsoft’s business support phone line for the region using the numbers listed under Customer service phone numbers - Microsoft Support or Support for Business Products.
    2. When interacting with the IVR/agent, clearly state:
      • The issue is with Microsoft Authenticator / MFA.
      • The product is Office 365 / Microsoft 365 for business.
      • The account is a company/organization account (not personal).
      • The caller is the only Global Administrator for the tenant.
      • There is no other admin who can open a ticket.
    3. Ask to create a service request and be routed to the Microsoft 365 Data Protection team (or equivalent Data Protection / Tenant Recovery team) to:
      • Verify ownership of the tenant.
      • Reset MFA / authentication methods or clear the broken registration state.

    The Data Protection team has specific tools and processes to validate identity and restore access when the sole Global Administrator is locked out due to MFA or registration issues.

    1. Alternative path: create a temporary trial tenant to open a ticket If direct phone support cannot be reached or cannot create a ticket:
    2. Sign up for a new Microsoft 365 trial tenant (separate from the locked tenant).
    3. In the new tenant, go to the Microsoft 365 admin center → SupportHelp & support.
    4. Open a support ticket explaining:
      • This new tenant is only for contacting support.
      • The real problem is a lockout on a different, existing Microsoft 365 tenant.
      • Provide the locked tenant’s domain and admin UPN, describe the MFA registration loop, and confirm being the only Global Administrator.
    5. Request escalation to the Data Protection team to perform tenant admin recovery on the original tenant.

    This temporary tenant does not give access to the locked tenant’s data; it is only a channel to reach support when the original tenant’s admin portal is inaccessible.

    1. Future prevention once access is restored After Microsoft restores access:
    2. Create at least two emergency access (break-glass) accounts:
      • Global Administrator accounts with long, complex passwords.
      • Excluded from MFA and Conditional Access policies, as recommended in Admin account security in Microsoft 365 for business and Preventing tenant lockouts.
    3. Ensure at least two Global Admin accounts with distinct credentials and MFA methods exist.
    4. Configure Self-Service Password Reset (SSPR) and keep recovery methods up to date.
    5. Design Conditional Access policies so that break-glass accounts are excluded and policies are tested before broad enforcement.

    These measures reduce the risk of future tenant lockouts due to MFA or Conditional Access misconfiguration.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.