Tag not monitored by Microsoft.
Because the account is a Microsoft 365 admin account with MFA enforced and there are no other global admins, self-service options are effectively exhausted. Recovery must go through Microsoft support and Data Protection / Tenant Recovery so identity and tenant ownership can be verified and MFA reset.
Action plan:
- Confirm there is truly no other global admin
- If any other account in the tenant has Global Administrator rights, that admin can reset MFA for the locked-out admin:
- Sign in to the Azure portal → Microsoft Entra ID → Users → select the locked-out admin → Authentication methods → Require re-register multifactor authentication.
- Next sign-in for that admin will prompt fresh MFA registration on a new device.
- If no such admin exists, proceed to step 2.
- If any other account in the tenant has Global Administrator rights, that admin can reset MFA for the locked-out admin:
- Contact Microsoft Support by phone and request Data Protection / Tenant Recovery
- Use the Microsoft global customer service phone numbers listed under Customer service phone numbers - Microsoft Support.
- When connected to the IVR/agent, clearly state:
- This is an Office 365 for business / Microsoft 365 business tenant.
- The caller is the only Global Administrator.
- The phone with Microsoft Authenticator was lost and MFA is now blocking all access.
- A Data Protection / Tenant Recovery or Data Protection team escalation is needed to reset MFA for the global admin.
- If the first-line agent routes incorrectly (e.g., to a consumer or non-admin queue), insist that this is a business tenant and that the only global admin is locked out and cannot open a ticket from the portal.
- Prepare to pass identity and tenant ownership verification
The Data Protection team may require:
- Official business documentation (registration, tax or incorporation documents).
- Proof of domain ownership for the tenant’s primary domain.
- Publicly listed organization information matching the tenant.
- Admin contact details (phone, email, country/region, time zone) that match existing records where possible. After verification, the Data Protection engineer can:
- Reset or clear MFA for the global admin account.
- Allow re-registration of MFA and possibly add an additional authentication method.
- If phone support is hard to reach, use a temporary tenant as a workaround
- Create a new Microsoft 365 trial tenant.
- From that new tenant’s admin center, open a support ticket explaining:
- The ticket is on behalf of a different tenant where the only global admin is locked out by MFA.
- A Data Protection / Tenant Recovery escalation is required for the original tenant.
- Support can then engage the Data Protection team for the locked-out tenant.
- For future prevention once access is restored
- Add at least one additional Global Administrator.
- Configure multiple MFA methods for each admin (Authenticator on more than one device where allowed, phone, email, security key, etc.).
- Document a break-glass account strategy and ensure those accounts are excluded from conditional access policies that could cause lockout.
There is no supported way to bypass MFA or recover the admin account without going through Microsoft’s identity verification and Data Protection process when the only global admin has lost all MFA methods.
References:
- Tenant access recovery
- Common problems with two-step verification for a work or school account
- Troubleshoot Microsoft verification code issues
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Restore account credentials from Microsoft Authenticator
- Unable to restore Authenticator account credentials
- I can't sign in to my Microsoft account