Locked out of Azure AD Tenant

andrew tugman 0 Reputation points
2026-06-02T19:18:07.7633333+00:00

Similar to other posts, such as this one, I'm locked out of my Azure tenant. I purchased a new iPhone, and no longer have access to the old one, which was used for MFA. I'm the global admin.

It seems I need to contact the Data protection team but have been unsuccessful in doing so. I am hoping someone can route my request to them/have them reach out to me. Will share my contact info when appropriate.

Thank you.

Community Center | Not monitored

1 answer

Sort by: Oldest
  1. AI answer

    2026-06-02T19:18:20.92+00:00

    Because the only registered MFA method was on the lost phone and there are no other global admins who can reset MFA, recovery must go through Microsoft’s Data Protection team.

    Use one of these supported paths:

    1. If there is any other global admin
      • Another global admin can sign in to the Azure portal, go to Microsoft Entra ID → Users → [your account] → Authentication methods, and select Require re-register multifactor authentication.
      • On next sign-in, MFA registration is prompted again so a new phone can be enrolled.
    2. If you are the only global admin on the tenant
      • Contact Microsoft’s Data Protection team via the regional support numbers. For Azure/Entra tenants, use the global support phone numbers listed in support documentation and ask to be routed to the Azure Data Protection (or Microsoft 365 Data Protection, depending on workload) team for tenant/admin account recovery.
      • Clearly state:
        • You are the only global administrator.
        • You are locked out due to loss of the MFA device and have no other verification methods.
        • You need MFA/security info reset or admin credential reset for your existing tenant.
      • The Data Protection team has dedicated processes to verify identity and reset credentials or MFA for locked-out global admins.
    3. If you cannot open a ticket from the locked tenant
      • If direct phone routing is difficult, one documented workaround is to create a separate, temporary tenant (for example, via a Microsoft 365 or Azure trial) and then use that tenant’s admin center to open a support request.
      • In the ticket, specify that the issue concerns a different existing tenant where you are the global admin but are locked out due to MFA.
      • Be prepared to provide:
        • The locked tenant’s domain (for example, contoso.onmicrosoft.com or custom domain).
        • The global admin UPN on that tenant.
        • Error messages seen at sign-in.

    Until Data Protection completes verification and resets MFA/credentials, access to the tenant cannot be restored by forums or moderators; they can only direct to these official channels.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.