Unable to login to Azure AD B2C tenant due to MFA and mobile device change

Caio Daruiz Correa 0 Reputation points
2026-06-03T04:20:48.89+00:00

I'm unable to sign-in to the Azure AD B2C tenant due to the MFA requirement and change in mobile phone. The admin account in Microsoft Authenticator is flagged with Action Required where a QR code needs to be scanned to recover the account in Microsoft Authenticator but there's nowhere where one can scan this.

I can see the B2C tenant details from the Azure subscription and I am the owner of the resource/resource group.

I am the only global administrator of the B2C tenant and the MFA options for either notification or code are not working.

Please assist.

Community Center | Not monitored

1 answer

Sort by: Newest
  1. AI answer

    2026-06-03T04:21:01.9133333+00:00

    Because the account is protected by MFA and there is no other global administrator in the B2C tenant who can reset MFA, this is a tenant lockout scenario that must be handled by Microsoft support/Data Protection.

    From the described situation:

    • Only one global admin exists in the B2C tenant.
    • Microsoft Authenticator is in “Action required” and cannot be completed because the QR code cannot be scanned.
    • Other MFA methods (notification/SMS/code) are not working.

    In this case, self-service recovery is not possible. The required path is:

    1. Contact Microsoft support and have a ticket raised specifically for MFA/tenant lockout.
      • If the tenant has no other admins, the Microsoft Data Protection team must verify identity and reset MFA for the locked-out global admin so access can be restored.
      • Use the customer service phone numbers listed in Microsoft Support to reach the frontline and clearly state that this is an admin MFA lockout for a business/organization tenant with only one global admin.
    2. If direct support access from the locked tenant is not possible (because sign-in fails), use one of these approaches to open a support ticket:
      • If the subscription/tenant was obtained through a partner or reseller, contact the partner and ask them to open a service request with Microsoft on behalf of the organization.
      • Alternatively, create a temporary new Microsoft 365/Azure trial tenant, sign in to its admin center, and from there open a support ticket. In the ticket, clearly state:
        • This is about a different, existing tenant (provide tenant domain and admin UPN).
        • The admin is locked out due to MFA and is the only global admin.
        • MFA methods (Authenticator and SMS) are not working.
    3. Work with the Microsoft support/Data Protection team:
      • They will perform identity and ownership verification for the locked tenant.
      • After verification, they can reset MFA for the global admin or otherwise restore access.
    4. After access is restored, add at least one additional global admin and configure multiple MFA methods (for example, Authenticator plus phone) to avoid future lockouts.

    There is no supported way to bypass or reset MFA for a sole global admin without going through Microsoft support/Data Protection.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.