Tag not monitored by Microsoft.
Because the account is protected by MFA and there is no other global administrator in the B2C tenant who can reset MFA, this is a tenant lockout scenario that must be handled by Microsoft support/Data Protection.
From the described situation:
- Only one global admin exists in the B2C tenant.
- Microsoft Authenticator is in “Action required” and cannot be completed because the QR code cannot be scanned.
- Other MFA methods (notification/SMS/code) are not working.
In this case, self-service recovery is not possible. The required path is:
- Contact Microsoft support and have a ticket raised specifically for MFA/tenant lockout.
- If the tenant has no other admins, the Microsoft Data Protection team must verify identity and reset MFA for the locked-out global admin so access can be restored.
- Use the customer service phone numbers listed in Microsoft Support to reach the frontline and clearly state that this is an admin MFA lockout for a business/organization tenant with only one global admin.
- If direct support access from the locked tenant is not possible (because sign-in fails), use one of these approaches to open a support ticket:
- If the subscription/tenant was obtained through a partner or reseller, contact the partner and ask them to open a service request with Microsoft on behalf of the organization.
- Alternatively, create a temporary new Microsoft 365/Azure trial tenant, sign in to its admin center, and from there open a support ticket. In the ticket, clearly state:
- This is about a different, existing tenant (provide tenant domain and admin UPN).
- The admin is locked out due to MFA and is the only global admin.
- MFA methods (Authenticator and SMS) are not working.
- Work with the Microsoft support/Data Protection team:
- They will perform identity and ownership verification for the locked tenant.
- After verification, they can reset MFA for the global admin or otherwise restore access.
- After access is restored, add at least one additional global admin and configure multiple MFA methods (for example, Authenticator plus phone) to avoid future lockouts.
There is no supported way to bypass or reset MFA for a sole global admin without going through Microsoft support/Data Protection.
References:
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A