I am locked out of my private Azure tenant

Ryan Menezes 0 Reputation points Microsoft Employee
2026-06-03T21:07:13.05+00:00

Unable to add a new local user in the tenant as Global Admin because conflicting CAS policies cause an a signin loop. MFA required and security info registrations policies conflict.
Unable to modify the CAS policies as it requires P1/P2 plan.

unable to upgrade to P1/P2 plan as it requires global admin

the account associated with global admin needs to be recovered but it says password reset was not enabled

so essentially the tenant is unusable at this point.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-06-03T21:07:35.1066667+00:00

    The tenant is in a lockout state that cannot be resolved from within the tenant because:

    • All effective Global Admin access is blocked by Conditional Access/MFA configuration.
    • Self-service password reset (SSPR) is not enabled for the Global Admin account.
    • Upgrading to P1/P2 (needed to adjust Conditional Access) also requires Global Admin.

    In this situation, recovery must be handled by Microsoft support/Data Protection; it cannot be fixed solely by configuration changes from inside the tenant.

    Use these steps, based on the documented lockout and recovery guidance:

    1. Try any remaining Global Admin or break-glass accounts
      • If there is any other Global Administrator account or an emergency/break-glass account that is not impacted by the conflicting Conditional Access policies, sign in with that account and:
        • Disable or adjust the Conditional Access policy that is causing the sign-in loop, as described in the Conditional Access troubleshooting guidance: an admin with access can disable the blocking policy so sign-in works again.
      • If such an account exists and can sign in, this is the fastest path to restore access.
    2. If no admin can sign in (full lockout)
      • When no Global Administrator can update Conditional Access policies, the documented path is to contact Microsoft support so they can review and update the policies that prevent access.
      • For tenant lockouts where all Global Admins lose access and there is no partner with the right GDAP roles, the guidance is:
        • The end-customer Global Administrator must contact Microsoft for support.
        • Use the Microsoft 365 for business support phone numbers by country/region to reach support and request escalation to the Data Protection / Tenant Recovery team.
      • For scenarios where the only Global Admin is locked out due to MFA/Conditional Access and SSPR is not usable, Microsoft’s Data Protection team has tools and processes to verify identity and help restore access to the administrator account or adjust the blocking policies.
    3. Use Self-Service Password Reset only if available
      • If SSPR had been enabled and the Global Admin had valid security information, the recommended first step would be to recover access via the Self Service Password Reset tool (https://passwordreset.microsoftonline.com/).
      • In this case, SSPR is not enabled for the Global Admin, so this path is not available and support escalation is required.
    4. If a partner with GDAP exists
      • If there is a partner with an active GDAP relationship and appropriate roles (Global Administrator or Privileged Role Administrator), that partner can:
        • Promote another user to Global Administrator, or
        • Adjust Conditional Access or authentication settings to restore access, without engaging Microsoft.
      • If the partner does not have the required GDAP roles, the guidance is still to use SSPR (if possible) and then have the Global Admin contact Microsoft support.
    5. Future prevention once access is restored After Microsoft support/Data Protection restores access or fixes the blocking policies, follow the tenant lockout prevention checklist:
      • Ensure at least two Global Admin accounts with different credentials and MFA methods.
      • Create break-glass emergency accounts excluded from Conditional Access policies.
      • Configure and test Self-Service Password Reset (SSPR) for admins.
      • Carefully design Conditional Access policies, always excluding break-glass accounts and testing before broad deployment.

    In summary, with no usable Global Admin access, no SSPR, and blocking Conditional Access policies, the only supported path is to contact Microsoft support (Data Protection / Tenant Recovery) using the regional Microsoft 365 for business support phone numbers and have them assist in restoring Global Admin access or correcting the Conditional Access configuration.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.