Unable to access Microsoft 365 tenant due to MFA Error 500121 — only admin locked out

Tahir Abbas 20 Reputation points
2026-06-05T10:59:54.14+00:00

Hello Microsoft Community,

I need urgent guidance regarding my Microsoft 365 business tenant.

I am unable to sign in to my Microsoft 365 admin account due to MFA verification failure. The Microsoft Authenticator approval/code is not working, and the sign-in page shows:

Error Code: 500121 “Sorry, we’re having trouble verifying your account. Please try again.”

The affected Microsoft 365 accounts are:

  • [[Moderator note: Personally Identifiable Information removed]@psystemexp.com] — admin account / Global Administrator
  • [[Moderator note: Personally Identifiable Information removed]@psystemexp.com] — business email account

The main issue is that I cannot access the Admin Center or even my Microsoft 365 emails because the MFA verification is failing. I am currently posting this question from my personal Outlook account:

[[Moderator note: Personally Identifiable Information removed]@outlook.com]

I have already created a Microsoft Support case, but I want to know the correct recovery path because I cannot access the tenant to reset MFA myself. There is no other admin account available to reset the MFA method.

Can Microsoft Support or the Data Protection / Tenant Recovery Team reset or re-register MFA for the Global Administrator after verifying domain/company ownership?

Please advise the correct escalation route for a sole Global Administrator locked out due to MFA Error 500121.

Thank you.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

Answer accepted by question author
Anonymous
2026-06-05T11:29:20.23+00:00

Hello @Tahir Abbas,

Thank you for sharing your detailed situation, I truly understand how critical this is, especially as you are currently locked out as the only Global Administrator.

I noticed that you mentioned you have already created a Microsoft Support case. To help check the progress and follow up more closely, may I kindly ask if you already have the support ticket number available?

If so, could you please share it with me via private message? I’ve already sent you a message, so kindly click on “View message” to check it and reply there. This helps ensure your information remains secure.

User's image

Just to share a bit more context, once the case is properly submitted, it will typically be placed in the queue for the Data Protection team. After that, a support engineer will reach out to you directly and assist with identity verification and the necessary steps to restore access to your tenant.

Thank you again for your patience, and I’ll be happy to help check the status once I receive your case details.

Warm regards,


Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Newest
  1. AI answer

    2026-06-05T11:00:29.0066667+00:00

    For a sole Global Administrator who is locked out because MFA (Microsoft Authenticator/SMS) fails with error 500121 and no other admin exists, the recovery path is through Microsoft Support and the Microsoft Data Protection / Tenant Recovery team. The tenant owner cannot resolve this from the portals.

    Use the following escalation path:

    1. Contact Microsoft 365 / Azure Data Protection support by phone
      • Find the correct regional phone number from Customer service phone numbers - Microsoft Support or Support for Business Products as described in the documentation.
      • Clearly state during the IVR and to the agent that:
        • This is a business/organization (work or school) tenant.
        • The caller is the only Global Administrator.
        • The issue is MFA lockout (Microsoft Authenticator / SMS not working) and error like “Sorry, we’re having trouble verifying your account.”
        • No other admin can sign in to reset MFA.
      • Ask to be routed to the Microsoft 365 Data Protection team or Azure Data Protection team for tenant lockout / admin MFA reset.
    2. Data Protection / Tenant Recovery process
      • The Data Protection team has specific tools and processes to:
        • Verify identity and ownership of the tenant (they will request business and domain information, proof of ownership, etc.).
        • Reset or clear the Global Administrator’s MFA registration so that MFA can be re-registered.
      • This is the documented path when:
        • There is only one Global Admin and that account is locked by MFA.
        • No other admin or partner with the right roles can reset MFA.
    3. If the tenant is managed by a partner (GDAP / CSP)
      • If a Cloud Solution Provider (CSP) or partner has granular delegated admin privileges (GDAP) with password reset roles, that partner can:
        • Reset the Global Admin’s password or MFA directly without Microsoft escalation.
      • If the partner has GDAP but no password reset roles, the guidance is:
        • Use the Self Service Password Reset tool if enabled.
        • Otherwise, the end-customer Global Administrator must contact Microsoft support, which in this case is already the situation, so proceed with the Data Protection route above.
    4. If a support ticket is already opened
      • Ensure the existing ticket explicitly states:
        • “Sole Global Administrator locked out due to MFA; no other admins; require Data Protection / Tenant Recovery involvement to reset MFA registration.”
      • If the ticket is not yet with Data Protection, ask the support engineer to escalate to the Microsoft 365/Azure Data Protection team for tenant lockout.
    5. Scenarios where another Global Admin exists (for completeness)
      • If at any point another Global Admin is identified, that admin can:
        • Sign in to the Azure portal → Microsoft Entra ID → Users → select the locked account → Authentication methods → choose Require re-register multifactor authentication so the Global Admin can re-enroll MFA on next sign-in.
      • This does not apply here since there is no second admin, but it is the standard method when available.

    In summary, for a sole Global Administrator locked out by MFA error 500121, the correct and only supported recovery path is to contact Microsoft Support by phone, have the case routed to the Microsoft 365 / Azure Data Protection team, and work through their identity verification so they can reset or clear the MFA registration and restore access to the tenant.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.