Tag not monitored by Microsoft.
To get Microsoft to actively work your MFA reset issue for an Azure AD B2C / Microsoft Entra tenant, use these escalation paths and make sure the case is correctly filed so it reaches the Data Protection / identity support teams.
- Verify the support ticket is opened in the correct place
- For Azure AD B2C, tickets must be opened from the Microsoft Entra tenant in the Azure portal, not directly from the B2C tenant:
- Sign in to the Azure portal.
- If there are multiple tenants, use Directories + subscriptions to switch to the Microsoft Entra tenant.
- Search for and select Microsoft Entra ID.
- Under Troubleshooting + Support, select New support request.
- On Problem description:
- Issue type:
Technical. - Subscription: select the correct Azure subscription.
- Service type:
Azure Active Directory Business to Consumer (B2C). - Provide a concise summary (under 140 characters) and choose the closest Problem type.
- Issue type:
- Proceed through Recommended solution; if self-help doesn’t fix it, continue to Additional details and fill in:
- Tenant ID/domain.
- Exact time/date of the lockout or MFA issue.
- That this is an MFA reset / tenant lockout scenario and that access to the admin account is blocked.
- Under Advanced diagnostic information, select Yes (Recommended) so support can access diagnostic data.
- Select an appropriate Severity (for business-impacting lockout, choose the highest justified severity) and preferred contact method.
- Complete Review + create and submit.
- Use severity and support plan correctly
- For paid plans, higher severity levels drive shorter initial response times. Ensure the ticket clearly states:
- That this is an MFA / admin lockout issue on an Azure AD B2C / Entra tenant.
- Business impact (e.g., sign-in blocked for users, production system affected).
- If there is a Premier or Unified support contract, use the highest appropriate severity and phone callback options where available. These contracts allow specifying severity (Critical / A / B / C) and scheduling callbacks, which typically accelerates handling.
- Engage the Data Protection team via phone if locked out as the only admin For tenant lockout / MFA reset when there is only one admin and portal access is blocked, the correct escalation path is via Microsoft’s Data Protection team through phone support:
- Call the regional number listed under Customer service phone numbers - Microsoft Support.
- When navigating the IVR / frontline agent, clearly state:
- The issue is Authenticator / MFA.
- Product: Office 365 for business / Microsoft 365 / Entra ID (company account).
- Confirm being an administrator and that there is no other admin.
- Request creation of a service request with the Data Protection team to reset MFA / restore admin access.
- This team has specific tools and processes to verify identity and restore access when all admins are locked out.
- If tickets are ignored or stuck If existing tickets are not being actioned despite a paid plan:
- Confirm that the ticket:
- Is filed under the correct Service type (
Azure Active Directory Business to Consumer (B2C)). - Has Technical issue type and appropriate Severity.
- Includes explicit mention of tenant lockout / MFA reset and business impact.
- Is filed under the correct Service type (
- If the ticket is misrouted (e.g., billing instead of technical), open a new technical ticket following the steps above and reference the existing case number in the description.
- For Premier/Unified support, use the portal options to adjust severity or request a callback if available.
- As a last resort: create a temporary tenant to reach support If phone support and normal ticketing paths fail to connect to the right team, a documented workaround is:
- Create a new trial Microsoft 365 / Azure tenant.
- From that new tenant’s admin center, open a support ticket.
- Clearly state that the request is on behalf of a different, existing tenant where the admin is locked out and provide:
- Admin UPN for the locked tenant.
- Tenant domain / name.
- Error messages and MFA details.
- Confirmation that this is a tenant lockout and requires Data Protection involvement.
- This temporary tenant is only a channel to reach support; it does not give access to the locked tenant. Remember to cancel the trial after resolution.
Using the correct support entry point (Microsoft Entra ID → New support request → Azure AD B2C) with high severity and explicitly requesting Data Protection involvement is the most reliable way to get an MFA reset / tenant lockout case actively worked.
References:
- Find help and open a support ticket for Azure Active Directory B2C
- Fabric and Power BI support overview
- Which support portal should I use?
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A