Tag not monitored by Microsoft.
Because the new phone no longer has the Microsoft Authenticator registrations and the account is a Global Administrator stuck at MFA with no alternative methods, this is a tenant lockout scenario that must be handled by Microsoft support/Data Protection.
From the available guidance, there are only two supported recovery paths:
- If there is another Global Administrator in the tenant
That admin can reset MFA so the locked-out admin can re-register on the new phone:- Sign in to the Azure portal and open Microsoft Entra ID.
- Go to Users and open the affected admin’s user profile.
- Go to Authentication methods and select Require re-register multifactor authentication.
- Next time the admin signs in, the portal will prompt for MFA registration again on the new device.
- If this is the only Global Administrator (tenant lockout)
In this case, recovery must be escalated to Microsoft’s Data Protection/Tenant Recovery team via a support ticket. Moderators and documentation describe the following options:- Use the existing support case and ensure it is routed to the Data Protection team for a tenant admin MFA reset / tenant recovery.
- If unable to manage the case from the locked tenant, call Microsoft’s global customer service phone numbers and, in the IVR and with the agent, clearly state:
- The issue is with Microsoft Authenticator / MFA.
- The product is Office 365 / Microsoft 365 for business or Microsoft Entra ID.
- It is a company/organization account.
- The caller is the only Global Administrator and is locked out at MFA.
- A service request is needed and it must reach the Data Protection team to verify identity and reset MFA.
- If phone support cannot be reached or cannot locate the tenant, one documented workaround is to:
- Create a new trial Microsoft 365 tenant.
- From that new tenant’s Admin Center → Support → Help & support, open a ticket explicitly stating that the request is for MFA reset / tenant recovery for a different existing tenant where the admin is locked out and is the only Global Admin.
In all single-admin lockout cases, the final resolution is performed only after Microsoft support verifies ownership of the tenant and then resets MFA registration for the locked-out Global Admin.
References:
- Preventing tenant lockouts
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A