Global admin acc locked out as in the new phone does not retain the credentials in authenticator app.

Test_acc 0 Reputation points
2026-06-09T18:55:09.9166667+00:00

My Global admin acc is locked out and stuck at MFA because my new phone did not retain the MFA authentications in the authenticator app.

I have opened the ticket and had been waiting to hear as I actively use this tenant for my everyday work.

PII

Have been emailing but no response. Would appreciate some help here.

Thanks!

Isha Kapoor

Community Center | Not monitored

1 answer

Sort by: Newest
  1. AI answer

    2026-06-09T18:55:25.3066667+00:00

    Because the new phone no longer has the Microsoft Authenticator registrations and the account is a Global Administrator stuck at MFA with no alternative methods, this is a tenant lockout scenario that must be handled by Microsoft support/Data Protection.

    From the available guidance, there are only two supported recovery paths:

    1. If there is another Global Administrator in the tenant
      That admin can reset MFA so the locked-out admin can re-register on the new phone:
      • Sign in to the Azure portal and open Microsoft Entra ID.
      • Go to Users and open the affected admin’s user profile.
      • Go to Authentication methods and select Require re-register multifactor authentication.
      • Next time the admin signs in, the portal will prompt for MFA registration again on the new device.
    2. If this is the only Global Administrator (tenant lockout)
      In this case, recovery must be escalated to Microsoft’s Data Protection/Tenant Recovery team via a support ticket. Moderators and documentation describe the following options:
      • Use the existing support case and ensure it is routed to the Data Protection team for a tenant admin MFA reset / tenant recovery.
      • If unable to manage the case from the locked tenant, call Microsoft’s global customer service phone numbers and, in the IVR and with the agent, clearly state:
        • The issue is with Microsoft Authenticator / MFA.
        • The product is Office 365 / Microsoft 365 for business or Microsoft Entra ID.
        • It is a company/organization account.
        • The caller is the only Global Administrator and is locked out at MFA.
        • A service request is needed and it must reach the Data Protection team to verify identity and reset MFA.
      • If phone support cannot be reached or cannot locate the tenant, one documented workaround is to:
        • Create a new trial Microsoft 365 tenant.
        • From that new tenant’s Admin Center → Support → Help & support, open a ticket explicitly stating that the request is for MFA reset / tenant recovery for a different existing tenant where the admin is locked out and is the only Global Admin.

    In all single-admin lockout cases, the final resolution is performed only after Microsoft support verifies ownership of the tenant and then resets MFA registration for the locked-out Global Admin.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.