Tag not monitored by Microsoft.
Because the account is a business/tenant account and there is only one administrator who is now locked out by MFA, recovery must go through Microsoft’s Data Protection team. Local changes or self-service options will not work once locked out as the sole admin.
Follow these steps:
- Try any alternative MFA/sign-in methods first (if available)
- If another verification method was ever configured (SMS, phone call, different app, security key), use “Sign in another way” on the sign-in screen and complete sign-in that way.
- If this works, go to the Security info / Additional security verification page and update or remove the old phone/app and add the new phone and Microsoft Authenticator again, as described in:
- If no alternative method works and you are locked out as the only admin
In this situation, only Microsoft’s Data Protection team can reset the admin’s MFA:- Call the Customer service phone numbers - Microsoft Support line listed in the documentation.
- When the IVR/automated system asks questions, answer along these lines to reach the correct team:
- Problem type: say “Authenticator”.
- Product: “Office 365 for business”.
- Account type: “For companies” (not education/personal).
- When asked if there is another administrator: “No”.
- When asked if a service request is needed: “Yes, I need to create a ticket and speak with the Data Protection team”.
- Clearly state that:
- This is a business/tenant account.
- The caller is the only global administrator.
- MFA is blocking access after a phone change and Authenticator reset.
- The frontline agent should open a Data Protection ticket. That team will then verify identity (business documentation, tenant details, etc.) and perform an admin MFA reset so access can be restored.
- If phone support cannot be reached or will not route correctly
As an alternative path used in similar cases:- Sign up for a new trial Microsoft 365 tenant (a completely separate environment) using the public Microsoft 365 Business/Enterprise trial link in the documentation.
- After creating that new tenant, go to the Microsoft 365 Admin Center for the new tenant and open a support ticket from there.
- In the ticket, clearly explain that:
- The issue is with a different, existing tenant.
- The original tenant’s only global admin is locked out by MFA after a phone change.
- Provide the locked tenant’s domain and admin UPN and request escalation to the Data Protection team to reset MFA on the original tenant.
- This temporary tenant is only for contacting support; it does not give access to data in the original tenant. Remember to cancel the trial once the original tenant is recovered.
- After Data Protection resets MFA
- Sign in again to the original tenant when instructed.
- Reconfigure MFA methods immediately: add the new phone number, install and register Microsoft Authenticator on the new phone, and consider adding at least one backup method (phone/SMS/alternate app) so a future device change does not cause another lockout.
These are the supported recovery paths when a sole business/tenant administrator is locked out due to Microsoft Authenticator/MFA issues.
References:
- Common problems with two-step verification for a work or school account
- Use a screen reader to set up and troubleshoot multifactor authentication
- Troubleshoot Microsoft verification code issues
- "Account verification system is having trouble" error message when you try to sign in by using a work or school account
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A