Additional Microsoft Entra services and features related to identity, access, and network security
For lockout scenarios where the only Global Administrator has lost access and cannot manage the tenant, recovery must be handled directly by Microsoft Support and the Data Protection/Tenant Recovery team. Community responders and forums cannot perform or trigger an admin takeover.
For Azure AD B2C tenants specifically:
- If there is any other Global Administrator on the affected tenants (even via a different account or partner/GDAP relationship), that admin must:
- Sign in to the Azure portal, open Microsoft Entra ID for the affected tenant.
- Use the guidance for emergency access accounts and global admin redundancy to restore access (for example, promote another account, reset credentials, or adjust Conditional Access so that an admin can sign in again). See the guidance on emergency access accounts and tenant lockout prevention.
- If there is no other Global Administrator and both B2C tenants are effectively locked (the situation described):
- The tenant owner/global admin must contact Microsoft Support directly and request escalation to the Data Protection / Tenant Recovery team.
- Use the regional support phone numbers listed in the Microsoft 365 for business support contact article to open a support ticket. Clearly state that:
- The issue is a tenant lockout on Azure AD B2C tenants.
- There is no other Global Administrator able to sign in.
- An admin takeover / ownership verification is required.
- The Data Protection team has specific tools and processes to verify ownership and help:
- Reset credentials of an administrator account.
- Claim or take over tenants owned by the organization when appropriate.
- If the B2C tenants are associated with a partner (GDAP):
- A partner with an active GDAP relationship and the right roles (for example, Global Administrator, Privileged Role Administrator, or Privileged Authentication Administrator) may be able to help restore access without Microsoft escalation. If no such partner/roles exist, the tenant owner still must contact Microsoft Support.
- For future prevention on B2C tenants:
- Configure two or more emergency access accounts that:
- Are not tied to a single individual.
- Use strong, distinct authentication methods.
- Are excluded from restrictive Conditional Access policies.
- Do not expire or get removed by automated cleanup.
- Ensure at least two Global Admin accounts per tenant, with different credentials and MFA methods, and document recovery procedures.
- Configure two or more emergency access accounts that:
Because this scenario involves locked administrator access and no working admin account, the only path to perform an admin takeover or restore access is through a support ticket and Data Protection/Tenant Recovery; it cannot be completed from within the portal or by forum escalation alone.
References:
- Discover your Microsoft cloud footprint FAQ
- Azure AD B2C: Frequently asked questions (FAQ)
- Manage emergency access accounts in Azure Active Directory B2C
- Preventing tenant lockouts
- Technical and feature overview of Azure Active Directory B2C
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A