I am locked out of the only administrator account on two Azure AD B2C tenants after changing the owner account of my main Azure subscriptions

Tim Hendriksen 0 Reputation points
2026-06-15T14:52:14.9666667+00:00

I am locked out of the only administrator account on two Azure AD B2C tenants. Neither Global Administrator is able to access the settings for these tenants. I am requesting escalation to the Data Protection / Tenant Recovery team to perform an admin takeover after ownership verification.

Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-15T14:52:36.3633333+00:00

    For lockout scenarios where the only Global Administrator has lost access and cannot manage the tenant, recovery must be handled directly by Microsoft Support and the Data Protection/Tenant Recovery team. Community responders and forums cannot perform or trigger an admin takeover.

    For Azure AD B2C tenants specifically:

    1. If there is any other Global Administrator on the affected tenants (even via a different account or partner/GDAP relationship), that admin must:
      • Sign in to the Azure portal, open Microsoft Entra ID for the affected tenant.
      • Use the guidance for emergency access accounts and global admin redundancy to restore access (for example, promote another account, reset credentials, or adjust Conditional Access so that an admin can sign in again). See the guidance on emergency access accounts and tenant lockout prevention.
    2. If there is no other Global Administrator and both B2C tenants are effectively locked (the situation described):
      • The tenant owner/global admin must contact Microsoft Support directly and request escalation to the Data Protection / Tenant Recovery team.
      • Use the regional support phone numbers listed in the Microsoft 365 for business support contact article to open a support ticket. Clearly state that:
        • The issue is a tenant lockout on Azure AD B2C tenants.
        • There is no other Global Administrator able to sign in.
        • An admin takeover / ownership verification is required.
      • The Data Protection team has specific tools and processes to verify ownership and help:
        • Reset credentials of an administrator account.
        • Claim or take over tenants owned by the organization when appropriate.
    3. If the B2C tenants are associated with a partner (GDAP):
      • A partner with an active GDAP relationship and the right roles (for example, Global Administrator, Privileged Role Administrator, or Privileged Authentication Administrator) may be able to help restore access without Microsoft escalation. If no such partner/roles exist, the tenant owner still must contact Microsoft Support.
    4. For future prevention on B2C tenants:
      • Configure two or more emergency access accounts that:
        • Are not tied to a single individual.
        • Use strong, distinct authentication methods.
        • Are excluded from restrictive Conditional Access policies.
        • Do not expire or get removed by automated cleanup.
      • Ensure at least two Global Admin accounts per tenant, with different credentials and MFA methods, and document recovery procedures.

    Because this scenario involves locked administrator access and no working admin account, the only path to perform an admin takeover or restore access is through a support ticket and Data Protection/Tenant Recovery; it cannot be completed from within the portal or by forum escalation alone.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.