Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
For a locked-out global admin with no working MFA methods, the only supported resolution is through another admin or Microsoft’s Data Protection team. Forum moderators and this service cannot reset MFA or access the tenant.
Follow the path that matches the situation:
- If there is another global admin or cloud services admin in the tenant
Ask that admin to reset the MFA settings for the blocked account:- Sign in to the Microsoft Entra admin center as an admin.
- Go to Users → All users and select the locked-out account.
- Open Authentication methods.
- Use the option to Require re-register multifactor authentication so the user is forced to set up MFA again at next sign-in.
- If there is no other admin and this is a business/partner tenant (only one global admin)
This is a tenant lockout scenario. In this case, Microsoft’s Data Protection team must intervene:- Call Microsoft support for business products and ask to open a ticket with the Data Protection team for an MFA/tenant lockout on a global admin account.
- Use the regional phone numbers listed under Customer service phone numbers / Support for Business Products in the documentation.
- Clearly state that:
- This is the only global admin on the tenant.
- MFA is blocking access and there is no alternative method.
- You need MFA reset / access restored for the global admin.
- Be prepared to provide verification (company details, tenant information, MPN ID, etc.) as requested by support.
- If the tenant is managed via a CSP partner with GDAP
- If a CSP partner has granular delegated admin privileges (GDAP) with roles that can reset passwords or manage authentication, that partner should work directly with the customer to restore access (no need to engage Microsoft directly in that case).
- If the partner does not have sufficient roles, the end-customer global admin must contact Microsoft support as in step 2.
- If the phone was lost/changed or Authenticator is unusable but another admin exists
- Another cloud services admin can reset the MFA settings using the legacy MFA management page as documented:
- Sign in as admin.
- Go to
https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx. - Select the affected admin account.
- Select Manage user settings.
- Check Require selected users to provide contact methods again, then Save.
- After this, the locked-out admin signs in again and re-registers MFA methods.
- Another cloud services admin can reset the MFA settings using the legacy MFA management page as documented:
If none of the above applies (no other admin, no CSP partner with rights), the only path is to contact Microsoft support by phone and request escalation to the Data Protection team for MFA reset/tenant lockout.
References:
- Troubleshoot sign-in issues and account access problems
- Common problems with two-step verification for a work or school account
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Common questions about partner security requirements
- Preventing tenant lockouts
- Mandatory multifactor authentication for Azure and admin portals
- I can't sign in to my Microsoft account
- I need to reset my mfa methods - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Please confirm my e mail address as <removed PII>@outlook.com - Microsoft Q&A