Sole global administrator locked out - MFA SMS blocked (error 399287)

Kristoffer Humstad 20 Reputation points
2026-06-17T20:37:02.83+00:00

The only global administrator for our Microsoft 365 tenant (domain: nks-trondhjem.no) is unable to log in, because the only MFA method is failing.

  • SMS Verification to the registered phone number fails with error code 399287 ("Sorry, we're having trouble verifying your account") E.g. flagged for whatever reason by PhoneReputation.
  • Microsoft Authenticator / Other Authenticator had not been set up in advance, so SMS verification is the only existing alternative.

Error code:

  • 399287

Since this is the sole administrator account on the domain, no one else can reset the MFA. Could someone please help unblock MFA for the account from the backend? I can provide further details as needed (e.g. tenant ID, phone number, etc) via private message as necessary.

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Answer accepted by question author
Rukmini 43,915 Reputation points Microsoft External Staff Moderator
2026-06-18T16:58:11.8533333+00:00

Hello @Kristoffer Humstad

Thank you for sharing your details(user's email address, tenant id, phone number, country code and country) with us over Private Message

I have reached out to the engineering team to unblock MFA for your account. They have now unblocked it from the backend and removed the bad reputation on it. You should be able to log in to the Azure Portal without any issues.

Please try logging in and check if you can complete SMS authentication without any errors. Let me know if you encounter any issues.

As a best practice, I recommend registering the Microsoft Authenticator method for your account instead of relying on SMS. SMS and voice call authentication methods are more vulnerable to IRSF attacks (telephony fraud) and are generally less secure.

For better practice, I recommend registering with Microsoft Authenticator method to your account instead of SMS method as these SMS/Voice telecom auth methods are susceptible to IRSF attacks telephony fraud.

I hope this information is helpful. Please feel free to reach out if you have any further questions.

If the resolution was helpful, kindly take a moment to click on 210246-screenshot-2021-12-10-121802.pngand click on Yes for was this answer helpful. And, if you have any further query do let us know.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

2 additional answers

Sort by: Oldest
  1. AI answer

    2026-06-17T20:37:22.0866667+00:00

    Because SMS is the only registered MFA method and it is failing with “Sorry, we're having trouble verifying your account” (error 399287), and there are no other global admins who can reset MFA, this is a tenant lockout scenario that requires Microsoft support/Data Protection intervention.

    From the available guidance:

    1. Error like “Sorry, we're having trouble verifying your account” during MFA via SMS indicates a verification failure and can be related to invalid input or issues with the verification method. When other verification options exist, the recommendation is to use Other verification options and confirm phone numbers in user settings. In this case, there are no other methods configured, so this path is not available.
    2. When a user is blocked from using Microsoft Entra multifactor authentication, another global admin can:
      • Sign in to the Azure portal → Microsoft Entra ID → Users → select the affected user → check Block sign in and disable it if enabled, or require MFA re-registration under Authentication methods.
      • However, this requires a second global admin, which does not exist in this tenant.
    3. For tenants where the sole global admin is locked out due to MFA and no other admin can reset MFA, Microsoft’s documented path is to involve the Microsoft Data Protection / Tenant Recovery team via a support request. Forum moderators and community members cannot unblock or reset MFA from the backend.

    Actionable next steps:

    1. Contact Microsoft Support/Data Protection by phone
      • Use the public Customer service phone numbers - Microsoft Support page referenced in the documentation.
      • When navigating the IVR, clearly state:
        • The issue is with Authenticator / MFA.
        • The product is Office 365 for business / Microsoft 365 for business.
        • It is a company (work/school) account, not personal.
        • Confirm that this is the only global administrator and that the admin is locked out due to MFA (SMS failing with error 399287) and has no other methods.
        • Ask explicitly to create a service request with the Data Protection team for tenant admin MFA reset / tenant recovery.
      • Be prepared to provide tenant-identifying information (tenant name, domain such as nks-trondhjem.no, admin UPN, business details) so Microsoft can verify ownership.
    2. If phone support is difficult to reach, create a temporary trial tenant to open a ticket
      • Sign up for a new Microsoft 365 trial tenant (separate from the locked tenant).
      • In that new tenant, go to the Microsoft 365 admin center → Support → Help & support and open a ticket.
      • In the ticket, clearly state that:
        • The problem is with a different existing tenant (provide its domain and admin UPN).
        • The sole global admin is locked out due to MFA, SMS verification fails with error 399287, and there are no alternative MFA methods.
        • Request escalation to the Data Protection team to verify identity and reset MFA / restore access for the locked tenant.
      • This trial tenant is only a channel to contact support; it does not give access to data in the locked tenant.
    3. Do not keep retrying SMS excessively
      • The verification system can temporarily block or slow down codes due to unusual activity or high volume of requests. Avoid repeated attempts that may extend or worsen any temporary block.

    Only Microsoft support (Data Protection / Tenant Recovery) can perform the necessary backend actions in this scenario. Once they verify ownership, they can reset MFA registration or otherwise restore access for the sole global administrator.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. Ryan-N 16,005 Reputation points Microsoft External Staff Moderator
    2026-06-17T21:07:02.95+00:00

    Hi @Kristoffer Humstad ,

    Welcome to the Microsoft Q&A forum.

    Error code 399287 typically appears when Microsoft's systems detect unusual activity on your device. As a security measure, the device may be flagged with a bad reputation status to help protect your tenant from potential security risks.

    In this situation, you will need to contact Microsoft's Data Protection Team for assistance. They can review the issue on their systems and verify that your device is safe and legitimate.

    Please look up the appropriate support hotline for your region and contact Microsoft's frontline support. Once connected, ask them to create a support ticket for you through the following resource:

    Customer service phone numbers – Microsoft Support.

    In this case, Microsoft's Data Protection Team is the only team with the specialized tools and procedures required to verify your identity and securely restore access to the administrator account.

    Please note that forum moderators do not have the authority to directly intervene in user accounts, especially for issues involving:

    • Account sign-in
    • Password resets
    • MFA authentication
    • Changing or restoring access permissions

    Tips for navigating the IVR system (automated phone support)

    To help you navigate the IVR system more effectively, please refer to the guidance below:

    • When calling the support number, you may hear an introduction for approximately 30 seconds (for example: "You can visit the link..."). You can skip this and wait until the system presents the available options.
    • Then:
      • Press "1" – if you are a business email user.
      • Press "1" again – to select Technical Support.

    In some regions, the initial interaction may be fully automated. Below is a sample dialogue you can prepare in advance:

    • What kind of problem are you experiencing? Answer: Authenticator
    • What products do you use? Answer: Office 365 for Business
    • Is this for an education or company account? Answer: For companies
    • Are you an administrator? Answer: Yes
    • Are there any other administrators in your organization? Answer: No. I am the only admin in my tenant.
    • Do you need a service request? Answer: Yes. I need to create a ticket. Please transfer me directly to the Data Protection Team.

    During the call, you may be asked to provide subscription-related information such as:

    • Company name
    • Billing information
    • Phone number
    • Alternate email address

    This information helps the Data Protection Team verify your identity and securely assist in restoring access to your account.

    I hope this information is helpful. Please follow these steps and let me know if it works for you. If not, we can work together to resolve this.   

    Thank you for your patience and your understanding. If you have any questions or need further assistance, please feel free to share them in the comments on this post so I can continue to support you.

    I look forward to continuing the conversation.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.