Locked out of Authenticator App - need MFA reset - sole global administrator

John Podaras 20 Reputation points
2026-06-18T05:43:34.09+00:00

Product: Office 365 Business Standard Single Licence

Global admin is locked out due to broken MFA.

Authenticator method is unavailable; SMS blocked (error 399287).

Still have active Office session but cannot access Entra or Security Info.

Everything I try, asks for the authenticator code and cannot register the account on the authenticator because it asks for the code each time.

I understand that I need an MFA reset / re-registration for admin account, however when I contacted MS Support, I was directed to online solution which keeps asking for the authenticator code.

Is there any way out of this? Many thanks in anticipation.

John

Microsoft 365 and Office | Subscription, account, billing | For business | Android
0 comments No comments

Answer accepted by question author

AI answer

2026-06-18T05:43:47.5033333+00:00

For a sole global administrator who is fully locked out of Microsoft Authenticator and all other MFA methods, the issue cannot be fixed self-service in the portal and requires Microsoft support intervention via the Data Protection / Tenant Recovery process.

Because there is no second global admin who can use Require re-register multifactor authentication for the account, the only supported path is to contact Microsoft support by phone and have a ticket escalated to the Data Protection team so they can verify tenant ownership and reset the MFA registration on the admin account.

Actionable path:

  1. Call Microsoft global customer service using the public support phone numbers listed in Customer service phone numbers - Microsoft Support.
  2. When connected to the IVR/agent, clearly state:
    • This is an Office 365 Business (commercial) tenant.
    • The caller is the only global administrator.
    • MFA is enforced and the only method (Microsoft Authenticator) is unavailable.
    • The admin can still use the account password but cannot complete MFA or access the admin portal.
    • A Data Protection / Tenant Admin MFA reset is required.
  3. Ask specifically for a service request to be opened and escalated to the Data Protection team for tenant recovery / MFA reset on the global admin account.
  4. Follow the identity-verification steps requested by the Data Protection team (they will typically contact by phone or email as part of the support case) and complete the process so they can clear or reset the MFA methods on the admin account.

If front-line support routes back to online self-service flows that require Authenticator, insist that:

  • There is no second global admin available to perform Require re-register MFA.
  • The case must be handled by the Data Protection team because it is a tenant lockout scenario.

Once Data Protection has reset MFA, sign in again with the global admin account, complete MFA re-registration with a new Authenticator instance and, if possible, add at least one backup method (such as phone or alternate app) to avoid future lockouts.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Newest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.