Single Global Administrator locked out of Microsoft 365 Developer E5 Sandbox after losing Microsoft Authenticator

Le Trung Dung 20 Reputation points
2026-06-28T06:53:24.1066667+00:00

Hello Microsoft Team,

I am currently locked out of my Microsoft 365 Developer Program E5 Sandbox tenant because Multi-Factor Authentication requires Microsoft Authenticator, and I no longer have access to the registered device.

My situation:

Microsoft 365 Developer Program (Renewable E5 Sandbox)

I am the only Global Administrator of the tenant.

I changed my phone and factory-reset the previous device.

The previous device contained the only registered Microsoft Authenticator.

I have no alternative MFA methods configured (SMS, recovery code, passkey, or another administrator).

I still have access to the original account used to register the Developer Program and can provide proof of ownership if required.

I would like to request guidance on the official recovery process for a Microsoft 365 Developer Sandbox tenant in this situation, or ask whether this case can be escalated to the appropriate Data Protection / Tenant Recovery team.

For privacy reasons, I have omitted the tenant domain and account details from this public post and can provide them through a private message if needed.

Thank you for your assistance.

Microsoft 365 and Office | Development | Microsoft 365 Developer Program
0 comments No comments

Answer accepted by question author
Anonymous
2026-06-29T04:39:12.1566667+00:00

Hi @Le Trung Dung

I’m sorry to hear you’re locked out of your Microsoft 365 Developer E5 account after resetting your phone. Unfortunately, this type of MFA issue can only be resolved by the Microsoft Support team. You might need to contact us via phone service number: Customer service phone numbers - Microsoft Support. The agent will be able to create a ticket for you under the affected tenant and then transfer this ticket to Data Protection team who could help you to regain access.  

When a call is made to support, the first step is to provide an automated voice response from AI. Be careful, you won't be able to speak to a support representative if you don't respond appropriately here. 

Here's an example of a response that actually led to a support representative. Please refer to it. 

Q. Can you tell me if you are calling as a home user who uses a product or service at home or a business user who uses it in your business to provide the best assistance? 
A.I am a business user. 
Q. Thank you. Can you give me the details of your inquiry? 
A. Login technical support. 
Q. First of all, can you tell me which products you are inquiring about today? 
A. Microsoft 365 business Standard。 
Q. Please wait a moment, I understand Microsoft 365. Are you calling about a new case or an existing one? 
A. New. 
Q. To receive phone support, your phone number must be associated with your Microsoft 365 admin profile. To do this, go to aka.ms/m365profile. Again, it aka.ms/m365profile . This can take 48 hours. In the meantime, you can go to aka.ms/m365profile and file a case online. If you prefer, you can also text the link to the phone number you are calling. What do you think? 
A. The phone number is already linked to the link. 
Q. Can you tell me about the products in your inquiry? 
A. Microsoft 365 Business Standard. 
Q. Are you a Global Administrator? 
A. That's right. 
Q. I'm sorry. I didn't understand. Are you a global administrator for your domain? 
A. Yes, I am a global administrator for the domain. 
Q. If you have any inquiries, you can contact a Microsoft representative. Are you sure? 
A. Yes. Please. 
Q. Yes, I understand. Please wait a moment.

Please note that this team is always overwhelmed, so you might need to wait for them to call you, this should take 3-10 working days. I know that this is not a convenient solution to hear but it seems to be the only way, and it's recommended that you should have a secondary/backup Global Administrator to fix this issue on your own.    

In case the phone line is not supportive, you can consider directly submitting a support request as a helpful workaround:    

-Create a temporary Microsoft 365 tenant using a trial license: Go to Microsoft 365 Business Plans and Pricing and click Try for free to set up a temporary Microsoft 365 tenant with a trial license.    

-Use this new account to sign in to the Microsoft 365 Admin Center and submit a support request on behalf of your primary (locked) account.   

-Click Help & Support > then choose Create a support request.    

Note: This method doesn't require you to use your new account for your business. Instead, it allows you to create a temporary global administrator account so you can submit a support request, as your original global administrator account is locked out due to issues with multi-factor authentication. The trial account is free for one month. Be sure to delete it after submitting your support request to avoid any automatic renewals or charges from Microsoft.     

For further instructions, you can follow this guide: Get support - Microsoft 365 admin | Microsoft Learn   

I appreciate your understanding and patience in this matter. While I truly want to assist you, this issue is beyond the scope of my role as a forum moderator. I do not have access to internal databases or the ability to escalate cases directly to Microsoft’s internal teams. Therefore, please kindly contact the Microsoft Support team for the most efficient help.   


If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".       

Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-06-28T06:53:58.0266667+00:00

    For a single Global Administrator who is locked out because Microsoft Authenticator on the only device was lost and no alternate MFA methods or admins exist, self-service recovery is not possible. Recovery must go through Microsoft support and the Data Protection / Tenant Recovery team, even for a Microsoft 365 Developer Program E5 sandbox tenant.

    Use this pattern, adapted from the documented and Q&A-supported process for similar tenant lockout scenarios:

    1. Try standard MFA alternatives (only if configured)
      If any other verification options were ever configured (phone, SMS, or another method), select Other verification options on the sign-in page and attempt those first, as described in the MFA troubleshooting guidance. If none exist or they all fail, proceed to support-based recovery.
    2. If there is another Global Administrator (not your case)
      When another Global Administrator exists, that admin can reset MFA for the locked-out account:
      1. Sign in to the Azure portal and open Microsoft Entra ID.
      2. Go to Users, select the affected user.
      3. Open Authentication methods.
      4. Select Require re-register multifactor authentication.
        On next sign-in, the user is prompted to set up MFA again.
        Since the scenario explicitly states there is only one Global Administrator, this option is not available.
    3. Contact Microsoft support and request Data Protection / Tenant Recovery involvement
      For a tenant where the only Global Administrator is locked out due to MFA and no other admin or method can reset it, the documented and Q&A-supported path is to involve the Microsoft Data Protection team via a support request:
      • Call the appropriate Microsoft customer service / support number for the region using the public "Customer service phone numbers" or "global support phone numbers" pages referenced in the context.
      • When interacting with the IVR/agent, clearly state:
        • The product: Microsoft 365 for business / Microsoft 365 Developer subscription.
        • The issue: locked out of the tenant because of Microsoft Authenticator / MFA, only admin, no other MFA methods.
        • That this is a tenant lockout and you are the only Global Administrator.
        • Request creation of a service request and escalation to the Data Protection / Tenant Recovery team to reset MFA for the admin account.
      The Q&A guidance for identical situations (single admin, MFA-only Authenticator, no access) explicitly states that:
      • Forum moderators and community channels cannot reset or access accounts.
      • The Microsoft Data Protection team has specific tools and processes to verify identity and restore access for locked-out administrators.
      • Support may ask for verification of identity and administrative rights (tenant domain, admin UPN, business details, etc.).
    4. If direct phone routing is difficult, use a temporary tenant to open a ticket
      If it is not possible to reach the right support queue directly (for example, IVR loops or misrouting), Q&A guidance describes a workaround:
      • Create a new, temporary Microsoft 365 tenant using a trial subscription (for example, a Microsoft 365 business/enterprise trial).
      • Sign in to the new tenant’s Microsoft 365 admin center.
      • Go to Support → Help & support and open a support ticket.
      • In the ticket, clearly explain that:
        • The issue concerns a different, existing tenant (your Developer E5 sandbox tenant).
        • You are the Global Administrator of that locked tenant.
        • You are locked out due to Microsoft Authenticator MFA with no alternate methods.
        • You are requesting escalation to the Data Protection team to reset MFA / restore access on the locked tenant.
      • Provide the tenant domain, admin account, and any requested proof of ownership during the support process.
      • After resolution, cancel the trial subscription for the temporary tenant to avoid charges.
    5. Expect verification and some delay
      Community reports in similar cases indicate that:
      • The Data Protection engineer will contact by email or phone to verify ownership and identity.
      • After verification, they can reset or re-register MFA for the admin account and may help add an additional authentication method.
      • The process can take several days depending on case load and verification steps.
    6. After recovery, add redundancy to avoid future lockouts
      Once access to the Developer E5 sandbox tenant is restored:
      • Add at least one additional Global Administrator account with a different MFA method.
      • Configure multiple MFA methods for the primary admin (Authenticator on more than one device where allowed, phone/SMS, security key, etc.).
      • Consider creating a break-glass/emergency account excluded from strict Conditional Access policies, as recommended in tenant lockout prevention guidance.

    This is the officially supported pattern for single-admin MFA lockouts, and the same approach applies to a Microsoft 365 Developer Program E5 sandbox tenant.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.