Error 399287 – Administrator Account Locked Out Due to MFA Verification Failure

Lotfi GARZOUN 20 Reputation points
2026-07-03T20:22:42.68+00:00

Hello

I am requesting assistance because I am locked out of my Microsoft 365 tenant and can no longer complete the required multi-factor authentication (MFA) process.

I am the administrator of this Microsoft 365 tenant. However, I am currently unable to access the Microsoft 365 Admin Center (https://admin.cloud.microsoft) because I cannot complete the MFA verification process.

During sign-in, I am prompted to approve a request in my Outlook mobile app. However, no approval notification is received on my mobile device. I also use Microsoft Authenticator, but I do not receive any authentication prompt there either.

When I select the alternative verification option ("I can't use my Outlook mobile app right now") and attempt to verify by SMS or phone, the verification fails. The phone number associated with the account appears to be blocked or unavailable for MFA delivery, preventing me from receiving verification codes or calls.

As a result, I am completely locked out of the tenant and unable to manage authentication methods or update MFA settings.

Error Information:

  • Error Code: 399287
  • Request ID: [Moderator note: Personally Identifiable Information removed]
  • Correlation ID: [Moderator note: Personally Identifiable Information removed]
  • Timestamp: [Moderator note: Personally Identifiable Information removed]

Authentication Issues:

  • No MFA approval notification is received in Outlook Mobile.
  • No MFA prompt is received in Microsoft Authenticator.
  • SMS and phone call verification methods are unavailable and fail during sign-in.
  • The phone number +XXXXXXX XXX [Moderator note: Personally Identifiable Information removed] cannot be used to complete MFA verification.
  • I cannot access the Admin Center to modify MFA settings because authentication cannot be completed.I am the administrator of this Microsoft 365 tenant. However, I am currently unable to access the Microsoft 365 Admin Center (https://admin.cloud.microsoft) because I cannot complete the MFA verification process. During sign-in, I am prompted to approve a request in my Outlook mobile app. However, no approval notification is received on my mobile device. I also use Microsoft Authenticator, but I do not receive any authentication prompt there either. When I select the alternative verification option ("I can't use my Outlook mobile app right now") and attempt to verify by SMS or phone, the verification fails. The phone number associated with the account appears to be blocked or unavailable for MFA delivery, preventing me from receiving verification codes or calls. As a result, I am completely locked out of the tenant and unable to manage authentication methods or update MFA settings. Error Information:
  • Error Code: 399287
  • Request ID: [Moderator note: Personally Identifiable Information removed]
  • Correlation ID: [Moderator note: Personally Identifiable Information removed]
  • Timestamp: [Moderator note: Personally Identifiable Information removed] Authentication Issues:
  • No MFA approval notification is received in Outlook Mobile.
    • No MFA prompt is received in Microsoft Authenticator.
    • SMS and phone call verification methods are unavailable and fail during sign-in.
    • The phone number PII REMOVED cannot be used to complete MFA verification.
    • I cannot access the Admin Center to modify MFA settings because authentication cannot be completed.
    I kindly request that the Data Protection team investigate Error 399287, the affected administrator account, and the associated phone number to restore access to my tenant.
    Thanks in advance
Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

Answer accepted by question author
Ruby-N 13,325 Reputation points Microsoft External Staff Moderator
2026-07-03T21:37:25.6633333+00:00

Good day Lotfi, 

Thank you for taking the time to share your experience.  

I’ve gone through your description, and I’m sorry to hear that you’re having trouble accessing your administrator account due to issues with the Microsoft Authenticator app and error 399287. 

Just to gently clarify before we go any further, forum moderators don't have the ability to access, modify, or recover user accounts. Due to security and privacy requirements, issues such as sign in failures, password recovery, and multi-factor authentication can only be addressed by Microsoft’s dedicated support teams, who have the appropriate tools and authorization to manage account level settings securely. 

These scenarios require identity validation and tools that are strictly handled by dedicated support teams for security reasons. Since the only admin in your tenant cannot sign in, the next step is to contact the Microsoft Data Protection team, as they are the only team authorized to assist with admin account recovery.  

In addition, error code 399287 is often caused by Microsoft's phone verification protection system blocking the phone number, which can prevent SMS or voice verification from working even when the number is correct, so a Microsoft Support request is needed to have the number reviewed and unblocked. 

Once your IT admin has reset your MFA, the next time you log in to your account, you will be guided through the process of setting up the Microsoft Authenticator app again from the beginning by scanning a QR code. This will break the loop and allow you to access your account normally.  

However, only Microsoft Support can assist with unblocking your phone number. Once you regain admin access, you can create a support ticket through the Microsoft 365 admin center by navigating to Support > Help & Support. 

During the phone call, you will need to provide the information associated with your subscription, such as your company name, billing details, phone number, and an alternate email address, etc. This information allows the Data Protection team to verify your identity and securely assist you in regaining access to your administrator account.       

In some regions, the initial interaction may be automated, so here’s a general idea of how the conversation might go to help you prepare:      

Here are some tips and an example of a prompt to help you reach out the Microsoft Data Protection team support more effectively:   

(When you call the support number, you may hear an introduction of about 30 seconds such as "you can visit the link...". You can ignore this introduction and wait until you are presented with the options. Then press "1" as a business email user, and again "1" for technical help.)         

In some countries, it is an automated conversation like:  

IVR: What kind of problem are you concerned about?        

You: Authenticator.        

IVR: What kind of product do you use?        

You: Office 365 for business.        

IVR confirmation: education or company account?        

You: For companies        

IVR: Are you an administrator?        

You: Yes.        

IVR: Do you have another administrator in your organization?        

You: No.        

IVR: Do you need a... Service request? 

You: Yes. I need to create a ticket. Please send me directly to the Data Protection Team. 

  • If you cannot reach a live agent, there is still a workaround, you might consider registering for a new tenant by signing up for a trial subscription and submit your request from there.      

To set up a new tenant, please follow these steps below: 

Visit  Microsoft 365 Business Plans and Pricing | Microsoft 365. This would allow you to create a new tenant following the prompts provided. Once set up, you can access the admin console of the new tenant and submit a support ticket requesting to speak with the Data Protection team on behalf of your previous tenant.       

Follow the guided setup process to create a new account for a new tenant.   

Once your tenant is created, you should be able to access the support portal and submit your ticket referencing your locked account without further issues 

In your ticket description, you'll need to clearly explain that you're trying to regain access to your previous Microsoft 365 tenant and need help from the Data Protection team. Here's a message you can use or adapt:   

"Hello, I’m currently unable to access my previous Microsoft 365 tenant due to losing MFA access, which prevents me from receiving verification codes. Additionally, when I attempt to verify my identity via SMS or phone call, the process fails and displays error 399287. 

I’m the global admin, but I’m locked out and unable to generate a QR code or bypass MFA.    

I created this new tenant solely to request assistance. I kindly ask to be connected with the Data Protection team so that I can verify my identity and receive help recovering access to my original tenant, as well as resolving the issue affecting my phone number. 

This is urgent, as I rely on Microsoft 365 for my work and have been unable to operate for several days. I’m available to provide any documentation or verification needed to support the recovery process."   

I truly hope this helps you regain access to your account quickly. Even though I can't directly intervene, directing you to the correct and specialized support is the most effective help I can provide from my position.  

Thank you for your kindness and contributions to the forum.  


If you have any extra questions about this answer, please click "Comment".            

Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Lotfi GARZOUN 20 Reputation points
    2026-07-03T22:11:09.34+00:00

    Hello @Ruby-N

    Thank you for your detailed explanation and for taking the time to outline the available options.

    I have already come across most of this information during my research in the Microsoft forums. However, I'm concerned about the recommendation to contact the regional Microsoft support hotline. Based on many forum discussions, I have not found many cases where users were successfully connected to the Data Protection team through the phone support route, especially for MFA lockout situations similar to mine.

    Could you please clarify whether there is another way to reach the Data Protection team? For example, would it be possible to open a support request using a different Microsoft 365 tenant or another domain email address and ask Microsoft to assist with my original tenant?

    As a reminder, I am the only Global Administrator of the affected tenant, I cannot access the Microsoft 365 Admin Center, and the phone number associated with MFA verification appears to be blocked with error 399287.

    I would appreciate any alternative process or escalation path that has been successful in similar cases.

    Thank you again for your assistance.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.