Only Global Administrator locked out after converting external user to internal user; MFA no longer works

EricYang-2174 20 Reputation points
2026-07-04T06:30:29.7033333+00:00

Hello,

I need help with an Azure / Microsoft Entra tenant administrator lockout.

I am the only Global Administrator for my Azure tenant. My admin account was originally an external Microsoft account:

Old sign-in account:

@outlook.*******

In Microsoft Entra ID, I converted this user from an external/B2B user to an internal user. After the conversion, the new internal UPN is:

@e**********.onmicrosoft.com

I still know the password for the new internal account. However, when I try to sign in, I am prompted for a Microsoft Authenticator verification code. The verification codes from my existing Authenticator entries no longer work.

The sign-in page says:

“You didn't enter the expected verification code. Please try again.”

There is no “Sign in another way” option available on the MFA page.

I no longer have:

  • another Global Administrator account,
  • another Authentication Administrator account,
  • an active Azure Portal session,
  • or a working Azure CLI Graph token that can manage the tenant.

Because of this, I cannot access:

  • Azure Portal,
  • Microsoft Entra admin center,
  • Azure support ticket creation,
  • or the user authentication methods page.

There are also active Azure resources running in the subscription, and I cannot stop/delete/manage them while locked out, so costs may continue to accrue.

Tenant / subscription details:

Tenant ID:

Subscription name:

Recent sign-in error details:

Request ID:

Correlation ID:

Timestamp:

2026-07-04T06:07:36.396Z

Question:

What is the correct Microsoft/Azure support path for recovering access when the only Global Administrator is locked out due to MFA/authentication method mismatch after converting an external user to an internal user?

Specifically, I need Microsoft to reset the authentication methods for:

@e*******.onmicrosoft.com

or issue a Temporary Access Pass so I can sign in and re-register MFA.

I cannot create an Azure support ticket because creating the ticket also requires signing in.

Any guidance on the correct escalation path would be appreciated.

Thank you,

Eric

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

Answer accepted by question author
Alina Le 5,080 Reputation points Independent Advisor
2026-07-04T15:25:35.95+00:00

Hello @EricYang-2174

Just to confirm your situation, you are the only Global Administrator in the tenant. You converted your admin account from a B2B/Guest Outlook.com account to an internal onmicrosoft.com account, and since then you can still enter the correct password, but MFA verification no longer works. Because there are no other administrators, active admin sessions, or alternative authentication methods available, you are currently locked out of the tenant and unable to access Azure, Entra ID, or create a support request.

At this point, the only team that can assist you is the Microsoft Data Protection Team. Contacting them directly is the only way to regain access to your account.

1/ Contacting Microsoft Data Protection team by phone support

In this situation, the Microsoft Data Protection team has tools and processes in place to verify identity and regain access to administrator accounts.     

Therefore, if you are the only administrator in your organization, then you need to involve Microsoft data protection team. Please try to find the related hotline number to call the frontline let them raise a ticket for you: Customer service phone numbers - Microsoft Support

If you can use English, you may prefer these numbers:

copyImage

copyImage

(Important Note: Depending on your country or region, when you call the support number, you may hear an introduction of about 30 seconds such as "you can visit the link...". You can ignore this introduction and wait until you are presented with the options. Then press "1" as a business email user, and again "1" for technical help.)

In some countries, this is an automated conversation: First, when you call the hotline, they will ask you what kind of problem you are struggling with.

Answer: Authenticator.

A: What products do you use?

B: Office 365 for business.

Verification: Education or company account?

B: For companies

A: Are you an administrator?

B: Yes.

A: Are there any other administrators in your organization?

B: No.

A: I need one.... Service request?

B: Yes  

If your organization's Office 365 Business subscription is from a partner or reseller, and the global administrator is unable to open a service request on your end, contact the reseller's support provider to help open a service request on behalf of you instead.

Please try "2 or 3"times until you can reach out to an agent.

2/ Another work around

If you still cannot reach to agent, there is still a workaround, you might consider registering for a new tenant by signing up for a trial subscription. This would allow you to create a new tenant following the prompts provided. Once set up, you can access the admin console of the new tenant and submit a support ticket requesting to speak with the Data Protection team on behalf of your previous tenant.   

For detailed guidance, to set up a new tenant, please follow these steps:    

User's image

Once your tenant is created, you should be able to access the support portal and submit your ticket without further issues 

Ticket Support: In the Microsoft 365 Admin Center->Support->Help & Support. You can raise support ticket In Microsoft Admin Center by this link:

https://admin.microsoft.com/#/support/requests 

copyImage copyImage copyImage

After that, they will contact you via email to schedule a direct support appointment

*Please remember to cancel the trial subscription once your issue is resolved to avoid any unintended charges.   

_

After successfully regaining access to your admin account, to prevent this issue from happening again, consider assigning 1 or 2 additional global admins to your tenant. That way, they’ll be able to help reset MFA in similar situations without having to contact customer support. 

Assign admin roles in the Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn 

Manage authentication methods for Microsoft Entra multifactor authentication - Microsoft Entra ID |… 

Please let me know if I can do anything more for you!


If you have extra questions about this answer, please click "Comment".  

Note: Please follow the steps in "our documentation" to enable e-mail notifications if you want to receive the related email notification for this thread.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.