Guest Global Administrator locked out by stale Entra MFA registration — all support intake channels blocked by the same lockout — need Data Protection / Tenant Recovery

Joshua Summers 20 Reputation points
2026-08-13T23:59:00.6166667+00:00

I am a Global Administrator and the sole subscription Owner in the Entra tenant catalystjshotmail.onmicrosoft.com (Pay-As-You-Go subscription). My identity in this tenant is an external guest backed by a personal Microsoft account. I can provide the exact UPN, the backing account address, and billing details through a private channel.

PROBLEM: Portal sign-in is blocked by a stale MFA registration on the guest identity in the resource tenant. After the personal-account authentication succeeds, the tenant demands a 6-digit verification code. The only methods I hold are on the underlying personal Microsoft account: Authenticator push and an 8-digit personal-account TOTP. The tenant's code field is hard-capped at 6 digits, so no method I possess can satisfy the prompt. My last successful interactive sign-in was November 2025.

SELF-SERVICE PATHS ALREADY RULED OUT:

  1. The security-info page (My Sign-Ins) rejects personal Microsoft accounts, so I cannot view or remove the tenant-side registration myself.
  2. A Temporary Access Pass cannot be issued to an external guest.
  3. My secondary admin account in the tenant is behind an MFA registration I also cannot satisfy.
  4. The tenant's only other Global Administrator (a cloud-only member account) is also locked out and unable to authenticate -- apparently since the October 2025 MFA enforcement phase, unnoticed because tenant activity stopped in November 2025. No administrator of this tenant can complete an interactive sign-in, so no admin-side reset ("Require re-register multifactor authentication") can be performed from inside the tenant.
  5. I cannot open a support request from inside the Azure portal, because the portal is what I cannot reach, and Microsoft's global customer service phone line disconnects callers to online help.
  6. Programmatic ticket creation is also blocked by the same lockout: "az support in-subscription tickets create" (against the Subscription Management service, problem classification "Unable to log in or access my subscription due to an MFA-related issue") is refused with RequestDisallowedByAzure -- "You are receiving this error because you tried to create, update or delete Azure resources without authenticating through MFA." The error's remediation instruction (register MFA) is the action items 1 and 2 above make impossible for this identity. Every support intake channel Microsoft provides requires the access this request seeks to restore.

Azure CLI read-only access still works via device-code sign-in, which I can use on request to demonstrate live control of the identity and subscription.

REQUEST: Please route this to the Data Protection / Tenant Recovery team to verify ownership and clear/reset the registered authentication methods on the guest user object in tenant catalystjshotmail.onmicrosoft.com, so that I am prompted to re-register at next sign-in. I can verify ownership via the subscription's billing payment instrument, tenant details, and the device-code sign-in above.

IMPACT: The subscription's sole Owner is locked out of a live, billing subscription -- two App Service plans and two MySQL Flexible Servers running unattended since November 2025 -- with no portal access to manage or decommission resources.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

Answer accepted by question author
Killian N 3,900 Reputation points Independent Advisor
2026-08-14T11:14:42.6966667+00:00

Hi,

Based on your description, it appears that all Global Administrator accounts in the tenant are inaccessible due to MFA-related lockout, leaving no administrator available to perform an MFA reset or other recovery actions from within the tenant.

In this scenario, the only available path to regain administrative access is to contact Microsoft Support by phone and request engagement with the Data Protection team, who have procedures available to verify ownership and assist with administrator account recovery.

Please locate the appropriate support number for your region here: Customer service phone numbers - Microsoft Support 

Here are some tips and an example of a prompt to help you navigate the IVR more effectively: 

(When you call the support number, you may hear an introduction of about 30 seconds such as "you can visit the link...". You can ignore this introduction and wait until you are presented with the options. Then press "1" as a business email user, and again "1" for technical help.)   

In some regions, the initial interaction may be automated, so here’s a general idea of how the conversation might go to help you prepare:     

  • What kind of problem are you experiencing?        
  • Answer: Authenticator        
  • What products do you use?        
  • Answer: Office 365 for business        
  • Is this for an education or company account?        
  • Answer: For companies        
  • Are you an administrator?        
  • Answer: Yes        
  • Are there any other administrators in your organization?        
  • Answer: No. I am the only admin in my tenant         
  • Do you need a... Service request?         
  • Answer: Yes. I need to create a ticket. Please send me direct to the Data Protection Teams.     

During the recovery process, you may be asked to provide tenant, subscription, billing, contact, and ownership information so that Microsoft can perform the necessary verification before assisting with access restoration.

While the Learn forum cannot directly route cases to the Data Protection team, contacting Microsoft Support by phone and requesting a Data Protection referral is the correct escalation path for a tenant-wide administrator lockout scenario such as the one you've described.

I hope these steps help you create a support ticket successfully and move closer to regaining access to your administrator account. While I’m not able to intervene directly, guiding you to the right support team is the most effective help I can provide here. 

Hope you're able to get this resolved soon.


If the answer is helpful, please click "Yes" and kindly upvote it. If you have extra questions about this answer, please click "Comment".      

Note: Please follow the steps in forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.