A cloud-based identity and access management service for securing user authentication and resource access
Tenant lockout, both Global Admins, AADSTS50196 security-info registration deadlock, case 2608190040008441 stalled 6 days
Requesting moderator assistance getting an existing Data Protection / Tenant Recovery case internally escalated.
Situation Both Global Administrator accounts on a Microsoft-direct production tenant have been locked out since 8/19/2026. Normal users authenticate fine. Password is accepted, "Let's keep your account secure" appears, security-info registration loops, the Authenticator challenge is never reached, and it terminates with AADSTS50196 LoopDetected. Reproduced on both GA accounts across multiple devices, browsers, private sessions, and networks. No break-glass account exists.
Diagnostic detail Tenant ID: 2ab87dba-924f-44e1-b9fc-3b262f0aa3ae Request ID: 132eb8ed-a123-48c4-8345-f423fe156300 Correlation ID: b27d25ce-601b-4324-bb66-23e65b3a347f Timestamp: 2026-08-24T16:34:47.044Z
The proof-up request from My Sign-Ins (client 0000000c-0000-0000-c000-000000000000) is issued with amr_values=ngcmfa and an essential acrs claim of urn:user:registersecurityinfo. Fresh MFA is required as a precondition for registering an MFA method, which the account cannot satisfy. This is a registration deadlock, not a client retry loop, so the standard AADSTS50196 token-caching guidance does not apply.
Case history 2608120010002185 - closed. Microsoft Support performed authentication/MFA configuration work under this case. The lockout began immediately afterward. 2608190040008441 - primary recovery case, open since 8/19, repeatedly said to be escalated to Data Protection / Tenant Recovery. No engagement received despite multiple promised callbacks. 2608210010000477 and 2608210010001259 - duplicates. 2608240040004238 - M365 case opened 8/24 from a separate tenant. Plus a Severity A Azure case opened 8/24 under a Standard support plan.
What I'm asking for
- Have 2608190040008441 reviewed, severity raised on business impact, and the duplicates merged into it.
- Have an engineer pull the change log from 2608120010002185 and check the tenant's Authentication methods policy and any Conditional Access policy targeting the Register security information user action.
- Issue a Temporary Access Pass to the affected GA. A TAP satisfies the MFA precondition and permits registration of new methods, resolving this without a full tenant recovery process.
I can complete DNS TXT domain verification, billing verification, and identity verification immediately. Happy to send tenant and account details by email rather than posting them.