Both Global Admins locked out — "Require re-register MFA" returns "Delete operation failed" — support case abandoned for 6 days

Eduardo Hoff Homem 0 Reputation points
2026-08-25T14:28:51.74+00:00

Tenant with two Global Administrators. Both lost Microsoft Authenticator registration after replacing their phones. No other authentication methods were registered. Result: complete tenant lockout with no self-service path.

While a session was still active, I attempted every documented remedy in the Entra admin center:

  • "Require re-register multifactor authentication" returns the error: "Require User Verification — Delete operation failed. Try this command again or delete them one by one in the user authentication methods blade."
  • The user's authentication methods list renders empty, so there is nothing to delete one by one.
  • "Add authentication method" remains permanently disabled.
  • Temporary Access Pass is enabled in the authentication methods policy, but cannot be issued because the add-method command is disabled.

The session has since expired. Both admins are now fully locked out.

Support case 2608210040000540 was opened five days ago, assigned to the Data Protection team, escalated in writing as 24/7 — and has been silent since a single failed phone call attempt. A message sent to the designated support address was auto-deleted unread 32 seconds after delivery.

Two questions:

  1. Is the "Delete operation failed" error on Require re-register MFA a known bug, and is there any workaround via Graph API or PowerShell that works when the portal command fails?
  2. Is there any way to get an abandoned Data Protection case actively worked? All ownership verification documents have been ready since day one.

Any Microsoft engineer able to pick this up internally, the case number is above.Tenant with two Global Administrators. Both lost Microsoft Authenticator registration after replacing their phones. No other authentication methods were registered. Result: complete tenant lockout with no self-service path.

While a session was still active, I attempted every documented remedy in the Entra admin center:

  • "Require re-register multifactor authentication" returns the error: "Require User Verification — Delete operation failed. Try this command again or delete them one by one in the user authentication methods blade."
  • The user's authentication methods list renders empty, so there is nothing to delete one by one.
  • "Add authentication method" remains permanently disabled.
  • Temporary Access Pass is enabled in the authentication methods policy, but cannot be issued because the add-method command is disabled.

The session has since expired. Both admins are now fully locked out.

Support case 2608210040000540 was opened five days ago, assigned to the Data Protection team, escalated in writing as 24/7 — and has been silent since a single failed phone call attempt. A message sent to the designated support address was auto-deleted unread 32 seconds after delivery.

Two questions:

  1. Is the "Delete operation failed" error on Require re-register MFA a known bug, and is there any workaround via Graph API or PowerShell that works when the portal command fails?
  2. Is there any way to get an abandoned Data Protection case actively worked? All ownership verification documents have been ready since day one.

Any Microsoft engineer able to pick this up internally, the case number is above.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.