Entire M365 tenant locked out for 5 days — all users including sole global admin return "account not found"; support keeps asking for a working email

2026-09-08T14:49:02.6433333+00:00

We have been completely locked out of Microsoft 365 since September 4. Every sign-in for our domain returns "We couldn't find an account with that username," including the sole global admin. No one in the organization can access email, Teams, or the admin center. Our business has effectively been down for five days and we have no path forward.

Tenant details

  • Tenant: xxx.onmicrosoft.com (originally provisioned via GoDaddy about a year ago, migrated to direct Microsoft management a few months later under the Microsoft for Startups program)
  • Custom domain: santechamerica.com
  • Licenses paid for a full year; production Azure workloads run in the same tenant and are still operational

What we have verified

  • getuserrealm still resolves santechamerica.com to this tenant as Managed (non-federated)
  • MX records still point to santechamerica-com.mail.protection.outlook.com
  • GoDaddy's email status page confirms the service is Microsoft-managed and GoDaddy has no control over it
  • No changes were made on our side. The portal does not allow deleting the last global admin, so removing 20 users plus the only admin could not have come from us. The user objects appear to have been deleted at Microsoft's end.

Support experience so far

  • First contact called it a "domain lock" and promised a same-day callback that never came.
  • A second agent called and said the case would be handled.
  • The Tenant Data Recovery team then spent an entire call asking for a "working email address." There is none — that is the problem. They declined to document the case in writing and told us to wait 48 hours. That window has now passed with no update.

We are genuinely helpless here. There is no admin to sign in with, no self-service path, and each call restarts from zero. We control DNS for the domain and can complete TXT-record ownership verification immediately.

What I'm asking

  1. Is there an escalation path for a full tenant lockout where no admin credential exists, beyond the standard Tenant Recovery queue?
  2. Can someone from Microsoft pick this up and confirm in writing what has been reviewed? The 30-day soft-delete window for the deleted users started September 4.
  3. Has anyone seen this pattern — a formerly GoDaddy-resold tenant losing all user objects after migration to direct Microsoft management?

Any pointers to the right team or process would be appreciated. Five days of total outage for a paying customer with no acknowledgment is not sustainable.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

2 answers

Sort by: Most helpful
  1. Kien 1,145 Reputation points Independent Advisor
    2026-09-08T14:56:37.4066667+00:00

    Dear Senthil Kumar Kulandaivelayutham,

    Please note that since your account is belonged to an organization, none of moderators or forum users could help you do this action.

    Based on your description, kindly try to create a new tenant with trial subscription to access and submit a ticket in the Admin Center.

    Sign up for a free trial (new tenant with trial subscription) of Microsoft 365 at this link: Compare All Microsoft 365 Plans | Microsoft. The goal is to create a temporary tenant with a Global Administrator account so that you can sign in to the Microsoft Admin Center. Once connected, you can submit a support ticket directly to Microsoft. Please remember to cancel the trial subscription once your issue is resolved to avoid unwanted charges.

    How to submit support ticket in Admin Center: Get support - Microsoft 365 Admin | Microsoft Learn

    Once you contact the Data Protection team, you will be required to provide proof of ownership of the company. This allows them to verify their identity and help reassign the Global Administrator account.

    After regain access, please proceed the steps you need (add, remove or edit user, or update the billing information on the account).

    I hope the information shared helps point you in the right direction.


    If the answer is helpful, please click "Yes" and kindly upvote it. If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


  2. AI answer

    2026-09-08T14:49:26.71+00:00

    For a full tenant lockout with no working Global Administrator, the supported path is Microsoft 365 support and identity verification. There is no separate self-service escalation that bypasses tenant recovery.

    Based on the described state:

    1. Try the standard recovery entry points first:
      • Go to the admin portal.
      • Try any previously used admin sign-in, including the original onmicrosoft.com admin account.
      • If prompted to request admin access, follow that flow.
    2. If sign-in and recovery prompts fail, open a support request through Microsoft 365 support:
      • Go to the Microsoft 365 support page.
      • Select I can't sign in or access my tenant.
      • Be prepared to verify organizational ownership through items such as:
        • official business documentation
        • domain ownership
        • publicly listed company registration data
    3. Because the tenant was originally provisioned through GoDaddy, confirm whether the custom domain is still tied to a GoDaddy-provisioned Microsoft 365 tenant state:
      • If sign-in is redirected or blocked because of a GoDaddy-managed connection, contact GoDaddy and request release of the custom domain from the Microsoft 365 tenant.
      • This can temporarily disrupt email service, so confirm impact before proceeding.
      • After release, sign in with the default NETORG...onmicrosoft.com admin account if applicable, and use Forgot my password if the password is unknown.
    4. If a partner previously managed the tenant and still has an active GDAP relationship with the required roles, the partner can help with password reset or elevation. If there is no partner with the required GDAP access and no other Global Administrator exists, Microsoft support is the required path.
    5. For a locked-out tenant owned by the organization, Microsoft support can route the case for credential reset or ownership claim after verification. The documented support path states that if locked out of a tenant, a support ticket must be opened.

    Supported answers to the specific questions:

    • For escalation beyond normal self-service: the documented path is still Microsoft 365 support with identity verification. Microsoft for Nonprofits and similar program teams cannot bypass identity verification or directly restore tenant access.
    • For the “working email address” issue: the documented process focuses on identity and ownership verification, not on requiring access to the affected tenant’s email. Domain ownership and business documentation are explicitly listed as verification methods.
    • For the GoDaddy history: the documented GoDaddy issue pattern is domain binding, redirected login, or blocked admin access. The provided material does not document a confirmed pattern of all user objects disappearing after migration to direct Microsoft management, so no supported conclusion can be drawn on that point.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.