Expired 2FA and Granular Admin Relationship – Request for Access Assistance

Matthias Olofsson 0 Reputation points
2026-09-18T13:49:37.5433333+00:00

Dear Microsoft,

We are currently assisting a customer with an account access issue.

Neither our team nor the customer currently has administrative access to the Microsoft tenant. The existing two-factor authentication (2FA) method is connected to an old phone number, which is no longer available. Our Granular Admin Relationship (GDAP) has also expired.

We would like to point out that we know the name of the user account that is registered with the locked Microsoft account.

The customer also has full control of the domain and its DNS zone. Because of this, the customer can create a DNS record for the domain if needed. This could be used as a way to verify that the customer controls the domain that is registered with the Microsoft account.

We would therefore like to ask if Microsoft can use the following information to verify ownership of the account:

We know the name of the user registered on the locked account.

The customer has full control of the registered domain.

The customer has full control of the DNS zone for this domain.

The customer can create a specific DNS record requested by Microsoft to prove control of the domain.

After successful verification, we would like assistance with updating the 2FA method to a new phone number, or with regaining the necessary administrative access to the tenant.

Please let us know what information or verification steps you require from us. If this case needs to be handled by a specific Microsoft team, we would appreciate it if you could escalate the case to the appropriate team, including the Microsoft Data Protection Team if necessary.

Thank you for your help with this matter. We are ready to provide any information or make any DNS changes needed to verify the customer's ownership and control of the domain.

Best regards,

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

1 answer

Sort by: Newest
  1. BabybooHN 3,210 Reputation points Independent Advisor
    2026-09-18T15:16:45.6366667+00:00

    Dear @Matthias Olofsson

    I understand the situation. Since the existing MFA method is tied to an unavailable phone number, there is no available administrator who can reset the authentication method, and the previous GDAP relationship has expired, this should be handled as a tenant/admin access recovery case.

    In this situation, I would recommend contacting Microsoft Support and specifically requesting escalation to the Microsoft 365 Data Protection/Tenant Recovery team. Microsoft has indicated that when the only Global Administrator is locked out and no other administrator can reset MFA, recovery must go through the appropriate Microsoft support process rather than bypassing MFA.

    You can provide Microsoft with the following information:

    • The affected tenant name/tenant ID and administrator UPN.
    • The name of the user/account that is locked out.
    • Confirmation that there are no other available Global Administrators.
    • Confirmation that the registered MFA phone number is no longer accessible.
    • Confirmation that the customer controls the custom domain and its DNS zone.
    • Any business or subscription information requested by Microsoft to establish ownership.

    Regarding DNS verification, Microsoft does use DNS records such as TXT or MX records to verify control of a custom domain.

    Please refer to this: Add your custom domain name to your tenant

    However, I would not assume that DNS ownership alone will be sufficient to restore administrative access. The Data Protection/Tenant Recovery team will determine the required verification based on the specific tenant and circumstances.

    I would also avoid sending passwords, MFA codes, or other sensitive information through a public Q&A post. Provide such information only through Microsoft’s official support process when specifically requested.

    Once ownership and identity have been successfully verified, Microsoft can advise whether the appropriate recovery action is to reset the authentication method, restore administrative access, or take another supported recovery action.

    For future prevention, Microsoft recommends maintaining at least two emergency access accounts so that an organization is not dependent on a single administrator’s MFA method.

    Please refer to this document: Manage emergency access accounts in Microsoft Entra ID

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.