Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
Dear @Matthias Olofsson
I understand the situation. Since the existing MFA method is tied to an unavailable phone number, there is no available administrator who can reset the authentication method, and the previous GDAP relationship has expired, this should be handled as a tenant/admin access recovery case.
In this situation, I would recommend contacting Microsoft Support and specifically requesting escalation to the Microsoft 365 Data Protection/Tenant Recovery team. Microsoft has indicated that when the only Global Administrator is locked out and no other administrator can reset MFA, recovery must go through the appropriate Microsoft support process rather than bypassing MFA.
You can provide Microsoft with the following information:
- The affected tenant name/tenant ID and administrator UPN.
- The name of the user/account that is locked out.
- Confirmation that there are no other available Global Administrators.
- Confirmation that the registered MFA phone number is no longer accessible.
- Confirmation that the customer controls the custom domain and its DNS zone.
- Any business or subscription information requested by Microsoft to establish ownership.
Regarding DNS verification, Microsoft does use DNS records such as TXT or MX records to verify control of a custom domain.
Please refer to this: Add your custom domain name to your tenant
However, I would not assume that DNS ownership alone will be sufficient to restore administrative access. The Data Protection/Tenant Recovery team will determine the required verification based on the specific tenant and circumstances.
I would also avoid sending passwords, MFA codes, or other sensitive information through a public Q&A post. Provide such information only through Microsoft’s official support process when specifically requested.
Once ownership and identity have been successfully verified, Microsoft can advise whether the appropriate recovery action is to reset the authentication method, restore administrative access, or take another supported recovery action.
For future prevention, Microsoft recommends maintaining at least two emergency access accounts so that an organization is not dependent on a single administrator’s MFA method.
Please refer to this document: Manage emergency access accounts in Microsoft Entra ID