Sole Global Administrator locked out of Azure/Entra – MFA requires 6-digit code but Authenticator generates 8 digits

Dany Trakhtenberg 0 Reputation points
2026-09-18T14:40:56.86+00:00

I am the sole Global Administrator of my Azure/Microsoft Entra tenant and I am unable to access the Azure portal because of an MFA issue.

Azure asks me to enter a 6-digit code from Microsoft Authenticator. However, when my account was configured as a Personal Microsoft Account in Authenticator, it generated an 8-digit code, which Azure does not accept.

I removed that account from Authenticator and attempted to add it as a Work or school account, but Microsoft reports that I cannot sign in there with a personal account.

I also tried signing in using an Incognito/InPrivate browser, but the problem is the same. The Azure authentication screen provides no “Sign in another way” option and returns error code 500121 when an incorrect verification code is entered.

I cannot access the Azure portal, Entra admin center, or Security Info page to re-register Microsoft Authenticator. There is also no other Global Administrator in the tenant who can reset my MFA authentication methods.

This appears similar to other sole Global Administrator tenant-lockout cases where the Microsoft Data Protection team had to reset the MFA registration.

Could a Microsoft moderator please help me initiate a tenant lockout / Data Protection recovery case so that I can regain access and re-register Microsoft Authenticator?

I can provide my affected administrator account, contact email, phone number, country, time zone, tenant/subscription information, and other verification information privately if required.

Microsoft 365 and Office | Subscription, account, billing | For business | Windows
0 comments No comments

3 answers

Sort by: Most helpful
  1. Teddie Dang 1,365 Reputation points Independent Advisor
    2026-09-29T03:34:20.3766667+00:00

    Hi @Dany Trakhtenberg

    It seems you have already attempted to contact Microsoft Support several times but have been unable to get past the automated system.

    If you have not already tried it, you could use the following script as an example:

    Q. Can you tell me if you are calling as a home user who uses a product or service at home or a business user who uses it in your business to provide the best assistance? 
    A.I am a business user. 
    Q. Thank you. Can you give me the details of your inquiry? 
    A. Login technical support. 
    Q. First of all, can you tell me which products you are inquiring about today? 
    A. Microsoft 365 business Standard。 
    Q. Please wait a moment, I understand Microsoft 365. Are you calling about a new case or an existing one? 
    A. New. 
    Q. To receive phone support, your phone number must be associated with your Microsoft 365 admin profile. To do this, go to aka.ms/m365profile. Again, it aka.ms/m365profile . This can take 48 hours. In the meantime, you can go to aka.ms/m365profile and file a case online. If you prefer, you can also text the link to the phone number you are calling. What do you think? 
    A. The phone number is already linked to the link. 
    Q. Can you tell me about the products in your inquiry? 
    A. Microsoft 365 Business Standard. 
    Q. Are you a Global Administrator? 
    A. That's right. 
    Q. I'm sorry. I didn't understand. Are you a global administrator for your domain? 
    A. Yes, I am a global administrator for the domain. 
    Q. If you have any inquiries, you can contact a Microsoft representative. Are you sure? 
    A. Yes. Please. 
    Q. Yes, I understand. Please wait a moment.
    

     In case the phone line is not supportive, you can consider directly submitting a support request as a helpful workaround:    

    -Create a temporary Microsoft 365 tenant using a trial license: Go to Microsoft 365 Business Plans and Pricing and click Try for free to set up a temporary Microsoft 365 tenant with a trial license.    

    -Use this new account to sign in to the Microsoft 365 Admin Center and submit a support request on behalf of your primary (locked) account.   

    -Click Help & Support > then choose Create a support request.    

    Note: This method doesn't require you to use your new account for your business. Instead, it allows you to create a temporary global administrator account so you can submit a support request, as your original global administrator account is locked out due to issues with multi-factor authentication. The trial account is free for one month. Be sure to delete it after submitting your support request to avoid any automatic renewals or charges from Microsoft.     

    For further instructions, you can follow this guide: Get support - Microsoft 365 admin | Microsoft Learn.   

    Since this is a user-to-user support forum, I do not have access to internal databases or the ability to escalate cases directly to Microsoft’s internal teams. Therefore, please kindly contact the Microsoft Support team for the most efficient help.   

    Was this answer helpful?


  2. Dany Trakhtenberg 0 Reputation points
    2026-09-19T15:05:09.2366667+00:00

    Thank you. Since I am unable to create an Azure support ticket because the Azure portal itself requires the MFA method that I no longer have, how can I initiate the Data Protection/Tenant Recovery case?

    Could a Microsoft moderator please assist with opening/escalating the tenant lockout case? I can provide my contact details and affected Global Administrator account privately.

    Was this answer helpful?

    0 comments No comments

  3. Levi Cornwell 255 Reputation points
    2026-09-18T15:59:53.6533333+00:00

    The 8-digit code is actually an important clue. Microsoft Authenticator uses different registration types, and the 8-digit code is associated with a Personal Microsoft Account, while the Entra work/school account uses the 6-digit verification code.

    Normally, you could re-register the account under Work or school account, but in this case you are the sole Global Administrator and you cannot access Security Info to fix the registration. Since there is also no "Sign in another way" option, this is effectively a tenant lockout.

    I would not keep trying to add/remove the account in Authenticator. Microsoft has handled similar sole-Global-Admin cases by escalating them through Support to the Data Protection/Tenant Recovery team, who can verify tenant ownership and help restore the administrator's access.

    When contacting Microsoft Support, clearly state that this is a sole Global Administrator tenant lockout, MFA error 500121, no other Global Administrator, and no usable alternate authentication method, and request escalation to Data Protection/Tenant Recovery.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.