Sole admin of tenant, have lost access to the authenticator app and unable to login azure portal

Nandhini Velu 16 Reputation points
2021-04-07T09:04:03.68+00:00

I created one tenant in azure account and using that for my work. I am the sole admin of that tenant. The only 2FA options I have to log in are via the authenticator app, which I now can't do. Even i am not able to change tenant for the subscription. Please help me to resolve this issue.

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
5,486 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,457 questions
0 comments No comments
{count} vote

5 answers

Sort by: Most helpful
  1. Antonio Arias Sánchez 6 Reputation points
    2022-11-30T16:07:59.103+00:00

    Hello, had the same problem.

    What you need to do, to be able to login to your home tenant, is just add the domain name (onmicrosoft.com or main one if set):

    https://portal.azure.com/{your tenant}

    eg. https://portal.azure.com/contoso.com or
    https://portal.azure.com/contoso.onmicrosoft.com

    Hope that helps!

    1 person found this answer helpful.

  2. SUNOJ KUMAR YELURU 13,926 Reputation points MVP
    2021-04-07T09:27:53.703+00:00

    Hi @Nandhini Velu

    Refer the below URL, if this helps your request.

    Change your two-factor verification method and settings

    To setup QR verification on the mobile, follow the below steps

    1. Sign in to https://myapps.microsoft.com using your azure ID.
    2. Select your account name in the top right, then select profile
    3. Select additional security verification
      85186-image.png
    4. Add a new account to the Microsoft authenticator app – follow steps from the below URL
      https://learn.microsoft.com/en-us/azure/active-directory/user-help/multi-factor-authentication-end-user-manage-settings

    If the Answer is helpful, please click Accept Answer and up-vote, this can be beneficial to other community members.


  3. AmanpreetSingh-MSFT 56,306 Reputation points
    2021-04-07T11:30:35.697+00:00

    Hi @Nandhini Velu · Welcome to QnA platform and thank you for reaching out.

    The recommendation is to always keep break-glass admin account, by excluding one or more global admins so that you can revert the settings. However, if you forgot to keep a breakglass account, the only option is to open a support ticket to get Microsoft Data Protection team engaged for this issue. If you are unable to sign into your tenant, you can use any other tenant or signup for a new one to open a support ticket.

    After providing required information and evidence to prove the company ownership on the subscription, they can help you with providing admin access to your tenant.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

  4. Hal Yaman 1 Reputation point
    2021-11-22T00:52:39.767+00:00

    We have been facing the same issue for the last five days; the support doesn't understand how critical this issue is. As a result, we are unable to access our DevOps, Emails, Azure subscription. More strangely, the MFA has never been set up on our subscription.

    Now I'm spending my time trying to convince MS support how critical the situation is :(.

    I appreciate any help you can provide.


  5. Chris Ma 1 Reputation point
    2022-02-25T11:17:34.323+00:00

    We have the same problem, which is quite frustrating.

    i created a B2C domain on side of our Azure active directory for testing. at this B2C domain i am the only admin and user , also domain is with MFA active. By switching Phone i lost Authedicator App. Now i cannot log in to this Domain. it's OK. but I can log in to the my Azure active directory no problem at all.

    But huge problem is at on Visual Studio, when i want to connect a service from Azure, always ask me the MFA by logging, but i do not have any MFA on my orginal Azure Active Directory, always link to the B2C domain MFA, very frustrating.

    I do not need to logging with B2C domain, any Suggestion instead of Ticket!?