How can I assign the Global Administrator role if the main admin account is blocked?

Moazzem Hossain 0 Reputation points
2024-12-11T06:50:45.8866667+00:00

Our primary Global Administrator account is blocked, and no other accounts currently have the Global Administrator role. We urgently need to assign this role to an active account to manage Azure AD effectively. Are there any steps or alternatives to resolve this issue, such as using another admin role, contacting Microsoft support, or any tools available? Any guidance would be appreciated.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andreas Baumgarten 123.8K Reputation points MVP Volunteer Moderator
    2024-12-11T07:43:44.43+00:00

    Hi @Moazzem Hossain ,

    the best option might be to create a support request with Microsoft in the Microsoft Entra Id admin center or the Azure Portal. Navigate to Help + support an create a support request.

    User's image

    On the page Recommended solutions click on Return to support request.

    User's image

    On the following page add required information and submit the request.


    Kind regards

    Andreas Baumgarten

    0 comments No comments

  2. Sandeep G-MSFT 20,921 Reputation points Microsoft Employee Moderator
    2024-12-12T06:04:00.43+00:00

    @Moazzem Hossain

    Thank you for posting this in Microsoft Q&A.

    As I understand in your organization primary Global admin has been blocked. Currently you do not have any admin to manage your Entra ID as there are no Global admins. You want to know if any other admin can assign Global admin role to anyone else.

    Yes, you can get the Global admin role assigned to some other account only if you can login with account which has Privileged Role Administrator

    This role has an ability to assign Global admin role to any other account within Entra ID.

    If you do not have any other account with Privileged Role Administrator, then the only option is to contact support and data protection team to unblock your Global admin account.

    If you are the only global admin on the account and are blocked entirely, you can reach out to our support team. You can look into below article to get support numbers depending on your country.

    https://support.microsoft.com/en-us/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2

    or creating a ticket through a different account:  https://learn.microsoft.com/en-us/microsoft-365/admin/get-help-support?view=o365-worldwide#phone-support

    Create a ticket with Microsoft support team. Give them the tenant ID which is locked out in your description. Tell them that no admin account has access anymore and your partners also have no access anymore.

    Once you create a ticket with support team you will have to work with our data protection team. You will have to first prove your identity against your tenant for security purpose. Post that this team will help you with help you in getting access to your tenant or unlock your account depending on your scenario.

    Also, for the future, you can create an emergency access account (break glass) in Azure AD. This account will help prevent being accidentally locked out of your Azure Active Directory (Azure AD) organization because you can't sign in for any reason.

    https://docs.microsoft.com/en-us/azure/active-directory/roles/security-emergency-access

    Let me know if you have any further questions on this.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.