Share via

Stuck in Authentication loop - cannot access Admin Center or anything that flows through Authenticator App

Sloan Dawson 0 Reputation points
2026-06-05T13:07:42.2433333+00:00

Hello. I took out a M365 subscription for my sole proprietor firm; I'm the sole user and admin. Immediately upon updating the domain registry (which is through Squarespace, formerly Google), I've been effectively locked out of any meaningful account setting or management. I tried adding the account to Authenticator on my phone, but it returned an error message about finding an account to complete multi-factor authentication. When I tried to access admin center (or anything but basic account portal), it requires authentication flow through Authenticator app, which of course it can't complete.

A complicating factor is that I have a 365 profile provided by an organization I consult for. Not sure if this would be interfering with anything on the back end?

The AI support line is completely unhelpful, and the one other number I could find for Azure is perpetually busy. Appreciate any advice anyone can provide. My next step is to dispute the subscription charge with my bank and permanently abandon Microsoft.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-05T13:08:18.8566667+00:00

    The account is in an MFA “loop” because Microsoft Entra multifactor authentication is requiring Microsoft Authenticator, but that method is not completing successfully and there is no alternative method available. As the sole admin, self-service recovery is not possible; this must be reset by Microsoft support/Data Protection.

    Use these steps depending on the situation:

    1. Check for any alternative verification methods
    • If any other method (SMS, phone call, another Authenticator account, office phone) was configured, use it:
      • On the sign-in page, when prompted for the code/approval, choose “Sign in another way” and select a different method if it appears.
      • If an alternative method works, sign in and update MFA methods (add Microsoft Authenticator again, and add at least one backup method).
    • If there is no “Sign in another way” link, there are no usable backup methods configured. Proceed to step 2.
    1. If an IT admin exists in the tenant (other than this account)
    • Another global admin can reset MFA for the affected user in Microsoft Entra:
      • Go to Microsoft Entra Admin CenterUsersAll users → select the user.
      • Open Authentication methods and choose Require re-register multifactor authentication.
      • After this, the next sign-in will prompt to set up MFA again (scan QR code in Microsoft Authenticator, then add a backup method such as phone or SMS).
    1. If this is the only admin account (sole proprietor tenant)
    • Microsoft’s Data Protection team must reset the admin’s MFA.
    • Call Microsoft’s global customer service phone numbers (commercial support) and have a frontline agent open a ticket to the Data Protection team:
      • When the IVR asks what the problem is, answer “Authenticator” or “lost access to Authenticator”.
      • When asked what product, answer “Office 365 for business” / Microsoft 365 for business.
      • Confirm it is a company account and that this account is the only administrator.
      • Confirm that a service request is needed and ask to be routed to the Data Protection team to reset admin MFA.
    • Data Protection will verify identity and then reset or re-register MFA for the admin account so that sign-in can complete and new methods can be configured.
    1. If support is hard to reach
    • If phone support cannot be reached or keeps routing incorrectly, create a temporary Microsoft 365 trial tenant:
      • Sign up for a Microsoft 365 trial (business/enterprise) to create a new tenant.
      • Sign in to the Microsoft 365 Admin Center of this new tenant.
      • Use Help & support to open a ticket and clearly state:
        • This is a temporary tenant.
        • The real tenant (with the custom domain) is locked because the only global admin is stuck in an Authenticator MFA loop.
        • Provide the locked tenant’s domain and admin UPN, and request escalation to the Data Protection team to reset MFA on that tenant.
      • After the original tenant is recovered, cancel the trial to avoid charges.
    1. Future prevention
    • Once access is restored:
      • Add multiple MFA methods (Microsoft Authenticator, SMS, phone call, possibly a second device).
      • Ensure at least one additional global admin account or a “break-glass” account is configured with different MFA.
      • Avoid deleting the Authenticator app or accounts; MFA apps must remain installed as long as access is required.

    These are the supported paths to break the MFA loop when the sole admin is locked out; there is no self-service bypass for a business tenant in this state.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.