I accidentally change my only user type to 'internal' now I cannot access my tenant or change settings

INFO WOW 0 Reputation points
2024-07-23T07:42:38.26+00:00

I accidentally change my only user type to 'internal' ,

After that I cannot undo, and not able to access Microsoft Entra ID menu at all.

The selected user account doesn't exist in the tenant 'Microsoft Services' and cannot access the application '631d36ba-ddbd-4e88-807a-b8cd54f9b390' in this tenant. This account needs to be added first as an external user in the tenant. Please use a different account.

{
  "sessionId": "1a96a6e96e974493b425f3e1496df3ab",
  "errors": [
    {
      "errorMessage": "interaction_required: AADSTS160021: Application requested a user session which does not exist. Trace ID: 1e3729ff-e756-4977-a6f7-159cc2867500 Correlation ID: 250da985-fea5-40fb-9cf8-c557b5e23615 Timestamp: 2024-07-23 07:47:42Z",
      "clientId": "74658136-14ec-4630-ad9b-26e160ff0fc6",
      "scopes": [
        "a57aca87-cbc0-4f3c-8b9e-dc095fdc8978/.default"
      ]
    }
  ]
}

How Can I gain access again??

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,908 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,066 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sandeep G-MSFT 19,761 Reputation points Microsoft Employee
    2024-07-24T08:18:48.7833333+00:00

    @INFO WOW

    Thank you for posting this in Microsoft Q&A.

    In this situation you will have to contact your global admin of the resource tenant to get your account converted to external account.

    If you are the only global admin on the account and are blocked entirely to use Entra ID services, you can reach out to our support team. You can look into below article to get support numbers depending on your country.

    https://support.microsoft.com/en-us/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2

    or creating a ticket through a different account:  https://learn.microsoft.com/en-us/microsoft-365/admin/get-help-support?view=o365-worldwide#phone-support

    Create a ticket with Microsoft support team. Give them the tenant ID which is locked out in your description. Tell them that no admin account has access anymore and your partners also have no access anymore.

    Once you create a ticket with support team you will have to work with our data protection team. You will have to first prove your identity against your tenant for security purpose. Post that this team will help you with help you in getting access to your tenant or unlock your account depending on your scenario.

    Also, for the future, you can create an emergency access account (break glass) in Azure AD. This account will help prevent being accidentally locked out of your Azure Active Directory (Azure AD) organization because you can't sign in for any reason.

    https://docs.microsoft.com/en-us/azure/active-directory/roles/security-emergency-access

    Let us know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.