I have locked myself (GA) out of my Azure tenant and I am unable to reload my authenticator app.

Angelo Parente 0 Reputation points
2024-07-30T09:19:26.28+00:00

I have locked myself (GA) out of my Azure tenant and I am unable to reload my authenticator app.

I have my GA account details (email & password) but I am unable to access my Authenticator App so logon is a continuous loop. I also have my Tenant & Subscription ID's. Is there anyway I can regain access to my environment?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sandeep G-MSFT 20,926 Reputation points Microsoft Employee Moderator
    2024-07-30T12:24:58.03+00:00

    @Angelo Parente

    Thank you for posting this in Microsoft Q&A.

    As I understand you are unable to access your Authenticator app, due to this you are unable to login to Azure portal.

    This means your account is locked out for Azure login.

    In this situation there are only 2 option that you can try,

    • Contact another global admin of the tenant and ask them to make your account to re-register for MFA. They can perform this by following below steps, Contact any global admin from the list and ask him to perform below steps to reset your MFA so that you can re-register for authenticator app.   • Admin has to login to Azure portal and access Azure active directory. • Once done they have to go to users blade on the left. • Click on Authentication methods and click on “Require re-register multifactor authentication”. • Now when you try to login to Azure services it will prompt you to register for MFA again.
    • If you are the only global admin on the account and are blocked entirely, you can reach out to our support team. You can look into below article to get support numbers depending on your country. https://support.microsoft.com/en-us/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2 or creating a ticket through a different account:  https://learn.microsoft.com/en-us/microsoft-365/admin/get-help-support?view=o365-worldwide#phone-support Create a ticket with Microsoft support team. Give them the tenant ID which is locked out in your description. Tell them that no admin account has access anymore and your partners also have no access anymore. Once you create a ticket with support team you will have to work with our data protection team. You will have to first prove your identity against your tenant for security purpose. Post that this team will help you with help you in getting access to your tenant or unlock your account depending on your scenario. Also, for the future, you can create an emergency access account (break glass) in Azure AD. This account will help prevent being accidentally locked out of your Azure Active Directory (Azure AD) organization because you can't sign in for any reason. https://docs.microsoft.com/en-us/azure/active-directory/roles/security-emergency-access

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.