Share via

Only Global Admin locked out – MFA / Authenticator not receiving notifications

Marko Manenica 0 Reputation points
2026-02-27T03:26:08.03+00:00

I am the only Global Administrator for our Microsoft 365 / Entra ID tenant. I am unable to sign in because Microsoft Authenticator push notifications are not arriving. There are no other admins who can reset my authentication methods. I need Microsoft Data Protection Team assistance to reset/bypass MFA so I can regain admin access.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Doris V 1,190 Reputation points Microsoft External Staff Moderator
    2026-02-27T04:15:59.4466667+00:00

    Hi @Marko Manenica,

    Thank you for reaching out to the Microsoft Q&A forum.

    Since you are the only Global Administrator and are completely locked out due to MFA, this situation cannot be resolved through the community. Direct Microsoft Support assistance is required.

    Please proceed with one of the following options:

    Option 1: Contact Microsoft Support by Phone (Recommended)

      + Issue: Authenticator / MFA / Password reset

      + Product: Microsoft 365

      + Role: Admin

      + Clearly explain that:

    • You are the only Global Administrator
    • You are locked out
    • Password reset is not working
    • No other admin exists in the tenant
    • Data Protection Team verification is required

    Microsoft will need to verify tenant ownership before restoring access.

    Option 2: Create a Temporary Trial Tenant (If Phone Support Is Unavailable)

    • Start a Microsoft 365 free trial
    • Sign in to the Admin Center of the trial tenant
    • Go to Support → Help & Support
    • Create a service request
    • In the request, include:

      + Blocked admin email address

      + Affected domain name

      + Any error messages

      + Confirmation that you are the only administrator

    Microsoft will complete formal ownership verification before making changes.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".   

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Q&A Assist
    2026-02-27T03:26:22.11+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Because there is only one global admin on the tenant and multifactor authentication cannot be completed, this is a tenant lockout scenario that requires Microsoft support (Data Protection team) to restore access. There is no self-service way to bypass or reset MFA in this situation.

    Follow these steps to proceed:

    1. Contact Microsoft support by phone
      • Call the appropriate regional support number listed under Customer service phone numbers - Microsoft Support.
      • When connected to the IVR/agent, clearly state:
        • The issue is admin locked out due to MFA / Microsoft Authenticator not working.
        • This is a business / Microsoft 365 for business / company account.
        • There is no other global administrator on the tenant.
        • A Data Protection / Tenant Recovery / Microsoft 365 Data Protection team escalation is required to reset MFA for the only global admin.
    2. Work with the Data Protection team
      • The frontline agent should create a support request and route it to the Data Protection team (sometimes referred to as Microsoft 365 Data Protection or Tenant Recovery).
      • Be prepared to provide tenant and ownership verification information (company details, domain, subscription info, etc.) as requested.
      • The Data Protection team will work with you to:
        • Verify ownership of the tenant.
        • Reset or clear the MFA requirement for the global admin account so that sign-in is possible again.
    3. After access is restored
      • Sign in as global admin and reconfigure MFA methods with redundancy:
        • Register Microsoft Authenticator on the current device.
        • Add at least one backup method (phone call, SMS, or another app/device) via https://aka.ms/mysecurityinfo.
      • Consider adding at least one additional global admin so that MFA resets can be performed internally in the future.

    If the support line in your region routes through automated prompts, answer along the lines of:

    • Problem: “Authenticator” or “Can’t sign in – admin account.”
    • Product: “Office 365 for business” / “Microsoft 365 for business.”
    • Account type: “Company account.”
    • Are you an administrator?: “Yes.”
    • Do you have another administrator?: “No.”
    • Request: “Yes, I need to create a ticket and speak with the Data Protection team to restore access to my tenant.”

    Forum moderators and documentation cannot directly reset or bypass MFA; only Microsoft support (Data Protection team) can handle this tenant lockout scenario.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.