Share via

MFA Error Code 500121

SDU 5 Reputation points
2026-03-05T22:38:11.72+00:00

I'm encountering an issue with authentication and need assistance resolving it. Below are the details of the error:

Error Code: 500121

The Authenticator wont show us a code to log in to our main account.

We cant reach support because we cant log in.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-05T22:38:27.3866667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Error 500121 indicates a problem completing Microsoft Entra multifactor authentication (MFA). In this scenario, the Microsoft Authenticator app is not providing a usable verification method and there is no way to reach support from within the tenant because sign-in is blocked.

    Use the appropriate path based on whether there is another admin in the tenant.

    1. If there is another Global Admin in the tenant That admin can reset MFA so the affected account can re-register the Authenticator app:
      1. Another Global Admin signs in to the Azure portal / Microsoft 365 admin portal.
      2. Open Microsoft Entra ID → Users.
      3. Select the affected user account.
      4. Go to Authentication methods.
      5. Select Require re-register multifactor authentication.
      6. Save the change.
      7. The affected user signs in again and is prompted to set up MFA from scratch on the Authenticator app (and/or add a phone number or other methods).
      This is the standard way to recover when the Authenticator app no longer works but at least one other admin still has access.
    2. If the locked-out account is the only Global Admin In this case, self-service recovery from the portal is not possible. The tenant must be recovered by Microsoft’s Data Protection / Tenant Recovery team via a support request from outside the locked tenant. Use one of these options: Option A – Call Microsoft support (recommended)
      • Call the regional Microsoft customer service phone number listed in the “Customer service phone numbers - Microsoft Support” page.
      • When prompted by the automated system, clearly indicate:
        • The issue is with Authenticator / MFA.
        • The product is Office 365 / Microsoft 365 for business.
        • It is a company / work account.
        • Confirm being the administrator and that there is no other administrator.
        • Request creation of a service request with the Data Protection (Tenant Recovery) team to reset MFA for the tenant admin account.
      • Be prepared to provide tenant details (admin sign-in name, domain, business information) so Microsoft can verify identity and ownership.
      Option B – Create a temporary trial tenant to open a ticket If it is not possible to reach a live agent directly:
      1. Sign up for a new Microsoft 365 trial tenant (separate from the locked tenant).
      2. In the new tenant, go to the Microsoft 365 admin center → SupportHelp & support.
      3. Open a support ticket explaining that:
        • There is a different, existing tenant where the only Global Admin is locked out due to MFA / Authenticator issues.
        • MFA is required and the only registered method was Microsoft Authenticator, which is no longer accessible.
        • Request escalation to the Data Protection team to reset MFA registration for the original tenant’s admin account.
      4. Provide the locked tenant’s admin UPN, tenant domain, and any error messages (including 500121) in the ticket.
      5. After recovery, cancel the trial tenant if it is no longer needed.

    These are the supported recovery paths when the Authenticator app does not provide a code and sign-in is blocked, especially for single-admin tenants.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.