Share via

Severity A Situation - Locked out of global admin account (MFA) - business down

SDU 5 Reputation points
2026-03-05T22:43:33.01+00:00

Got a new phone, and can't access my Microsoft Authenticator app from the old phone. Locked out of the account. Business down. There is only one global admin on the account. Have all business documentation and information. @Raja Pothuraju - I need your support immediately on this. Thank you.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-05T22:43:44.78+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Because there is only one global administrator on the tenant and that account is locked behind Microsoft Authenticator, this is a tenant lockout scenario that must be handled by Microsoft’s Data Protection team.

    Action steps:

    1. Collect proof of ownership
      • Have business documentation ready (company details, domain name, admin UPN, subscription info, billing details, etc.). The Data Protection team will use this to verify identity and tenant ownership.
    2. Contact Microsoft by phone and request Data Protection / Tenant Recovery
      • Use the global support phone numbers listed under Customer service phone numbers - Microsoft Support for business products.
      • When the IVR/agent asks about the issue, clearly state:
        • The problem is with Microsoft Authenticator / MFA.
        • The product is Office 365 / Microsoft 365 for business.
        • It is a company (work) account, not personal.
        • The caller is the only Global Administrator and is locked out due to MFA on a lost/replaced phone.
        • A service request is needed and the call must be routed to the Microsoft Data Protection team (sometimes called Tenant Recovery or Data Protection / Tenant Admin MFA reset).
    3. Work with the Data Protection team
      • The Data Protection team has internal tools and processes to:
        • Verify identity and tenant ownership.
        • Reset or clear the MFA registration for the locked global admin.
      • After they reset MFA, sign in again with the existing password and register new authentication methods (Authenticator on the new phone, plus backup methods such as SMS, phone call, or passkey/certificate-based authentication where applicable).
    4. Prevent future lockouts
      • Add at least one additional Global Administrator.
      • Configure emergency access (“break glass”) accounts as described in the emergency access guidance so the tenant is not dependent on a single admin or single device for MFA.

    This scenario (single global admin locked out due to MFA on a new phone) cannot be resolved self-service; escalation to Microsoft Data Protection via support is required.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.