Share via

How to access Azure when I am sole user and I changed the phone which has authenticator and I do not use my phone number for MFA.

vishal kumar 45 Reputation points
2026-03-06T00:05:06.8066667+00:00

I am the only Global Administrator in my Azure AD.

I recently changed my phone and but I am not getting notofication on new phone Microsoft Authenticator app.

I did not set up any alternate phone number, backup email, recovery codes, or additional admin accounts.

When attempting to sign in, it loops endlessly asking for an authenticator code I can’t provide.

I cannot access any portal or service to open a support ticket.

What I've tried so far:

  • Signing in → “Use a different verification option” → “I don't have any of these,” which leads nowhere
  • Contacting support via bot and global phone numbers, but cannot create a case because I’m locked out . This appears to be a tenant lockout scenario (only admin lost MFA), where only Microsoft’s Data Protection / Identity Verification team can intervene .

Request:

Please advise on the official process to regain access.

Regards

Vishal

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author
  1. Rukmini 35,245 Reputation points Microsoft External Staff Moderator
    2026-03-06T00:08:11.13+00:00

    Hello vishal kumar

    The issue pertains to a tenant lockout, where no other global admin in the tenant has the necessary permissions to login and make changes in your tenant.

    To resolve this, we have engaged our Data Protection team through a support ticket. They will reach out to you via email or phone to help restore access to the tenant and assist in resolving the issue.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Alex Burlachenko 19,850 Reputation points MVP Volunteer Moderator
    2026-03-06T11:38:36.84+00:00

    hi vishal kumar,

    this is a classic tenant lockout scenario and unfortunately there is no technical trick to fix it from ur side because u are the only Global Admin and u lost the only MFA method tied to that account. Azure will not let u bypass MFA even if u prove u know the password, that is by design. Since there are no backup methods or additional admins, the only path is through Microsoft identity verification. U need to contact Microsoft support through the account recovery or billing support channel and explain that this is a sole Global Admin lockout case, it usually gets routed to the Data Protection team who will verify ownership of the tenant. They will ask for proof like subscription details billing information domain ownership or company documentation before they reset MFA or grant temporary access. There is no self service recovery in this situation. For the future always have at least two Global Admins and multiple MFA methods configured because Azure treats single admin with single MFA device as high risk. Right now the only real solution is to go through Microsoft support identity verification process.

    rgds,

    Alex

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.