Share via

Global admin locked out due to MFA.

Leonardo Azzini 0 Reputation points
2026-03-06T11:15:06.4866667+00:00

Authenticator app shows the account but does not generate codes or approval prompts.

Tenant: azzini.onmicrosoft.com

User: <Mod remove PII> @azzini.onmicrosoft.com

Request: reset MFA for the global admin account.

I have already tried all the suggestions found online. AI indicates the only solution is to reset MFA.

How i can do.

Thanks

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-06T11:15:24.32+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Because the global admin is locked out by MFA and the Authenticator app no longer works, the MFA registration must be reset by one of the supported recovery paths.

    Use the option that matches the situation:

    1. If there is another Global Administrator in the tenant
      1. Another global admin signs in to the Microsoft Entra admin center.
      2. Go to Users → All users and select the locked-out global admin account.
      3. Open Authentication methods.
      4. Select Require re-register multifactor authentication.
      5. The next time the locked-out admin signs in, the portal will prompt to set up MFA again (re‑pair Microsoft Authenticator or another method).
    2. If there is no other Global Administrator (only one global admin on the tenant) In this case, tenant recovery must be handled by Microsoft’s Data Protection team via a support request:
      1. Call Microsoft using the appropriate Customer service phone numbers for the region.
      2. When connected to support/IVR, clearly state:
        • The issue is a tenant admin MFA lockout.
        • The caller is the only global administrator for the tenant.
        • A reset of MFA registration for the global admin is required.
        • Ask to be routed to the Data Protection / Tenant Recovery team.
      3. Follow the verification steps requested by the Data Protection team (they will validate tenant ownership and then reset the admin’s MFA methods so a new Authenticator registration can be completed).
    3. If no phone support is reachable As an alternative (from the Q&A guidance), create a temporary Microsoft 365 trial tenant, sign in as its admin, and open a support ticket from that tenant’s admin center requesting help from the Data Protection team to recover the original tenant where the global admin is locked out.

    Until MFA is reset by another global admin or by Microsoft Support/Data Protection, the locked-out global admin will not be able to sign in, even if the password is correct.


    References:

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.