Share via

Admin locked out due to MFA requirement

Stephanie Piquette 0 Reputation points
2026-03-07T16:21:19.3333333+00:00

Admin locked out because MFA required but authenticator was never configured
Reset MFA for admin account ******@spconsultation.ca

I am the administrator of the Microsoft 365 tenant for the domain spconsultation.ca. When attempting to sign in with the account ******@spconsultation.ca, I am required to enter a code from the Microsoft Authenticator app. However, the Authenticator app was never configured for this account, so I cannot generate the required code. As a result, I am locked out and unable to access the security settings to configure MFA.

I still have access to Outlook with this account on my computer, but any attempt to access security settings or the admin portal requires the MFA code.

Could you please reset or disable the MFA requirement for this admin account so that I can sign in and properly configure the authentication methods?

Tenant domain: spconsultation.ca

Admin account: ******@spconsultation.ca

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-07T16:21:33.11+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    MFA for the admin account cannot be reset or disabled directly here. The recovery path depends on whether there is another Global Administrator in the tenant.

    1. If there is another Global Administrator
      • That admin must sign in to the Azure portal and go to Microsoft Entra ID → Users.
      • Select the locked-out admin account.
      • Open Authentication methods and select Require re-register multifactor authentication.
      • Next time the locked-out admin signs in, the portal will prompt to set up MFA again and allow configuration of Microsoft Authenticator or another method.
    2. If this is the only Global Administrator
      • This is a tenant lockout scenario. MFA reset must be handled by Microsoft’s Data Protection/Tenant Recovery team.
      • Call Microsoft using the Customer service phone numbers - Microsoft Support channel and clearly state:
        • The issue is loss of access due to MFA on a Microsoft 365 for business / company account.
        • The caller is the only Global Administrator for the tenant.
        • MFA was never successfully configured and now blocks sign-in.
      • Ask the agent to open a Data Protection / Tenant Recovery ticket to verify identity and reset the admin’s authentication methods.
      • Be prepared to provide tenant and identity verification information as requested.
    3. If support is hard to reach
      • As an alternative, create a new temporary Microsoft 365 tenant using a trial subscription.
      • From that new tenant’s Microsoft 365 admin center, open a support ticket and request to speak with the Data Protection team on behalf of the locked tenant, providing:
        • The locked tenant’s domain (spconsultation.ca).
        • The locked admin UPN.
        • Error messages and a description that MFA was never configured but is now required.

    Forum moderators and tools outside Microsoft support cannot reset or disable MFA on the account. Only another Global Administrator or Microsoft’s Data Protection team can perform the necessary reset.


    References:

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.