A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the only Global Administrator is locked out by MFA and there is no other admin who can reset the authentication methods, recovery must go through Microsoft’s Data Protection / Tenant Recovery process. Forum moderators and tools outside Microsoft support cannot directly reset MFA or restore access.
Follow these steps:
- Confirm there is no other admin who can reset MFA
- If there is any other Global Administrator or Privileged Authentication Administrator in the tenant, that admin should:
- Sign in to the Microsoft Entra admin center (
https://entra.microsoft.com). - Go to Users > All users and select the locked-out admin account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- The next sign-in for that admin will prompt for MFA setup again, allowing registration of a new device/method.
- Sign in to the Microsoft Entra admin center (
- If such an admin exists and performs these steps, no Microsoft support escalation is required.
- If there is any other Global Administrator or Privileged Authentication Administrator in the tenant, that admin should:
- If you are the only Global Admin (tenant lockout)
When there is no other admin with rights to reset MFA, this is treated as a tenant lockout. In this case, only Microsoft support (Data Protection team) can help:- Call Microsoft global customer service using the phone number for the country/region from:
- When connected to the IVR/agent, clearly state:
- This is a Microsoft 365 for business / company account.
- The caller is the only Global Administrator for the tenant.
- The admin is locked out due to Microsoft Authenticator / MFA and cannot access the admin portal to open a ticket.
- A Data Protection / Tenant Recovery case is needed to reset MFA methods for the tenant admin.
- Work with the support agent to pass verification. The Data Protection team will validate tenant ownership (they may use domain email, business documentation, etc.) and then reset the MFA registration for the admin account.
- After MFA is reset, sign in again with the existing password and complete MFA registration on the new device.
- Alternative path if unable to reach a live agent
If it is impossible to reach an agent directly via phone in the region:- Create a temporary new tenant by signing up for a Microsoft 365 trial subscription.
- From that new tenant’s admin center, open a support ticket and request to speak with the Data Protection team on behalf of the locked-out tenant, explaining that the original tenant’s only Global Admin is locked out by MFA.
- Support can then route the case appropriately and proceed with verification and MFA reset for the original tenant.
- Future prevention once access is restored
After regaining access:- Add at least one additional Global Administrator or Privileged Authentication Administrator so that a future lockout can be resolved internally.
- Configure multiple MFA methods (e.g., Microsoft Authenticator on more than one device, phone, or other supported methods) to avoid a single point of failure.
- Follow the security guideline to keep the number of Global Administrators low, but ensure at least one other admin can reset a Global Admin’s password or MFA.
References:
- About administrator roles in the Microsoft 365 admin center
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Common problems with two-step verification for a work or school account
- Preventing tenant lockouts
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Mandatory multifactor authentication for Azure and admin portals