Share via

Please help reset MFA and verify ownership of the domain.

PhuocPH 0 Reputation points
2026-03-22T09:45:33.9233333+00:00

I am the Global Administrator of tenant bctech.edu.vn. My account is ******@bctech.edu.vn

Currently, I am locked out due to MFA (Microsoft Authenticator not showing passcode or approval request).

I no longer have access to the configured authentication methods.

This is the only Global Admin account, and I need to regain access to manage the organization.

Please help reset MFA and verify ownership of the domain.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-22T09:45:46.78+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    MFA for the only Global Administrator cannot be reset directly from portals when locked out. Recovery must go through Microsoft support and the Data Protection/Tenant Recovery process so identity and domain ownership can be verified.

    Follow these steps:

    1. Prepare proof of ownership
      • Collect official business documentation for the organization (registration documents, tax certificates, etc.).
      • Ensure access to email addresses and evidence that the organization owns the domain bctech.edu.vn (for example, domain registrar records or DNS control).
    2. Open a Microsoft support ticket for tenant lockout
      • Go to the Microsoft global support phone numbers page: Customer service phone numbers - Microsoft Support.
      • Call the number for the region and clearly state:
        • This is a tenant lockout.
        • The account is the only Global Administrator.
        • MFA methods are no longer accessible (Authenticator not providing code/approval).
        • Assistance is needed from the Data Protection team to reset admin credentials/MFA and verify ownership of the tenant and domain.
    3. Ask specifically for Data Protection / Tenant Recovery
      • During the call, request creation of a service request and escalation to the Data Protection team.
      • Explain that no other global admin exists who could use “Require re-register multifactor authentication,” so self-service or admin-based reset is impossible.
      • Follow their instructions to submit required documentation and complete identity verification.
    4. What Microsoft’s Data Protection team can do
      • According to the documented process, when locked out of a tenant with no other global admin, the Data Protection team can:
        • Reset credentials of an administrator account.
        • Help claim or confirm ownership of the tenant.
      • After verification, they will reset MFA/credentials so sign-in can be completed and new authentication methods (including a new Authenticator registration) can be configured.
    5. If the tenant is associated with an unmanaged or partner-created directory
      • If a Microsoft partner or reseller manages the tenant, contact that partner and ask them to open a support ticket on behalf of the organization for tenant lockout/MFA reset.
      • If the domain is tied to an unmanaged directory, a global admin can perform an admin takeover after access is restored, as described in the admin takeover guidance.

    Until Microsoft completes verification and resets the admin’s MFA/credentials, access cannot be restored by any portal or self-service flow.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.