Share via

Recover Global Admin Microsoft account with lost MFA Access lockout

Hugo Deleon Dias 10 Reputation points
2026-03-25T16:01:00.5066667+00:00

Hello, I am unable to get logged back into one of my tenants as a global administrator because my Microsoft Authenticator app was reset and I found out my tenant only had this form of verification configured on the global admin account. I do not have any other global administrator accounts so I am currently experiencing a total lockout.

  • Contact phone number (add +Country code): PII
  • Contact email address: PII
  • Global admin email address (affected account): PII
  • Country:PII
  • TimeZone: PII
Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-25T16:01:48.5+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Because the only global administrator is locked out by MFA and there are no other admins who can reset the authentication methods, this is a tenant lockout scenario that must be handled by Microsoft support/Data Protection.

    Follow these steps:

    1. Try self‑service options first (if any other methods exist)
      • If there is any chance another MFA method or security info is still available (phone, email, alternate app), start sign‑in and, at the Verify your identity prompt, choose any available method.
      • If prompted and applicable, select I don't have any of these and follow the instructions to replace security info. Be aware this can trigger a 30‑day restriction before sign‑in is fully restored.
      • If you know the password but have lost all security info, follow the guidance under I've lost access to my security info for work or school accounts: begin sign‑in, select I don't have any of these, and complete the replacement process.
    2. If no MFA/security info method works and you remain locked out
      • This is the case described in the Microsoft Q&A threads where the only global admin loses access to Microsoft Authenticator and cannot complete MFA.
      • In such cases, recovery requires Microsoft’s Data Protection/Tenant Recovery team to verify tenant ownership and reset the MFA registration for the global admin.
    3. Contact Microsoft support by phone (primary path)
      • Call Microsoft 365 commercial support using the regional phone number listed under Customer service phone numbers - Microsoft Support for Brazil.
      • When connected to the IVR/agent, clearly state:
        • This is a Microsoft 365 for business / company account.
        • You are the only global administrator for the tenant.
        • You know the password but are locked out by MFA because Microsoft Authenticator was reset and it was the only configured method.
        • You need to create a service request with the Data Protection/Tenant Recovery team to reset the admin’s MFA methods.
      • Be prepared to provide business documentation and proof of domain/tenant ownership as requested.
    4. Alternative path if phone support is difficult to reach
      • As described in the Q&A guidance, if reaching a live agent is problematic, create a temporary trial Microsoft 365 tenant (with a different domain), sign in to its admin center, and open a support ticket from there.
      • In that ticket, request escalation to the Data Protection team for MFA reset on the original tenant, providing the affected tenant name and global admin UPN.
    5. After Microsoft completes verification
      • The Data Protection team will reset or clear the MFA registration for the global admin account on the locked tenant.
      • Sign in again with the global admin username and password; you should then be prompted to set up MFA from scratch.
      • Configure multiple methods (Authenticator plus phone, email, or passkey) to avoid future lockouts.

    Self‑service and partner‑based recovery are not possible here because:

    • There is no second global admin who can use Require re‑register multifactor authentication for the affected account.
    • GDAP/partner scenarios do not apply unless a partner with appropriate roles exists for this tenant.
    • Microsoft for Nonprofits and general support cannot bypass identity verification; all access decisions go through standard Microsoft 365/Data Protection processes.

    References:

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.