Share via

Azure MFA locked out

Adam Tobin 5 Reputation points
2026-04-04T13:25:28.2466667+00:00

I am unable to access my Azure portal because MFA is not working.

I am the only Global Administrator on this tenant and have no alternative authentication method available.

I cannot sign in to create a support request through the Azure portal.

There is also active billing on the subscription that I cannot manage due to being locked out.

Please escalate this case to the Data Protection / Tenant Recovery team to verify ownership and reset MFA for my admin account.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-04-04T13:25:43.7566667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Because there is only one Global Administrator on the tenant and no working MFA or alternate authentication method, this is a tenant lockout scenario that must be handled by Microsoft’s Data Protection / Tenant Recovery team.

    Follow these steps to regain access:

    1. Contact Microsoft support by phone
      • Use the regional phone numbers listed under Customer service phone numbers - Microsoft Support / Support for Business Products / Microsoft 365 for business support phone numbers by country or region.
      • When navigating the IVR, clearly indicate:
        • The product: “Office 365 for business” or “Azure / Microsoft 365 for business”.
        • That this is a company/organization account.
        • That you are an administrator.
        • That there is no other global administrator.
        • That you are locked out due to MFA and need to be connected to the Microsoft Data Protection team (sometimes called Tenant Recovery) to reset MFA for the only Global Admin.
    2. Ask specifically for Data Protection / Tenant Recovery
      • Explain that:
        • MFA is required and is not working.
        • You are the only Global Administrator.
        • You cannot access the Azure/Microsoft 365 admin portals to open a ticket.
        • There is active billing you cannot manage.
      • The frontline agent must create a service request and route it to the Data Protection team, who have tools and processes to verify tenant ownership and reset the admin’s authentication methods.
    3. If phone support cannot be reached
      • As an alternative, create a temporary trial tenant (for example, a Microsoft 365 or Azure trial) and use that tenant’s admin center to open a support ticket.
      • In the ticket, clearly state that:
        • The issue concerns a different existing tenant where you are the only Global Admin.
        • You are locked out due to MFA and need MFA reset / admin recovery by the Data Protection team.
      • Be prepared to provide proof of ownership and business documentation for the locked tenant.
    4. After recovery
      • Once access is restored, configure:
        • At least two Global Administrator accounts with different credentials and MFA methods.
        • Emergency/break-glass accounts excluded from Conditional Access policies, with strong passwords and monitored sign-ins.
      • This prevents future tenant lockouts caused by MFA or policy issues.

    The actual MFA reset and tenant recovery can only be performed by Microsoft support (Data Protection team); community forums and tools cannot override MFA or admin access in this scenario.


    References:

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.