Share via

Locked out of admin.microsoft.com – only Global Admin lost Microsoft Authenticator bypass

Louie 20 Reputation points
2026-04-10T07:57:05.02+00:00

I cannot sign in to https://admin.microsoft.com.

I am the only Global Administrator in our Microsoft 365 tenant. My phone was reset / replaced, and the Microsoft Authenticator app was not backed up.

Now sign-in requires approval in Microsoft Authenticator, but:

The old device is no longer available

No QR code is shown to re-register

No other MFA methods are available

There are no other Global Admins in the tenant other than me

As a result, I am completely locked out of the Microsoft 365 Admin Center.

i just want to bypass 2FA temporarily to regain access to admin center

Thank you.

Microsoft Security | Microsoft Authenticator
0 comments No comments

Answer accepted by question author

  1. Q&A Assist
    2026-04-10T07:57:20.38+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Bypassing Microsoft 365 MFA for a locked-out sole Global Administrator is not possible. MFA cannot be skipped or disabled from the sign-in page, and support agents or community moderators cannot turn it off for an account on request.

    To regain access when the only Global Admin has lost Microsoft Authenticator and has no alternative MFA methods, the supported recovery path is through Microsoft’s Data Protection / Tenant Recovery process.

    Use the following approach:

    1. Try any alternative verification methods (if they exist)
      • If any other security verification options were ever configured (SMS, voice call, alternate phone, etc.), select “Other verification options” at sign-in and use those instead.
      • If none exist or they also fail, proceed to step 2.
    2. If there is another Global Admin (not in this case)
      • A different Global Admin could reset MFA by:
        • Going to Microsoft Entra ID in the Azure portal → Users → select the locked-out user → Authentication methodsRequire re-register multifactor authentication.
      • This does not apply here because there are no other Global Admins.
    3. As the only Global Admin: contact Microsoft Data Protection team
      • This is the required route when the sole Global Admin is locked out and cannot complete MFA.
      • Call the regional support number listed under Customer service phone numbers - Microsoft Support or Support for Business Products (from the context). Ask to open a ticket with the Microsoft 365 / Microsoft Entra Data Protection team for tenant admin account recovery.
      • Clearly state:
        • This is a work/company Microsoft 365 tenant.
        • The caller is the only Global Administrator.
        • MFA is enforced and the only method was Microsoft Authenticator on a lost/reset phone.
        • The admin can still provide username and password but cannot complete MFA.
      • Follow their identity and tenant ownership verification process. They have internal tools and procedures to reset the MFA registration for a locked-out sole Global Admin.
    4. If frontline support misroutes the call
      • If told to “contact your admin” or that the account is “commercial” and they cannot help, insist that this is a tenant lockout of the only Global Admin and request escalation to the Data Protection team.
    5. Optional workaround to open a ticket if phone support is difficult
      • Create a new trial Microsoft 365 tenant (separate from the locked tenant).
      • In the new tenant’s Microsoft 365 Admin Center, go to Support → Help & support and open a ticket.
      • In the ticket, explain that the issue is with a different existing tenant where the only Global Admin is locked out due to lost Authenticator and no other MFA methods.
      • Provide the locked tenant’s domain and admin UPN so support can route the case to the Data Protection team.

    There is no supported way to temporarily bypass or disable MFA on the locked account from the outside. Recovery must go through Microsoft support (Data Protection / Tenant Recovery) so they can reset the MFA registration after verifying identity.


    References:

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.