Share via

MFA Lockout – Only Global Admin Cannot Access Tenant

teams AP 20 Reputation points
2026-04-17T12:20:32.3766667+00:00

Dear Microsoft Support,

We are currently completely locked out of our Microsoft tenant due to MFA verification failure.

Details:

  • Tenant domain: apli7945.onmicrosoft.com

Admin account: ******@apli7945.onmicrosoft.com

This is the only Global Administrator account in the tenant

Issue:

Error Code: 399287

Platform: Android

Microsoft Authenticator cannot be used

No alternative verification method (SMS/Phone not available)

Cannot access Entra admin center

We are completely unable to access any admin portal.

Please assist in resetting MFA for the administrator account as soon as possible.

Thank you.Dear Microsoft Support,

We are currently completely locked out of our Microsoft tenant due to MFA verification failure.

Details:

Tenant domain: apli7945.onmicrosoft.com

Admin account: ******@apli7945.onmicrosoft.com

This is the only Global Administrator account in the tenant

Issue:

Error Code: 399287

Platform: Android

Microsoft Authenticator cannot be used

No alternative verification method (SMS/Phone not available)

Cannot access Entra admin center

We are completely unable to access any admin portal.

Please assist in resetting MFA for the administrator account as soon as possible.

Thank you.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-04-17T12:20:47.9033333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Because the only Global Administrator is locked out by MFA and there is no alternative verification method, this is a tenant lockout scenario that cannot be fixed from the portals and must be handled by Microsoft’s Data Protection/Tenant Recovery teams.

    Follow these steps:

    1. Contact Microsoft by phone and ask for the Data Protection team When the IVR or agent asks what the problem is, clearly state:
      • The tenant is a business/organization (not personal).
      • This is an admin MFA lockout.
      • There is only one Global Administrator and that account cannot complete MFA.
      • Request to be transferred to the Microsoft 365 Data Protection team (or Data Protection / Tenant Recovery team) to reset MFA / authentication methods for the global admin.
      Example flow (from the documented guidance):
      • Problem: “Authenticator”
      • Product: “Office 365 for business”
      • Account type: “For companies”
      • Are you an administrator?: “Yes”
      • Any other administrators?: “No”
      • Do you need a service request?: “Yes, I need to create a ticket and speak with the Data Protection team.”
    2. If phone support is hard to reach, create a temporary trial tenant to open a ticket (workaround)
      • Sign up for a new Microsoft 365 trial tenant (separate from apli7945.onmicrosoft.com).
      • From that new tenant, go to the Microsoft 365 admin center → Support → Help & support and open a ticket.
      • In the ticket, clearly explain:
        • The locked tenant domain: apli7945.onmicrosoft.com.
        • The affected admin UPN.
        • That this is the only Global Administrator and MFA cannot be completed (Authenticator unavailable, no SMS/phone).
        • Request that the Data Protection team reset MFA / security info for the global admin on the original tenant.
      • After recovery, cancel the trial subscription on the temporary tenant to avoid charges.
    3. If the tenant was purchased via a CSP partner
      • If a Cloud Solution Provider (CSP) or reseller manages the subscription, contact the partner and ask them to open a Data Protection / tenant recovery service request on your behalf.
    4. Future prevention once access is restored
      After Microsoft resets MFA and access is restored, implement these safeguards to avoid future lockouts:
      • Ensure at least two Global Admin accounts with different credentials and MFA methods.
      • Create emergency/break-glass accounts excluded from Conditional Access and MFA policies, with strong passwords and monitored sign-ins.
      • Configure additional MFA methods (e.g., SMS, phone, passkey/FIDO2, or certificate-based authentication) for all admins.
      • Consider assigning a Privileged Authentication Administrator or similar role so someone else can reset admin MFA in the future.

    Only Microsoft’s Data Protection/Tenant Recovery team can verify ownership and reset MFA in this single-admin lockout scenario; self-service or portal-based fixes are not possible.


    References:

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.