Share via

Global admin locked out MFA no access to authenticator

KHR Consultants 0 Reputation points
2026-04-19T11:02:54.8466667+00:00

I am the only Global Administrator of my organization’s Microsoft 365 tenant.

I reset my phone and lost access to Microsoft Authenticator, and I no longer have any MFA methods available. I am completely locked out of Microsoft Entra ID and the admin center.

I need assistance regaining access and resetting MFA. I can verify domain ownership and provide all required details.

Microsoft Security | Microsoft Authenticator
0 comments No comments

2 answers

Sort by: Most helpful
  1. Liora D 14,875 Reputation points Microsoft External Staff Moderator
    2026-04-19T11:49:16.4266667+00:00

    Please understand that, as forum moderators and community members, we don’t have the tools or access required to make changes to user accounts. This includes signing in on your behalf, resetting MFA, changing passwords, or modifying access rights. For security reasons, only Microsoft Support can assist with requests like this.


    Dear @KHR Consultants,

    I hope you’re having a good day.

    I’m really sorry you’re dealing with this, being locked out when you’re the only Global Administrator is an extremely stressful situation, and unfortunately it does happen more often than people expect.

    Based on what you described, this is a tenant lockout scenario. Because you are the sole Global Admin and you no longer have access to any MFA method. In this situation, the supported recovery path is to contact Microsoft Support and request escalation to the Data Protection team. This team is specifically responsible for scenarios where the only admin is locked out. They will ask you to prove that you are the legitimate owner or authorized administrator of the tenant, typically using domain ownership, billing details, and organization information. After successful verification, they can reset or clear the MFA registration for your Global Admin account so you can sign in again and re‑enroll MFA.

    To reach Microsoft Support, you can start by calling the appropriate customer service number for your region here: Customer service phone numbers - Microsoft Support   

    User's image

    (Depending on your country or region, when you call the support number you may hear an automated introduction lasting around 30 seconds (for example, suggesting you visit a website). You can ignore this introduction and wait for the menu options. When prompted, select “1” for a business or work account, and then “1” again for technical support.)

    In some regions, you may initially interact with an automated system. Based on experience, answering along these lines usually helps you reach the right team faster:

    • What kind of problem are you experiencing?           
    • Answer: Authenticator           
    • What products do you use?           
    • Answer: Office 365 for business           
    • Is this for an education or company account?           
    • Answer: For companies           
    • Are you an administrator?           
    • Answer: Yes           
    • Are there any other administrators in your organization?           
    • Answer: No. I am the only admin in my tenant            
    • Do you need a... Service request?            
    • Answer: Yes. I need to create a ticket. Please send me direct to the Data Protection Teams.        

    During the call, you will be asked to provide information that verifies your identity and proves ownership of the tenant, such as your organization name, billing information, contact email, phone number, or other subscription‑related details.


    If you’re unable to open a support ticket because you cannot access your admin center at all, there is an alternative approach. You can create a temporary Microsoft 365 trial tenant using this link: Microsoft 365 Business Plans and Pricing | Microsoft 365    

    User's imageUser's image

    Once the new tenant is created, you can access the admin center and submit a support ticket from there, requesting to speak with the Data Protection Team on behalf of your original tenant.    

    Important notes:     

    • This new trial tenant will not give you access to any of the data or settings in your original locked tenant. It is solely a temporary means to contact Microsoft support.    
    • The resolution time might be longer as you are contacting support from a different tenant.    
    • Remember to cancel the trial subscription for the new tenant once your issue with the original account is resolved to avoid any unintended charges.  

    I hope the information provided helps guide you in the right direction. Although I’m unable to take direct action, I sincerely hope that the steps and recommendations I’ve shared can support you through the process.  

    I hope this information helps clarify the correct path forward. Please feel free to share an update once you’re able to connect with Microsoft Support, and I’ll be happy to help interpret any next steps if needed.

    Warm regards, 


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".    

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.   

    Was this answer helpful?

    0 comments No comments

  2. Q&A Assist
    2026-04-19T11:03:10.02+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Because there is only one Global Administrator and no working MFA methods, this is a tenant lockout scenario that must be handled by Microsoft support/Data Protection. Self-service recovery or portal-based fixes are not possible.

    Follow these steps:

    1. Prepare ownership evidence
      • Have ready: official business documentation, domain ownership proof, and any tenant-identifying information (tenant name, primary domain, billing details) so Microsoft can verify identity and tenant ownership.
    2. Contact Microsoft support by phone (Data Protection path)
      • Call Microsoft’s global customer service for business and request a service ticket specifically for tenant admin MFA reset / tenant lockout.
      • Use the guidance from the documented flow when interacting with the IVR/agent:
        • State that this is an Office 365 for business / Microsoft 365 for business account.
        • Confirm it is a company/organization account, not personal.
        • Confirm being an administrator and that there is no other admin available.
        • Ask to create a service request and be routed to the Data Protection team to reset MFA for the only global admin.
      • Reference that this is a tenant lockout and that MFA must be reset because the only admin lost access to Microsoft Authenticator.
    3. If phone support is hard to reach: create a temporary tenant to open a ticket
      • As an alternative, register a new Microsoft 365 tenant (for example via a trial subscription) and sign in to its admin center.
      • From that new tenant’s admin portal, open a support ticket requesting to speak with the Data Protection team on behalf of the original locked-out tenant, explaining:
        • The original tenant name and domain.
        • That there is only one global admin and MFA is lost.
        • That an MFA reset / admin recovery is required.
    4. Work with the Data Protection team
      • The Data Protection team will contact by phone or email, validate identity and tenant ownership using the documentation provided, and then perform the necessary steps to restore access (typically by resetting MFA registration for the global admin account or providing an alternative sign-in path).
    5. Prevent future lockouts once access is restored
      • Add at least one additional admin or a Privileged Authentication Administrator so another account can reset a global admin’s password/MFA if this happens again.
      • Configure multiple MFA methods (Authenticator on more than one device, phone, SMS, etc.).
      • Consider more resilient methods such as passkeys (FIDO2) or certificate-based authentication for admin accounts.

    References:

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.