Share via

Cannot complete MFA - Admin account locked

chollada chokdeesrijun 20 Reputation points
2026-04-27T11:11:40.8133333+00:00

Hello,

I recently changed my phone and no longer have access to Microsoft Authenticator.

I am the only Global Admin of my tenant and cannot complete MFA verification. All authentication methods require MFA, and my phone number also does not work.

I still have an active session in Power BI but cannot change authentication settings.

Please help reset MFA so I can register a new authenticator device.

Thank you.

Microsoft Security | Microsoft Authenticator
0 comments No comments

Answer accepted by question author

AI answer

2026-04-27T11:11:53.75+00:00

Because all existing MFA methods are unavailable and there is only one Global Administrator, this is a tenant lockout scenario that cannot be fixed from the portals or Power BI alone.

Use the following recovery paths:

  1. If there is actually another admin
    • Any Global or Authentication Administrator in the tenant can reset the locked-out admin’s MFA so new methods can be registered:
      1. Sign in to the Microsoft Entra admin center as an admin.
      2. Go to Entra IDUsers → select the locked-out admin account.
      3. Open Authentication methods.
      4. Select Require re-register MFA.
      5. Next time the locked-out admin signs in, they will be prompted to set up MFA again (new phone / new Authenticator app, new phone number, etc.).
  2. If there is no other admin (only one Global Admin – your case)
    • This must be handled by Microsoft’s Data Protection / Tenant Recovery team via a support request. Forum moderators or normal users cannot reset MFA for an admin.
    • Contact Microsoft Support by phone using the “Customer service phone numbers - Microsoft Support” page referenced in the context. When connected to the IVR/agent, clearly state:
      • The issue is loss of access to Microsoft Authenticator and all MFA methods for the only Global Admin.
      • The tenant is a business/organization (work or school) account.
      • There is no other administrator who can reset MFA.
      • A Data Protection / Tenant Recovery case is needed to reset the admin’s MFA registration.
    • Be prepared to provide proof of identity and tenant ownership (business details, domain, billing info, etc.) as requested by the Data Protection team.
  3. Alternative way to reach Data Protection if phone support is difficult
    • Create a temporary trial Microsoft 365 tenant, then use that tenant’s admin center to open a support ticket on behalf of the locked tenant, explicitly requesting Data Protection / tenant recovery for the original tenant and describing that the only Global Admin is locked out due to MFA.

Once Microsoft Support/Data Protection verifies ownership, they can clear the MFA methods on the admin account so that, on next sign-in, a fresh MFA registration (new Authenticator on the new phone, updated phone number, etc.) can be completed.

Active sessions in services like Power BI do not provide a supported path to bypass or change MFA; the reset must be done either by another admin via Require re-register MFA or by Microsoft Support/Data Protection.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.