MFA Recovery Request for Global Administrator Account

Tính Tồ 0 Reputation points
2026-06-06T07:01:50.23+00:00

Dear Microsoft Support,

I am following up regarding our Microsoft 365 Education tenant.

Tenant: <pii removed>

Global Administrator account:<pii removed>

I can successfully sign in with the correct password, but I am unable to complete MFA verification.

Current situation:

The old phone containing Microsoft Authenticator has been permanently damaged.

The verification code method is unavailable because the Authenticator data is lost.

The SMS verification method fails with the message: "Sorry, we're having trouble verifying your account."

I do not have access to any other Global Administrator account.

I still control the DNS records of tnpc.edu.vn and can provide proof of domain ownership.

Could you please advise the recovery procedure or assist with restoring administrative access to the tenant?

Thank you very much.

Best regards, Văn Tính

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-06T07:02:04.05+00:00

    For a Microsoft 365 Education tenant where the only Global Administrator is locked out due to lost Microsoft Authenticator and non-working SMS, recovery must be handled by Microsoft’s Data Protection team via a support request. Forum moderators and standard support channels cannot directly reset MFA or bypass verification for security reasons.

    Follow this approach:

    1. Confirm there is no other Global Admin
      Recovery through the portal is only possible if another Global Admin can sign in and reset MFA. Since there is no other Global Admin, self-service options are not sufficient.
    2. Contact Microsoft Data Protection by phone (primary method)
      Use the official customer service phone numbers listed here:
      Customer service phone numbers - Microsoft Support
      When connected to the IVR/agent, clearly state:
      • This is a Microsoft 365 Education / Entra ID tenant.
      • The tenant name: bachkhoataynguyen.onmicrosoft.com.
      • The affected account is the only Global Administrator.
      • MFA cannot be completed because the phone with Microsoft Authenticator is permanently damaged and SMS verification fails.
      • Request to create a service request with the Microsoft Data Protection team for Global Admin MFA reset / tenant lockout.
      Example IVR flow (varies by country):
      • Problem type: “Authenticator”
      • Product: “Office 365 for business” (covers Education tenants as well in this flow)
      • Account type: “Company / education account”
      • Are you an administrator? “Yes”
      • Any other administrator? “No”
      • Need a service request? “Yes – need Data Protection team for admin lockout.”
      Be prepared to provide:
      • Tenant name and primary domain (including tnpc.edu.vn).
      • Proof of domain ownership (DNS control, documentation, etc.).
      • Business and identity verification details requested by the Data Protection team.
    3. Alternative: Create a temporary trial tenant to open a ticket
      If it is not possible to reach the correct support queue by phone, create a new temporary Microsoft 365 tenant (trial subscription) and use it only to open a support ticket:
      • Sign up for a Microsoft 365 trial and complete tenant creation.
      • Go to the Microsoft 365 Admin Center of this new tenant.
      • Navigate to Support → Help & support.
      • Open a support ticket explaining:
        • The issue is with a different existing Education tenant: bachkhoataynguyen.onmicrosoft.com.
        • The Global Admin account on that tenant is locked behind MFA.
        • There is no other Global Admin.
        • Request escalation to the Data Protection team for MFA reset / admin recovery on the original tenant.
      • Include tenant name, domain, and all error details (including the SMS error message) in the ticket.
      • After resolution, cancel the trial subscription of the temporary tenant to avoid charges.
    4. What the Data Protection team does
      • Verifies identity and administrative ownership of the tenant (including domain ownership such as tnpc.edu.vn).
      • Once satisfied, they can reset MFA or otherwise restore access to the Global Admin account so that sign-in can complete and new authentication methods can be configured.

    Self-service options like “I don’t have any of these” or standard verification-code troubleshooting do not apply here because the only admin account is blocked by MFA and no working second factor is available. In this scenario, escalation to the Microsoft Data Protection team via an official support request is required.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.