Tag not monitored by Microsoft.
The described scenario matches a tenant lockout of the only Global Administrator due to enforced MFA (Microsoft Authenticator) without having the app configured or any other methods available.
In this situation, the only supported path is to open a support ticket with Microsoft so the case can be escalated internally (including to the Data Protection team when required) to restore access to the tenant and reset MFA for the locked-out Global Administrator. This is the same process used in similar cases where there is no second Global Admin who can reset MFA or require re‑registration.
Once support validates tenant ownership and identity, they can help restore access to the Global Admin account and assist with resetting MFA methods so that Microsoft Authenticator or alternative methods can be configured correctly.
References:
- Common problems with two-step verification for a work or school account
- You don't receive a text or voice call that contains the verification code for Microsoft Entra multifactor authentication
- Mandatory multifactor authentication for Azure and admin portals
- Require MFA for administrators
- Can't set up MFA because five devices are already registered to use an authenticator app
- Step 3: Protect your Microsoft 365 user accounts
- Microsoft account has been locked
- How to add your accounts to Microsoft Authenticator
- Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A