[Azure] Sole Global Administrator locked out due to Microsoft Authenticator MFA - need escalation

Haochuan Chen 0 Reputation points
2026-06-27T13:53:56.47+00:00

Hello Microsoft Support / Microsoft Entra team,

I am the sole Global Administrator of my personal Azure / Microsoft Entra tenant.

I am completely locked out because Azure sign-in requires Microsoft Authenticator approval with 6 digits code. However, my Microsoft Authenticator app shows 8 digits.

User's image

Current situation:

  • I still know the correct username and password.
  • I can use my account for other Microsoft personal services (Windows, Office, XBox, etc.)
  • I also cannot create a support ticket from the affected tenant because MFA is required before sign-in can complete.

This appears to be an Entra tenant lockout scenario.

I need Microsoft Support / Data Protection Team to verify tenant ownership and reset or clear the MFA registration for my administrator account.

Please help escalate this case.

Thank you.

.

[Moderator edit: Changed tags from: Azure | Azure Policy ]

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Jerald Felix 16,745 Reputation points Volunteer Moderator
    2026-06-27T16:31:11.8233333+00:00

    Hello Haochuan Chen,

    Greetings! Thanks for raising this question in the Q&A forum.

    The 8 digit code showing in Microsoft Authenticator instead of the expected 6 digit code is the key clue here. Microsoft Authenticator always generates standard 6 digit TOTP codes for Entra ID and Microsoft accounts. An 8 digit code coming from the app means that particular entry in your Authenticator app is not actually linked to this tenant's account, it is a different account entry, a duplicate or stale entry added manually at some point, or a non-Microsoft account that uses a different code length. This is why entering it never works, you are looking at the wrong entry rather than experiencing a bug in the MFA system itself.

    Check Authenticator for multiple entries tied to similar looking accounts

    Open the app and scroll through every entry, not just the one you assume is correct. Look closely at the account name and email shown under each entry, since duplicate or old entries from previous re-registrations of the same admin account commonly stay in the list and only differ by small details.

    If you find the correct 6 digit entry, use that one instead

    Once located, retry sign-in using the code from that specific entry rather than the 8 digit one. This resolves the issue immediately if it is simply a matter of using the wrong entry.

    If there is no 6 digit entry at all, try a different verification method on the sign-in screen

    Look for a link that says:

    I can't use my Microsoft Authenticator app right now
    

    This should reveal any other registered methods on the account, for example SMS, voice call, or a second security info method, if one was ever configured. Since you mention you can still use this same Microsoft account normally for Windows, Office, and Xbox, it is worth checking whether a phone number or alternate email is already registered as a backup method on the security info page for that account.

    Check your registered methods from a working session

    Since you can sign in to other Microsoft personal services with this account, go to:

    https://account.live.com/proofs/Manage
    

    or

    https://mysignins.microsoft.com/security-info
    

    from a session where you are already authenticated for those other services, and confirm what backup verification methods exist. If a phone number is listed, that becomes your fallback for the tenant sign-in.

    If neither of the above resolves it, this becomes a Microsoft-side identity verification case, not a self-service fix

    Being the sole Global Administrator with no working MFA method and no way to reach Help + Support from inside the tenant is a known hard-lockout scenario. Self-service password or MFA reset cannot bypass MFA itself, so the remaining path is Microsoft support verifying your ownership through alternate means.

    Contact Microsoft support through a channel that does not require signing in to the locked tenant

    https://support.microsoft.com/contactus
    

    Select Microsoft Entra ID as the product area and explain that you are the sole Global Administrator, completely MFA-locked, and unable to reach Help + Support from inside the tenant. Have ready your Tenant ID, the primary admin UPN, and proof of tenant ownership such as a billing invoice, subscription ID, or domain ownership record, since Global Admin recovery is a sensitive operation and Microsoft will need to verify you are the legitimate owner before resetting any MFA registration.

    Going forward, register a second MFA method and ideally a second admin account

    Once you regain access, add a phone number as a backup method under Security info, and consider creating a second Global Administrator account or break glass account stored securely offline. A single admin with a single MFA method is the exact setup that leads to this kind of full lockout.

    If this answer helps you kindly accept the answer which will help others who have similar questions.

    Best Regards,

    Jerald Felix.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.