Problem with MFA

Associazione Andrea Tudisco 0 Reputation points
2026-07-13T10:29:12.4566667+00:00

Hello Microsoft Team,

We are locked out of our Microsoft 365 Nonprofit tenant because the only Global Administrator lost access to Microsoft Authenticator.

Tenant:

[Moderator note: personal info removed]

Global Administrator:

[Moderator note: personal info removed]

Current situation:

  • We know the correct password.
  • The account is recognized by Microsoft.
  • Login always stops at Microsoft Authenticator.
  • The Authenticator app no longer contains this account.
  • There are no other Global Administrators.
  • We cannot open a support ticket because access to the Admin Center requires MFA.

We own the custom domain:

[Moderator note: personal info removed]

We also have the original Microsoft Nonprofit approval documentation and we can prove ownership of the organization and the domain.

We are requesting escalation to the Microsoft Data Protection / Tenant Recovery team for an MFA reset of the only Global Administrator.

Thank you.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Gabriel-N 20,645 Reputation points Microsoft External Staff Moderator
    2026-07-13T10:59:35.9833333+00:00

    Q&A forum is a public platform, and moderators will modify the question to hide personal information in the description. Kindly ensure that you hide any personal or organizational information the next time you post an error or other details to protect personal data.

    Hello @Associazione Andrea Tudisco

    Please check whether the administrator still has an active session that can access the Microsoft Entra admin center. If so, they may be able to create a new Global Administrator account. Since administrators generally cannot reset their own MFA methods, the new Global Administrator account can be used to reset the affected administrator's authentication methods and allow them to re-register Microsoft Authenticator. According to Microsoft documentation, an Authentication Administrator or another authorized administrator can manage authentication methods for other users, including requiring MFA re-registration. Reference: https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-userdevicesettings#manage-user-authentication-options

    If this is a complete tenant lockout scenario, the usual approach involves two options:

    • Contact Microsoft Support directly by phone: Contact Microsoft Office Support
    • If calling support does not work, you may consider creating a trial tenant and submitting a support ticket from there on behalf of the affected (locked) tenant. Please remember to cancel the trial subscription afterward to avoid any potential charges. Please note that this process may take longer than usual (around 7-14 business days), as the Data Protection team handles a high volume of requests. As a forum moderator, I don’t have access to Microsoft internal systems and won’t be able to expedite the process.

    User's image

    For detailed steps, kindly refer to the referenced thread: Denied global administrator access although I am the only admin

    Hope this info helpful.


    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.