A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the account is protected by Microsoft Entra/Azure MFA and there is no second administrator on the tenant, this situation must be handled by Microsoft support/Data Protection; it cannot be fixed from the sign-in page alone.
Based on the documented patterns for similar cases, the recovery path is:
- If there is any other Global Administrator in the tenant
- That admin signs in to the Microsoft Entra admin center.
- Goes to Identity > Users > All users.
- Selects the locked-out user account.
- Opens Authentication methods and selects Require re-register multifactor authentication.
- After that, the next sign-in for the locked-out account will prompt to set up MFA again, breaking the loop.
- If there is no other Global Administrator (your case)
- This is treated as a tenant lockout / sole-admin lockout scenario.
- The only supported resolution is through Microsoft’s Data Protection / Tenant Recovery process.
- To start that process, contact Microsoft support by phone using the Customer service phone numbers - Microsoft Support page referenced in the documentation.
- When calling, clearly state:
- The issue is Authenticator / MFA lockout.
- The product is Office 365/Azure for business.
- It is a company/organizational account, not personal consumer.
- You are the only Global Administrator for the tenant.
- You are completely locked out and need the Data Protection team to reset MFA / restore access.
- The frontline agent will create a service request and route it to the Data Protection/Tenant Recovery team, who will verify identity and ownership and then reset MFA or otherwise restore access.
- If phone support is difficult to reach
- One documented workaround is to create a new trial Microsoft 365/Azure tenant solely to open a support ticket:
- Sign up for a Microsoft 365 or Azure trial and complete tenant creation.
- In the new tenant’s Microsoft 365 Admin Center, go to Support > Help & support.
- Open a ticket explicitly stating that you are locked out of a different existing tenant where you are the only Global Administrator and need Data Protection to reset MFA.
- Provide the locked-out tenant’s domain (for example,
mmc96.onmicrosoft.com) and admin UPN, plus the error behavior.
- Support will then contact you, verify identity, and work on the original tenant. The trial tenant is only a channel to reach support.
- One documented workaround is to create a new trial Microsoft 365/Azure tenant solely to open a support ticket:
- Personal data in the tenant
- Only the Data Protection/Tenant Recovery process can restore access or perform actions such as resetting MFA so that you can sign in and manage or delete your personal data in that tenant.
There is no self-service method to bypass or disable MFA in this scenario when:
- MFA is enforced,
- Microsoft Authenticator is the only registered method, and
- there is no other Global Administrator who can reset your MFA.
References:
- "Account verification system is having trouble" error message when you try to sign in by using a work or school account
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Common problems with two-step verification for a work or school account
- Use a screen reader to set up and troubleshoot multifactor authentication
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Reset Personal Azure MFA - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A