Forum Discussion
Sole Global Admin locked out - lost MFA device, SSPR phone verification returns error
Hello,
I am the sole Global Administrator of a Microsoft 365 Business Standard tenant and I am completely locked out of the account.
What happened:
- My phone with Microsoft Authenticator was physically destroyed.
- I installed Authenticator on a new phone. My personal account restored from cloud backup, but the work account only appears as a "connected account" - it shows no TOTP code and receives no push notifications. Push requests still go to the old device.
What I tried while my admin session was still alive:
- Entra ID > per-user MFA > "Require selected users to provide contact methods again" - saved successfully.
- User > Authentication methods > "Require re-register multifactor authentication" - returned "Delete operation failed. Try this command again or delete them one by one in the user authentication methods blade."
- The Authentication methods list for the user was EMPTY, and default sign-in method showed "No default". "Add authentication method" button was greyed out.
- "Revoke sessions" - succeeded, but this also terminated my own admin session and signed me out of Outlook and OneDrive.
- aka.ms/mfasetup cannot be reached because it requires a fresh MFA challenge.
Self-service password reset (passwordreset.microsoftonline.com):
- First verification via alternate email succeeds every time (I have full access to that mailbox).
- Second verification fails: both "Text my mobile phone" and "Call my office phone" return "Sorry, we ran into a problem contacting you." I tried +370xxxxxxx, 370xxxxxxx and 8xxxxxxxx formats - same error every time. This looks like a service-side failure, not a formatting issue.
- Sign-in Helper now also reports "Account blocked due to multiple incorrect password attempts."
Error codes seen: 500121 and AADSTS50133.
I have tried calling Microsoft support in several countries. The automated system either asks for an internal extension number or the AI assistant disconnects the call before reaching a human.
There is no second Global Admin and no recovery codes.
I can provide the tenant ID, user unique identifier, subscription order number and proof of access to the billing email address privately.
Requesting escalation to the Data Protection team for admin account recovery. Any guidance on how to reach a human agent would be greatly appreciated.
Thank you.
1 Reply
You lost the usable MFA registration, revoked the remaining admin session, and SSPR cannot complete its second verification. There is no safe client-side bypass; recovery now requires an authenticated administrator or Microsoft verification. Stop repeated sign-in and reset attempts to avoid adding lockout signals. Contact Microsoft 365 business support using the organization’s registered contact details; Microsoft may verify the request through data stored in the tenant profile. If the subscription was bought through a partner, contact that partner because it owns the support route. Keep the tenant ID, custom domain, subscription or order number, billing records, and registered-contact access ready, but share them only in the support case. Ask for tenant administrator access recovery, not a public forum reset. After access is restored, create two cloud-only emergency Global Administrator accounts, register independent phishing-resistant credentials, monitor their use, and test them regularly so one lost device cannot lock the tenant again.