Forum Discussion
Sole Global Admin locked out - lost MFA device, SSPR phone verification returns error
Hello,
I am the sole Global Administrator of a Microsoft 365 Business Standard tenant and I am completely locked out of the account.
What happened:
- My phone with Microsoft Authenticator was physically destroyed.
- I installed Authenticator on a new phone. My personal account restored from cloud backup, but the work account only appears as a "connected account" - it shows no TOTP code and receives no push notifications. Push requests still go to the old device.
What I tried while my admin session was still alive:
- Entra ID > per-user MFA > "Require selected users to provide contact methods again" - saved successfully.
- User > Authentication methods > "Require re-register multifactor authentication" - returned "Delete operation failed. Try this command again or delete them one by one in the user authentication methods blade."
- The Authentication methods list for the user was EMPTY, and default sign-in method showed "No default". "Add authentication method" button was greyed out.
- "Revoke sessions" - succeeded, but this also terminated my own admin session and signed me out of Outlook and OneDrive.
- aka.ms/mfasetup cannot be reached because it requires a fresh MFA challenge.
Self-service password reset (passwordreset.microsoftonline.com):
- First verification via alternate email succeeds every time (I have full access to that mailbox).
- Second verification fails: both "Text my mobile phone" and "Call my office phone" return "Sorry, we ran into a problem contacting you." I tried +370xxxxxxx, 370xxxxxxx and 8xxxxxxxx formats - same error every time. This looks like a service-side failure, not a formatting issue.
- Sign-in Helper now also reports "Account blocked due to multiple incorrect password attempts."
Error codes seen: 500121 and AADSTS50133.
I have tried calling Microsoft support in several countries. The automated system either asks for an internal extension number or the AI assistant disconnects the call before reaching a human.
There is no second Global Admin and no recovery codes.
I can provide the tenant ID, user unique identifier, subscription order number and proof of access to the billing email address privately.
Requesting escalation to the Data Protection team for admin account recovery. Any guidance on how to reach a human agent would be greatly appreciated.
Thank you.
4 Replies
I believe yes, you are required to contact the Microsoft support team and request escalation to Data Protection for MFA reset and tenant access restoration.
https://support.microsoft.com/en-us/support/
- JamesGLELECopper Contributor
J'ai le même problème actuellement.
- RadanarasMBCopper Contributor
Update: RESOLVED. Posting the full path in case it helps someone else in the
same situation.
Summary: sole Global Administrator, cloud-only tenant, Authenticator device
physically destroyed, authentication methods list empty, SSPR second step failing.
Resolved in about 24 hours through the Microsoft 365 Data Protection team.
WHAT ACTUALLY WORKED
1. Reaching a human. With no admin access there is no way to open a support case.
I created a separate free trial tenant, and from its admin center I opened a
support request describing the problem with the ORIGINAL tenant. That was the
only way in. (I cancelled the trial afterwards so it would not bill.)
2. The first agent routed the case to the Data Protection team, and an engineer
took ownership the same day.
3. Identity verification was done by phone. The engineer called the phone number
already registered on the tenant profile - in our case the company director's
number - and the director then added me to the call. We confirmed full name,
both contact phone numbers, and both e-mail addresses on record.
4. Approval step. I received an e-mail titled "MFA reset request for the GA/CA
account" and replied with the exact sentence "I approve this request".
5. The reset was executed shortly after. I signed in at portal.office.com with
the EXISTING password (it was never the problem), and instead of the
Authenticator prompt I got the "More information required" registration wizard.
Scanned the QR with Authenticator on the new phone. Access restored.
PRACTICAL NOTES THAT COST ME TIME
- The engineer's e-mails went to the case contact address, which was the
.onmicrosoft.com mailbox of the trial tenant, not my normal inbox. I did not see
them for hours. Tell the engineer explicitly which mailbox you can actually read,
and check the trial tenant's Outlook.
- Some of the case correspondence CC'd the locked account itself. State clearly and
repeatedly that you cannot read that mailbox - it is the one you are trying to
recover.
- Keep the TrackingID in the subject line and always reply in the same thread.
My first case was closed as a duplicate and a new ID was issued; replying to the
closed one would have gone nowhere.
- Prepare identity evidence before the call: tenant ID, user unique ID,
subscription order number, invoice number, company registration and VAT number,
billing e-mail. Having it ready made the verification call short.
- Do NOT revoke sessions. That is what killed my own remaining admin session and
turned an inconvenience into a full lockout.
AFTER RECOVERY
Registering a second method was not straightforward - phone/SMS registration
returned "We ran into a problem" every time, which matches the current retirement
of Microsoft-provided SMS and voice authentication. Passkeys and a second
Authenticator instance are the way forward.
What I am doing now, and what I would recommend to anyone reading this:
- more than one authentication method on the admin account, on more than one device
- a second, cloud-only break-glass Global Administrator account
- a custom domain added to the tenant, so ownership can be proven by DNS TXT
instead of documents and phone calls
Thanks Jamony - your answer was correct: there is no client-side bypass, and the
support route through the organization's registered contact details is the only
one that works.
You lost the usable MFA registration, revoked the remaining admin session, and SSPR cannot complete its second verification. There is no safe client-side bypass; recovery now requires an authenticated administrator or Microsoft verification. Stop repeated sign-in and reset attempts to avoid adding lockout signals. Contact Microsoft 365 business support using the organization’s registered contact details; Microsoft may verify the request through data stored in the tenant profile. If the subscription was bought through a partner, contact that partner because it owns the support route. Keep the tenant ID, custom domain, subscription or order number, billing records, and registered-contact access ready, but share them only in the support case. Ask for tenant administrator access recovery, not a public forum reset. After access is restored, create two cloud-only emergency Global Administrator accounts, register independent phishing-resistant credentials, monitor their use, and test them regularly so one lost device cannot lock the tenant again.