Forum Discussion
Sole Global Admin locked out - lost MFA device, SSPR phone verification returns error
Update: RESOLVED. Posting the full path in case it helps someone else in the
same situation.
Summary: sole Global Administrator, cloud-only tenant, Authenticator device
physically destroyed, authentication methods list empty, SSPR second step failing.
Resolved in about 24 hours through the Microsoft 365 Data Protection team.
WHAT ACTUALLY WORKED
1. Reaching a human. With no admin access there is no way to open a support case.
I created a separate free trial tenant, and from its admin center I opened a
support request describing the problem with the ORIGINAL tenant. That was the
only way in. (I cancelled the trial afterwards so it would not bill.)
2. The first agent routed the case to the Data Protection team, and an engineer
took ownership the same day.
3. Identity verification was done by phone. The engineer called the phone number
already registered on the tenant profile - in our case the company director's
number - and the director then added me to the call. We confirmed full name,
both contact phone numbers, and both e-mail addresses on record.
4. Approval step. I received an e-mail titled "MFA reset request for the GA/CA
account" and replied with the exact sentence "I approve this request".
5. The reset was executed shortly after. I signed in at portal.office.com with
the EXISTING password (it was never the problem), and instead of the
Authenticator prompt I got the "More information required" registration wizard.
Scanned the QR with Authenticator on the new phone. Access restored.
PRACTICAL NOTES THAT COST ME TIME
- The engineer's e-mails went to the case contact address, which was the
.onmicrosoft.com mailbox of the trial tenant, not my normal inbox. I did not see
them for hours. Tell the engineer explicitly which mailbox you can actually read,
and check the trial tenant's Outlook.
- Some of the case correspondence CC'd the locked account itself. State clearly and
repeatedly that you cannot read that mailbox - it is the one you are trying to
recover.
- Keep the TrackingID in the subject line and always reply in the same thread.
My first case was closed as a duplicate and a new ID was issued; replying to the
closed one would have gone nowhere.
- Prepare identity evidence before the call: tenant ID, user unique ID,
subscription order number, invoice number, company registration and VAT number,
billing e-mail. Having it ready made the verification call short.
- Do NOT revoke sessions. That is what killed my own remaining admin session and
turned an inconvenience into a full lockout.
AFTER RECOVERY
Registering a second method was not straightforward - phone/SMS registration
returned "We ran into a problem" every time, which matches the current retirement
of Microsoft-provided SMS and voice authentication. Passkeys and a second
Authenticator instance are the way forward.
What I am doing now, and what I would recommend to anyone reading this:
- more than one authentication method on the admin account, on more than one device
- a second, cloud-only break-glass Global Administrator account
- a custom domain added to the tenant, so ownership can be proven by DNS TXT
instead of documents and phone calls
Thanks Jamony - your answer was correct: there is no client-side bypass, and the
support route through the organization's registered contact details is the only
one that works.