admin
74 TopicsSole Global Admin locked out - lost MFA device, SSPR phone verification returns error
Hello, I am the sole Global Administrator of a Microsoft 365 Business Standard tenant and I am completely locked out of the account. What happened: - My phone with Microsoft Authenticator was physically destroyed. - I installed Authenticator on a new phone. My personal account restored from cloud backup, but the work account only appears as a "connected account" - it shows no TOTP code and receives no push notifications. Push requests still go to the old device. What I tried while my admin session was still alive: - Entra ID > per-user MFA > "Require selected users to provide contact methods again" - saved successfully. - User > Authentication methods > "Require re-register multifactor authentication" - returned "Delete operation failed. Try this command again or delete them one by one in the user authentication methods blade." - The Authentication methods list for the user was EMPTY, and default sign-in method showed "No default". "Add authentication method" button was greyed out. - "Revoke sessions" - succeeded, but this also terminated my own admin session and signed me out of Outlook and OneDrive. - aka.ms/mfasetup cannot be reached because it requires a fresh MFA challenge. Self-service password reset (passwordreset.microsoftonline.com): - First verification via alternate email succeeds every time (I have full access to that mailbox). - Second verification fails: both "Text my mobile phone" and "Call my office phone" return "Sorry, we ran into a problem contacting you." I tried +370xxxxxxx, 370xxxxxxx and 8xxxxxxxx formats - same error every time. This looks like a service-side failure, not a formatting issue. - Sign-in Helper now also reports "Account blocked due to multiple incorrect password attempts." Error codes seen: 500121 and AADSTS50133. I have tried calling Microsoft support in several countries. The automated system either asks for an internal extension number or the AI assistant disconnects the call before reaching a human. There is no second Global Admin and no recovery codes. I can provide the tenant ID, user unique identifier, subscription order number and proof of access to the billing email address privately. Requesting escalation to the Data Protection team for admin account recovery. Any guidance on how to reach a human agent would be greatly appreciated. Thank you.282Views1like4CommentsStuck in an authenticator loop
I have a 365 Business account. Haven't logged in for a while due to reasons, i was just starting up as a sole trader. Anyway decided now is the time to resurrect it and get up and running, except Authenticator doesn't work because I changed my phone, and my back up email is out of date, and no longer exists. I have tried the support web chat which wants to send a code to authenticator or my back up email. Just called the help line that referred me to the web chat which doesn't work, I couldn't get past the bot. So I am stuck. Any recovery options does not recognise my log in details, i think this is because its been a while since I logged in (I still pay but ....) but I can't resurrect it because I don't have a way of getting a code due to authenticator/back up email as cited above. I am really at a loss as to what to do. I don't want to abandon it and start again as there are documents in my one drive that I need. Can anyone help please. (I think all that needs to happen is an update to my back up email and then I can get going). I am the sole administrator on my business account.201Views1like3CommentsMicrosoft Teams and Authenticator lockdown
I’m having a very frustrating issue with Microsoft Teams. I am able to log in to teams using my normal personal email and account ONLY ON THE WEB BROWSER. From the web browser, I am not able to access the business channel that I am in. When attempting to log in on the downloaded mobile Teams App, I am sent directly to Microsoft Authenticator, which after waiting several hours, waiting even a full day, is still displaying a message about repeated verification attempt and to wait and try again later. I have accessed Microsoft support chat and they had no help for me. I need the authenticator lockdown to refresh and it will not.176Views0likes1CommentHow to target Azure VPN (Microsoft-Registered) app with Conditional Access Policies?
I have an Azure Point-to-Site VPN Gateway configured using the Microsoft-registered Azure VPN Client App ID (Audience value: c632b3df-fb67-4d84-bdcf-b95ad541b5c8). Everything is working correctly for our users. The issue I am having is that anyone with an Entra account can connect to the VPN and I want to restrict this with a blocking Conditional access policy. I do not want to create a custom app registration, because then I will have to change the 'audience' value on the app gateway and all user's will need to modify their VPN clients. The problem is I need to target the Microsoft-registered Azure VPN app in a Conditional Access policy but it does not appear in my Enterprise Applications list or in the CA app picker when searching. My questions: Why does the Microsoft-registered app not automatically create a service principal in my tenant the way other Microsoft apps do? Is there a supported way to make it appear in the CA app picker without creating a custom app registration or changing the gateway Audience value? Has anyone successfully targeted c632b3df-fb67-4d84-bdcf-b95ad541b5c8 in a CA policy while keeping it as the gateway Audience value? Thanks for the assistance here191Views0likes2CommentsVaihdoit uuteen puhelimeen. Authenticator ongelma
Vaihdoit uuteen puhelimeen. Microsoft Authenticator ei ole enää saatavilla vanhalla laitteellasi. Et voi kirjautua Microsoft 365 -työtilillesi, koska MFA-vahvistus vaaditaan. Sinulla ei ole pääsyä mihinkään vaihtoehtoiseen todennusmenetelmään. Tarvitset apua suomeksi, jos mahdollista.158Views0likes1CommentUnable to access Global Admin, username not recognised, need tenant recovery billing active
Unable to access Global Admin account for Microsoft 365 tenant. Username not recognised and I need tenant recovery. Billing is still active. I am the billing owner of a Microsoft 365 Business subscription for yutoriacupuncture.com.au but I have lost access to all Global Admin accounts. The original admin account email is returning “username may be incorrect”. No other admin or business emails are recognised. I have a business email associated with the admin account i can still log into. I recently briefly cancelled and reinstated my domain which may have affected tenant linkage. I also recently joined a university Microsoft 365 organisation which may be affecting sign-in routing? I have tried login.microsoftonline.com, admin.microsoft.com, password resets, and incognito browsers with no success. I have tried contacting support via phone and email but keeps cutting out, saying it can't identity me, or sends me into a loop hole with the support chat bot. I need Microsoft to escalate this to tenant recovery or Data Protection team to restore Global Admin access using billing and domain ownership verification.83Views0likes2Commentsmail@mydomain is causing a cert mismatch error in all browsers for Outlook.com
Hello, I have created a CNAME for our users in my domain so that they can access webmail. For example, it's called mail.mycustomdomain.com, and it is directed to Outlook.com But when I try to visit mail.mycustomdomain.com, it shows a security warning and recommends going back. I can understand because the SAN name in the certificate presented by Outlook doesn't include my CNAME. Is there anything I can do as a workaround so our users can enter the CNAME without encountering a Certificate Mismatch Error? It is causing repeated calls to the helpdesk, and we would like them to use something simple they can remember. Thanks197Views0likes3CommentsAlternative hostname for ADFS proxy possible?
Dear Community, I have setuped a ADFS server with "adfs.customer.com" and a ADFS proxy, who also externally listening on this URL. Here is my question: Can I configure an additional "external" URL like "adfs.bla.com" in the ADFS proxy so, that its listening to incoming requests and redirect it to adfs.customer.com? Thanks André806Views0likes1CommentLogin Catch-22: locked out of Work account due to MFA mismatch.
"I am the owner of the domain mydomain.be, registered at one.com. I have a Microsoft 365 Business Premium subscription. I am locked out of my work/school tenant admin account (mailto:email address removed for privacy reasons) due to an MFA issue — the Microsoft Authenticator is configured but not delivering push notifications, and the TOTP code length does not match what the login screen expects. I cannot access the admin center. I need to recover Global Admin access to my flavo.be tenant so I can manage users and licenses. I can prove domain ownership via DNS if required.104Views0likes1Comment