microsoft 365 admin center
1104 TopicsSole Global Admin locked out - lost MFA device, SSPR phone verification returns error
Hello, I am the sole Global Administrator of a Microsoft 365 Business Standard tenant and I am completely locked out of the account. What happened: - My phone with Microsoft Authenticator was physically destroyed. - I installed Authenticator on a new phone. My personal account restored from cloud backup, but the work account only appears as a "connected account" - it shows no TOTP code and receives no push notifications. Push requests still go to the old device. What I tried while my admin session was still alive: - Entra ID > per-user MFA > "Require selected users to provide contact methods again" - saved successfully. - User > Authentication methods > "Require re-register multifactor authentication" - returned "Delete operation failed. Try this command again or delete them one by one in the user authentication methods blade." - The Authentication methods list for the user was EMPTY, and default sign-in method showed "No default". "Add authentication method" button was greyed out. - "Revoke sessions" - succeeded, but this also terminated my own admin session and signed me out of Outlook and OneDrive. - aka.ms/mfasetup cannot be reached because it requires a fresh MFA challenge. Self-service password reset (passwordreset.microsoftonline.com): - First verification via alternate email succeeds every time (I have full access to that mailbox). - Second verification fails: both "Text my mobile phone" and "Call my office phone" return "Sorry, we ran into a problem contacting you." I tried +370xxxxxxx, 370xxxxxxx and 8xxxxxxxx formats - same error every time. This looks like a service-side failure, not a formatting issue. - Sign-in Helper now also reports "Account blocked due to multiple incorrect password attempts." Error codes seen: 500121 and AADSTS50133. I have tried calling Microsoft support in several countries. The automated system either asks for an internal extension number or the AI assistant disconnects the call before reaching a human. There is no second Global Admin and no recovery codes. I can provide the tenant ID, user unique identifier, subscription order number and proof of access to the billing email address privately. Requesting escalation to the Data Protection team for admin account recovery. Any guidance on how to reach a human agent would be greatly appreciated. Thank you.23Views0likes1CommentNot For Profit Licence suddenly disappeared and then deleted
Hi All Have a big issue. Have a not for profit account for our charity. Renewed licence earlier in the year and all was ok and working. Then a few days ago I had reports of not being able to access data. After much hunting I found the below. Seems account was suddenly and without warning disabled and then reported as deleted a few days later. What do I do? I desperately need to recover the files that were on the associated teams? Any help would be much appreciated449Views0likes15CommentsWhere does Teams get its user list from? I can't make sense of which accounts I see vs which I can't
OK, so I have a currently rather unusual situation. I am looking at a 365 Tenant. A number of users have four accounts on the same tenant (let's not even get into why, cleaning things up is part of the reason I got called in). When you start typing their name into teams it comes up with three of them as a suggestion (I only want one) Account 1: has just been used for ActiveDirectory for permissions to the company's Distributed File System (stored in on on premises servers in various locations). This account has to the best of my knowledge never had a license or mailbox associated with it, and so has never been on the global address list, it's also never had the teams app enabled for it. I don't want this one to show, but it does Account 2: A now defunct account which used to have a Business Standard license assigned to it, but has now had the licensed removed. Before the license was removed this account was hidden from the GAL and its teams app disabled. I don't want this one to show, but it does Account 3: An now defunct account which still has a Business Standard license, but with Teams deselected in the Apps. I don't want this one to show... and it doesn't Account 4: An account shared via a multi tenant organization (the users in question have been migrated to a new tenant). So these are members (not guests) but external ones. I want this to show, and it does. Now, accounts 2 and 3 will be deleted soon, whether we can get rid of account 1 depends on whether the necessary access to the DFS can be done using account 4 (which I need to look into next). However for the time being they are all there so I was trying to hide accounts I don't want users trying to message on teams from teams, and I cannot make any sense of which I see which I don't. To sum up. Account that has never been on the Global Address List and never been activated for Teams - Shows Account that used to have a license and was on the GAL, and used in teams - Shows Account that still has a license, but has been removed from GAL and had teams app disabled - Doesn't show Account that has no license and is not on the GAL, but has teams on it's host tenant - Shows After a previous inquiry I set "Scope directory search using an Exchange address book policy" in the teams setup, but I have not set up any specific address book policy as yet. I have tried showing and hiding people from the global address list, and also the "ShowInAddressList" setting in Entra (which seems to only be available through graph?). Nothing seems to make a difference (it doesn't help that Teams takes forever to update its local cache for this stuff, so maybe a change DID make a difference at some point and I missed it). I cannot find any logic as to which of these accounts is showing in the auto suggests and which not, most notably that account 1 shows but account 3 doesn't. So, where is Teams getting its list of contacts from?2.7KViews0likes4CommentsUnable to Access Admin Center - SMS and Authenticator Options Not Working for Account Recovery
I am currently unable to access the Microsoft 365 admin center because I cannot complete the account verification process. When I try to loggin to my account, the assistant only offers two options: using the Microsoft Authenticator app or receiving an SMS code. Unfortunately, I do not have access to the Authenticator app, and the system is not able to send me the SMS code either. This leaves me completely locked out of the admin panel. I have tried multiple times to use the SMS option, but I never receive the code. The recovery assistant keeps prompting me to use either the Authenticator or SMS, but neither method works. Because of this, I cannot regain access to the admin center. I have the correct password, but without multi-factor authentication (Authenticator or SMS recovery) I cannot access the Microsoft 365 admin center. Without access to the admin center, I cannot create or manage support requests directly from the admin portal. I also tried calling support by phone, but the AI does not understand what I am saying and does not transfer me to a human agent who can actually help me resolve the problem. I would appreciate any guidance on how to contact so a human for support or alternative ways to verify my identity and regain access to the Microsoft 365 admin portal. Thank you in advance for your help.47Views0likes1CommentStuck in an authenticator loop
I have a 365 Business account. Haven't logged in for a while due to reasons, i was just starting up as a sole trader. Anyway decided now is the time to resurrect it and get up and running, except Authenticator doesn't work because I changed my phone, and my back up email is out of date, and no longer exists. I have tried the support web chat which wants to send a code to authenticator or my back up email. Just called the help line that referred me to the web chat which doesn't work, I couldn't get past the bot. So I am stuck. Any recovery options does not recognise my log in details, i think this is because its been a while since I logged in (I still pay but ....) but I can't resurrect it because I don't have a way of getting a code due to authenticator/back up email as cited above. I am really at a loss as to what to do. I don't want to abandon it and start again as there are documents in my one drive that I need. Can anyone help please. (I think all that needs to happen is an update to my back up email and then I can get going). I am the sole administrator on my business account.84Views1like3CommentsNeed to Restore PST Files to Office 365 Mailboxes - What's the Best Approach
Hey everyone, I have a task coming up where I need to restore several PST files back into Office 365 mailboxes. Haven't done this before at this scale and honestly not sure where to begin. I've looked at Microsoft's native import service through Purview but I have a few concerns: Some of the PST files are quite large — not sure how well it handles that I need to restore only specific folders for some users, not the entire PST I'm worried about data consistency after the restore Would prefer something that doesn't require too many admin roles or complex setup For those who have done PST to Office 365 restores — what approach worked best for you? Any tools, tips, or things to watch out for that you wish you knew before starting?156Views0likes4CommentsCost Savings In Microsoft 365
Long story short, I had a client say, "We have more M365 licensed users than employees. Please help us find them." It took me about a week to find all the waste (first time always takes forever). Now I've run the same steps for a dozen other clients (takes less than an hour now). On average, I've been able to save clients 22% of their budget. Thought I'd share exactly how I do it. There are 5 areas of waste in Microsoft 365: Remove licenses from disabled users. Remove licenses from inactive users. Downgrade licenses on over-licensed users. Stop paying for unassigned licenses. Redefine the license terms. NOTE: I have the steps using the admin center, PowerShell, and a third-party app, but it's too long to re-post in Reddit. Go to Microsoft 365 License Audit to see all the steps. Find Disabled Users Log in to the Microsoft 365 admin center. Users > Active Users > Export > Continue. Open the spreadsheet. In the Home Ribbon, click Sort & Filter > Filter Click the dropdown in the Licensed column > uncheck Unlicensed > click OK Click the dropdown in the Block credential column > uncheck FALSE > click OK. Find Inactive Users NOTE: You need to either have a Microsoft Entra P1 license or use a third-party app to get this data. Open Microsoft Entra Admin Center Users > Manage view > Edit columns. Remove, replace, or add so the only columns you can see are: Display name, User principal name, User type, Identities, Assign licenses, and Last interactive sign-in time. Click Save. Click Download users > Start bulk operation Wait for the success pop-up message to appear, then click the notification bell at the top of the page. Under the notifications menu, click Success!, and then select the [report name]. Open the downloaded spreadsheet. Click Sort & Filter > Filter to enable the column filters. Click the drop-down in the assignedLicenses column. Uncheck any empty options, i.e., []. Click OK. Click the drop-down in the signInActivity column. Click Sort A to Z. Any users who have an empty signInActivity or a sign-in that was over 30 days ago can be safely disabled, and the license removed after the data is properly secured. Find Downgradable Users Review the report located on the website, then click Export. Open the CSV in Excel. Next, download the Microsoft 365 apps spreadsheet by going back to Reports > Usage and clicking View More located under “Active users - Microsoft 365 Apps” Review the report and click Export. You can start by deleting everyone that you’ve already determined hasn’t logged on or is currently disabled. Add the filter by clicking Sort & Filter in the home ribbon > Filter. Add a column for Current Licenses. Copy the licenses from the How To Use The Admin Center To Find Inactive Users spreadsheet you downloaded earlier into the new column. Be sure to align the user names in both spreadsheets. Add a column for Microsoft 365 Apps. Copy the Last Activity Date column from the Pro Plus Usage report you downloaded above in step 7 into the Office 365 app usage spreadsheet you’ve been using. Be sure to align the new data with the appropriate users in the Office 365 app usage report. For each of the following columns, click the drop-down next to the column name and filter out any logins that have happened in the last month. OneDrive Last Activity Date SharePoint Last Activity Date Skype For Business Last Activity Date Yammer Last Activity Date Team’s Last Activity Date Microsoft 365 Apps The users who have not been filtered out are excellent candidates for Exchange Online-only licenses. You may want to double-check their usage of other apps before making any license changes on their accounts. Find Unassigned Licenses Open the Microsoft 365 admin center. Click Show All > Billing > Licenses. On that webpage, you’ll see a list of all your licenses in your organization, along with a column labeled “Available Licenses”. Any number above 0 in the Available Licenses column is typically safe to remove from your organization with two caveats. Some licenses aren’t assigned to users through the Microsoft 365 admin center. NOTE: Some licenses are consumed as they are used. For example, additional storage licenses for SharePoint Online may show as available, but removing them will decrease the amount of free space available in SharePoint Online and possibly cause a disruption to SharePoint Online usage. Redefine The License Terms Microsoft adjusted its pricing model, charging different rates for the same license based on commitment terms, billing frequency, or sector-specific eligibility. The subscription length Billing Frequency Go to the Microsoft 365 admin center Click Billing > Licenses > Select the license you want to review. Click ellipsis (…) next to the subscription > Manage subscription settings. You can view the billing settings right on this page.142Views1like3CommentsMicrosoft Customer Agreement created without Billing Profile after CSP deauthorization
I am the Global Administrator of a Microsoft 365 tenant that previously had an Exchange Online Plan 1 subscription supplied through Endurance International Holding B.V. (Bluehost). This is not a mailbox migration issue. My mailbox already resides in Exchange Online within my existing Microsoft 365 tenant. The only intended change is to move from the former Cloud Solution Provider (CSP) to direct Microsoft billing after the CSP was deauthorized. The Partner Relationships page now displays: Endurance International Holding B.V. (Netherlands)'s account is closed. Find a new partner using Partner app finder or buy from Microsoft directly. Following Microsoft's guidance, I have: Created a Microsoft Customer Agreement (MCA) Created a Billing Account ("Pecten Development") Added and verified a SEPA payment method Updated the Sold-to and Technical Contact details However: Purchasing Exchange Online Plan 1 continually requests a Billing Profile. Completing the Billing Profile workflow never creates one. My Billing Account contains no Billing Profile or Billing Scope. Azure Cost Management reports that there is no supported billing account or subscription. I therefore cannot purchase Exchange Online Plan 1 directly from Microsoft before the existing subscription expires. I have also confirmed that: The former reseller account is closed. There are no delegated partner roles remaining. Microsoft support repeatedly directs me back to the former CSP. Bluehost have confirmed they can no longer escalate through Microsoft CSP channels because their reseller relationship has ended. My current diagnosis is that the Microsoft Customer Agreement has been created successfully, but the associated Billing Profile/Billing Scope was never provisioned. This leaves the tenant unable to purchase services directly from Microsoft despite the former CSP relationship having been closed. Has anyone encountered this after a CSP deauthorization? Does this require intervention by the Microsoft Commerce team, or is there another way to force creation of the missing Billing Profile? If a Microsoft moderator requires my tenant ID or billing account details, I would be happy to provide them by private message. Thank you.57Views0likes1CommentPlanning a Google Workspace to Microsoft 365 Migration? What Should You Consider?
Hi everyone, Has anyone recently migrated from Google Workspace to Microsoft 365? I’m interested in knowing what challenges you faced during the migration, especially around mailbox data, calendars, contacts, user mapping, or the final cutover process. For those planning the migration, what are the key things you recommend preparing before getting started? Would like to hear your experiences and suggestions.50Views0likes2CommentsStrange redirect when signing in - phishing?
I just restarted my Business Standard 365 license today and this afternoon got an email from email address removed for privacy reasons with the following content: But when I clicked on the 'Verify payment information' button I am redirected to a page with the following URL: https://admin.cloud.microsoft/Error/UnAuth?errorCode=100014 looking like this: This looks highly suspicious (Times New Roman font, URL with no top-level extension such as .com, unusual graphics). Is this legitimate or a phishing attempt? Now, when I try to login to admin.microsoft.com to check my account the same suspicious "Sign out and login with a different account" page pops up repeatedly.170Views0likes6Comments