Share via

Unable to access Microsoft 365 admin account due to lost Microsoft Authenticator (MFA)

Marcel Wittmann 20 Reputation points
2026-03-11T18:28:31.65+00:00

Hello,

I am the owner of a Microsoft 365 Business subscription that is connected to my custom domain. I can still sign in with the admin username and password, but I cannot complete the login because Microsoft Authenticator (MFA) is required. Unfortunately, I lost access to the authenticator after changing my mobile phone, and the old device is no longer available. Because of this, I am currently locked out of the admin account and cannot manage my Microsoft 365 tenant.

Important details:

  • The Microsoft 365 subscription is still active and billed monthly.
  • I have access to the domain and DNS management.
  • I know the admin username and password.
  • The only issue is that I cannot provide the Microsoft Authenticator code.

I would like to request assistance with the official recovery process and an MFA reset for the admin account.

I can provide any verification required, such as:

  • Domain ownership verification
  • Billing information
  • Tenant details
  • Identity verification

Thank you for your assistance.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-11T18:28:55.9466667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Because the account is protected by Microsoft Entra multifactor authentication and there is no longer access to the Microsoft Authenticator app or any alternative MFA method, the admin account cannot be recovered or changed from within the tenant itself. The official recovery path depends on whether there is another global administrator.

    1. Check if there is another global administrator
    • If any other global admin exists in the tenant, that admin can reset MFA for the locked-out admin:
      1. Sign in to the Azure/Microsoft 365 portal as a global admin.
      2. Open Microsoft Entra ID (Azure AD) and go to Users.
      3. Select the locked-out admin account.
      4. Open Authentication methods.
      5. Select Require re-register multifactor authentication and save.
      6. Next time the locked-out admin signs in, the portal will prompt to set up MFA again on the new phone.
    1. If there is no other global administrator (sole admin scenario) When the locked-out user is the only global admin, MFA reset must be handled by Microsoft’s Data Protection team via a support request. Forum moderators and normal support channels cannot directly change MFA or passwords for security reasons.

    Use these supported options:

    Option A – Call Microsoft global customer service (recommended)

    1. Call the appropriate number listed under Customer service phone numbers - Microsoft Support.
    2. When interacting with the IVR/agent, clearly state:
      • The issue is with Microsoft Authenticator / MFA.
      • The product is Office 365 / Microsoft 365 for business.
      • The account is a company (work) account, not education or personal.
      • The caller is the only global administrator for the tenant.
      • Access to Microsoft Authenticator was lost due to a phone change, and MFA reset is required.
    3. Ask specifically to open a service request with the Data Protection / Tenant Recovery team for an admin MFA reset / tenant lockout.
    4. Be prepared to provide verification such as:
      • Domain ownership (DNS or WHOIS details).
      • Billing/subscription information.
      • Tenant name and admin UPN.
      • Any other identity or business verification they request.

    Option B – Create a temporary trial tenant to open a ticket (fallback) If it is not possible to reach the correct support team directly by phone:

    1. Sign up for a new Microsoft 365 trial tenant (separate from the locked tenant).
    2. In that new tenant, go to the Microsoft 365 admin center and open Support → Help & support.
    3. Create a support request explaining:
      • The new tenant is only for contacting support.
      • The real problem is a lockout from a different existing tenant where the caller is the only global admin.
      • Provide the locked tenant’s domain, admin UPN, and a clear description that an MFA reset / Data Protection escalation is needed.
    4. Work with support as they escalate to the Data Protection team, who will verify ownership and help restore access.
    5. If another admin exists but is not available If there is technically another global admin (for example, a partner or reseller) but that admin cannot be reached, treat the case as a sole-admin lockout and follow the Data Protection route above. If the subscription was purchased via a partner, that partner’s support can also open a service request with Microsoft on behalf of the tenant.
    6. General notes and limitations
    • Microsoft support agents and community moderators cannot send verification codes, bypass MFA, or directly modify security info without going through the Data Protection process.
    • Having the domain, DNS, billing data, and credentials is helpful, but the MFA reset still must be processed by Microsoft’s protected support workflow.
    • Once the Data Protection team resets MFA or clears authentication methods, sign-in will prompt to register MFA again on the new phone (for example, by reconfiguring Microsoft Authenticator).

    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.