A cloud-based identity and access management service for securing user authentication and resource access
A call cannot be placed, but there are supported ways to regain access and then transfer Global Administrator rights.
Because the current Global Admin account is locked behind a broken two‑step verification loop and there is no other admin available, this is treated as a tenant lockout scenario. In this case, only Microsoft’s Data Protection team can restore access or reset the admin’s authentication methods.
Follow these steps:
- Contact Microsoft support and reach the Data Protection team
- Use the regional phone number listed under Customer service phone numbers - Microsoft Support.
- When the automated system asks what the problem is, answer along these lines (based on the documented flow):
- Problem: say “Authenticator” or “two-step verification”.
- Product: “Office 365 for business” or “Microsoft 365 for business”.
- Account type: “Company account”.
- Are you an administrator?: “Yes”.
- Are there any other administrators?: “No”.
- When asked if a service request is needed: “Yes, I need to create a ticket and speak with the Data Protection team.”
- Clearly state that:
- You are the only Global Administrator.
- You are locked out due to two‑step verification / Microsoft Authenticator.
- You need admin access restored so you can manage the tenant and transfer Global Admin rights.
- The Data Protection team has specific tools and processes to verify identity and restore access when the sole Global Admin is locked out.
- Alternative path if phone support is difficult to reach
- If support cannot be reached directly from the locked tenant, create a temporary trial tenant as documented in the Q&A guidance:
- Sign up for a Microsoft 365 trial (business/enterprise) to create a new tenant.
- Sign in to the new tenant’s Microsoft 365 admin center.
- Go to Support → Help & support and open a ticket.
- In the ticket, clearly state that:
- You are contacting support from a temporary trial tenant.
- You are locked out of a different, existing Microsoft 365 tenant where you are the only Global Admin.
- Provide the locked tenant’s domain and admin UPN, and describe the MFA/two‑step issue.
- Request escalation to the Data Protection team to restore access to the original tenant.
- This trial tenant is only a channel to reach support; it does not give access to the original tenant’s data.
- If support cannot be reached directly from the locked tenant, create a temporary trial tenant as documented in the Q&A guidance:
- After access is restored
Once the Data Protection team has helped you sign back in as Global Admin on the original tenant:
- Sign in to the Microsoft 365 admin center for the original tenant.
- Add the new account (for example, the
@OmegaDispatchingOps.comuser) as a user if it does not already exist. - Assign the Global Administrator role to that user:
- Follow the steps in Add an administrator from the admin roles documentation.
- Verify that the new Global Admin can sign in and has access.
- Optionally, reduce privileges on the original account if desired, following the least privilege principle.
- Prevent future lockouts
- Create at least two emergency access (“break glass”) accounts that:
- Are assigned the Global Administrator role.
- Are not tied to specific individuals and are used only in emergencies.
- Are excluded from MFA policies and protected with long, complex passwords.
- This ensures that if a primary Global Admin is locked out by MFA again, emergency accounts can be used to recover access.
- Create at least two emergency access (“break glass”) accounts that:
If the organization already has another Global Admin, that admin can instead sign in and reset the locked admin’s password or MFA methods directly, without needing Data Protection.
References:
- Troubleshoot sign-in issues and account access problems
- All about passwords
- Common problems with two-step verification for a work or school account
- Add and manage admin accounts
- Admin account security in Microsoft 365 for business
- Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A