can't login with only azure admin

Adel Sadek 0 Reputation points
2024-09-28T09:25:38.51+00:00

we can not login with our only one global admin user which have a MFA with microsoft authenticator on lost phone without any backup and there isn't any admin user on this tenant .

we opened ticket and no one reply since about 6 days .

what can we do ?

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
6,790 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,649 questions
{count} votes

5 answers

Sort by: Most helpful
  1. SUNOJ KUMAR YELURU 14,051 Reputation points MVP
    2024-09-28T10:08:30.2766667+00:00

    Hello @ADEL SADEK

    Sorry to hear on facing this issue.

    Try with the below alternative option.

    1. filling out the account recovery form Microsoft account recovery form follow the link and submit the details

    Or

    1. You can re-add the authenticator and other authentication methods on https://myapps.microsoft.com/ After login, Navigate to your profile located at the upper right corner of your screen. Select "View Account." > Security Info >Add sign-in Method > select Authenticator App

    If the Answer is helpful, please click Accept Answer and up-vote, so that it can help others in the community looking for help on similar topics.

    0 comments No comments

  2. NoOneCan 250 Reputation points
    2024-09-29T08:11:30.44+00:00

    Based on other users' experience. If the ticket has already been escalated to the data protection team, it may take a few weeks to be resolved.

    0 comments No comments

  3. akinbade abiola 16,555 Reputation points
    2024-09-29T12:33:52.5766667+00:00

    As u dont have access to the app anymore, the only way to resolve this is to request for Product Support to reset MFA for the affected user for microsoft accounts. Contact Product Support with the email address for the affected user. https://azure.microsoft.com/en-us/support/create-ticket

    See: https://learn.microsoft.com/en-us/xandr/curate/troubleshooting-multi-factor-authentication-mfa?source=recommendations#dont-delete-mfa-app

    But since you already created a ticket, I will recommend you use the Global Support numbers:

    https://support.microsoft.com/en-us/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2

    You can mark it 'Accept Answer' and 'Upvote' if this helped you

    0 comments No comments

  4. A SIVAGAYATHRI 0 Reputation points
    2024-09-29T13:10:01.6633333+00:00

    If you're unable to log in with the only Global Admin account due to a lost phone and MFA without backup, and there are no other admin users, your options are:

    1. Contact Microsoft Support directly via their emergency support channels or escalate the ticket by calling the support hotline.
    2. Use the Azure AD account recovery if any recovery methods were set up, like alternative email or phone.
    3. Register a new Global Admin using the billing account owner’s privileges if possible.

    Keep pushing the support ticket for an urgent resolution.

    0 comments No comments

  5. Sandeep G-MSFT 19,021 Reputation points Microsoft Employee
    2024-10-03T05:02:56.42+00:00

    @Adel Sadek

    Thank you for posting this in Microsoft Q&A.

    As I understand you are unable to access Azure using Global admin account as you have lost the phone on which Microsoft authenticator app is configured.

    In this situation you have only one option to recover the Global Admin account.

    If you are the only global admin on the account and are blocked entirely, you can reach out to our support team. You can look into below article to get support numbers depending on your country.

    https://support.microsoft.com/en-us/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2

    or creating a ticket through a different account:  https://learn.microsoft.com/en-us/microsoft-365/admin/get-help-support?view=o365-worldwide#phone-support

    Create a ticket with Microsoft support team. Give them the tenant ID which is locked out in your description. Tell them that no admin account has access anymore and your partners also have no access anymore.

    Once you create a ticket with support team you will have to work with our data protection team. You will have to first prove your identity against your tenant for security purpose. Post that this team will help you with help you in getting access to your tenant or unlock your account depending on your scenario.

    Also, for the future, you can create an emergency access account (break glass) in Azure AD. This account will help prevent being accidentally locked out of your Azure Active Directory (Azure AD) organization because you can't sign in for any reason.

    https://docs.microsoft.com/en-us/azure/active-directory/roles/security-emergency-access

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

     

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.