Share via

Only Global Admin Account Locked in MFA Registration Loop (AADSTS50072)

Movaci FSA 0 Reputation points
2026-05-13T00:52:46.48+00:00

Hi Microsoft Support Team

I am unable to access my Microsoft 365 tenant because my Global Administrator account is locked due to Multi-Factor Authentication (MFA). Details:

  • Tenant domain: please email to us we will provide the info 
  • Admin account: please email to us we will provide the info 
  • MFA is enabled, but I cannot approve sign-in via the Microsoft Authenticator app because it requires me to log in first.
  • The alternative method all disabled fails with the error: “Sorry, we’re having trouble verifying your account. Please try again.”

I am the only Global Administrator for this tenant, so I cannot disable MFA or reset authentication methods myself.

Thank you for your urgent assistance.,

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-05-13T00:53:11.7966667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    The account is in an MFA lockout loop with only one Global Administrator on the tenant. This scenario must be handled by Microsoft’s Data Protection team; it cannot be resolved directly from the sign-in page.

    Use the following path based on the documented and Q&A-supported guidance:

    1. Since there is no other Global Admin who can reset MFA:
      • This matches the “only global admin on the account” / “tenant lockout” scenarios described in the Partner Center and Microsoft Q&A guidance.
    2. Contact Microsoft support and ask specifically for the Data Protection / Tenant Recovery (or Microsoft 365 Data Protection) team:
      • Call the appropriate regional support number listed under Customer service phone numbers - Microsoft Support or Get support - Microsoft 365 admin.
      • When prompted by the automated system, clearly indicate that the issue is with Authenticator / MFA and that this is an Office 365 for business / Microsoft 365 for business administrator account.
      • When asked:
        • Product: Office 365 / Microsoft 365 for business.
        • Account type: Company (not education, if that’s correct for the tenant).
        • Role: Administrator.
        • Other admins available: No.
        • Confirm that the tenant’s only Global Admin is locked out due to MFA and cannot complete sign-in.
      • Request that a service request be opened and escalated to the Data Protection team for tenant recovery and MFA reset.
    3. Data Protection team process (per documented guidance and Q&A examples):
      • The Data Protection team has tools and processes to:
        • Verify identity and ownership of the tenant.
        • Regain access to the administrator account.
        • Reset or clear MFA registrations so that the Global Admin can sign in again and re-register MFA methods.
      • Be prepared to provide:
        • The tenant domain.
        • The Global Admin UPN.
        • Business and subscription details, and any requested proof of ownership.
    4. If the tenant is managed through a partner or reseller:
      • If the subscription is from a Cloud Solution Provider or other reseller and the Global Admin cannot open a service request:
        • Ask the partner/reseller’s support to open a Microsoft support ticket on behalf of the tenant and request Data Protection team involvement.
    5. Optional fallback if direct support access is difficult:
      • As described in the Q&A guidance, one possible workaround (if needed) is to:
        • Create a new trial Microsoft 365 tenant purely to gain access to the Microsoft 365 Admin Center.
        • From that new tenant, open a support ticket explaining that the real issue is a lockout from a different existing tenant where the caller is the only Global Admin.
        • Provide the locked tenant’s domain, admin UPN, and error details (e.g., AADSTS50072, MFA loop, SMS verification failure).
        • Ask support to route the case to the Data Protection team for the locked tenant.
        • After resolution, cancel the trial to avoid charges.

    Once Data Protection has reset MFA for the Global Admin, sign-in should proceed and will prompt to re-register MFA methods (for example, Microsoft Authenticator, SMS, or more secure options like passkeys or certificate-based authentication, as recommended in the mandatory MFA FAQ).


    References:

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.