Managing security settings and protections in Outlook on the web for business
Dear @White Ella,
I understand how critical this issue is, especially for a business account where work, communications, and company data are affected.
When a Microsoft 365 Business (work or school) account is compromised and contact details are changed, the account recovery process differs from personal accounts. You cannot recover a business account using standard personal recovery forms.
Here are the steps to regain access:
Step 1: If you are end user:
If you are an end-user or employee, contact your organization’s IT Helpdesk or Microsoft 365 Global Administrator.
- They will go Microsoft 365 admin center > go to the Microsoft Entra admin center (formerly Azure AD).
- They will select your user profile and choose Require re-register MFA (or delete your old authentication methods).
- Once reset, the next time you sign in, you will be prompted to set up the Microsoft Authenticator app from scratch on your new device without being asked for a previous code.
For official steps your administrator can follow, please refer to Microsoft's documentation on Manage authentication methods for Microsoft Entra multifactor authentication - Microsoft Entra ID |…
Step 2: If You Are the Only Global Administrator
If your account is the sole Admin account and you are completely locked out, you must contact Microsoft Data Protection Support directly by phone. For security reasons, Microsoft online agents cannot alter Admin account details without identity verification through this specialized team.
Find the support telephone number for your region here: Find Microsoft 365 for business support phone numbers by country or region.
When calling, explain that you are the Global Administrator locked out of your tenant due to account compromise and modified MFA/security details, and request an escalation to the Data Protection Team.
Be prepared to verify your identity and organization details (such as domain registration, billing records, or tax information) to prove ownership of the tenant.
Once access is restored, ensure the following steps are taken:
- Revoke all active user sessions from the Admin Center.
- Audit Azure AD / Entra ID audit logs to check for created backdoor accounts, new mail flow rules, or unauthorized application permissions.
- Re-enable Strong Multifactor Authentication (MFA) and update all emergency recovery options.
For official Microsoft guidance on handling compromised business accounts, please refer to Responding to a Compromised Identity in Microsoft 365.
If the answer is helpful, please click "Yes" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in the forum document to enable e-mail notifications if you want to receive the related email notification for this thread.