A cloud-based identity and access management service for securing user authentication and resource access
Updated todo list
Hi Danny
Losing the only Global Admin's MFA method and getting stuck waiting on support is a rough spot, but there are a few self-service paths depending on what you still have access to.
If you have a second Global Admin account (even one nobody normally uses), sign in with that and go to the Microsoft Entra admin center > Users > find your locked account > Authentication methods > Reset or remove the old authenticator, then register a new one. This is by far the fastest fix if it's available to you.
If you're truly the sole Global Admin with no other privileged account and no working MFA method at all, check whether your tenant has a break-glass emergency access account set up — these are meant to be excluded from MFA/Conditional Access for exactly this scenario. If one exists, sign in with it and fix the authentication method on your regular admin account from there.
If neither of those exist, you'll need Microsoft's Global Admin recovery process, which does require proof of ownership of the tenant (domain verification, billing info, etc.) — this only goes through support, so unfortunately there's no way around the wait for that specific path. To speed it up: make sure you opened the case as a "Sign-in" or "User and licensing management" issue under Entra ID in the admin center rather than a general request, mark it as Severity A / business-critical since you have zero admin access, and if you have a Premier/Unified support contract, call the phone line directly rather than only using the web ticket — phone escalations for full admin lockout usually move much faster than portal tickets.
For next time: setting up a proper break-glass account (cloud-only, excluded from all Conditional Access, strong password, monitored) is the standard fix so this can never happen again.
Let me know which of these applies to your situation and I can narrow it down further.