logo
search
list

Table of Content

Assigning Global Administrator Privileges to an Existing User
Self-Service Recovery for a Locked Global Administrator Account
Escalation Path for Lost MFA Devices or Complete Tenant Lockouts
Alternative Method: Using Delegated Administration Partners
Use WPS Office for Local Files Related to Assigning or Recover Global Administrator Access in Microsoft 365
Frequently Asked Questions

How to Assign or Recover Global Administrator Access in Microsoft 365

Posted by Chanuka Geekiyanage

calendar

2026-09-08

views

869

likes

4

Managing administrative privileges is the cornerstone of securing your organizational tenant. This troubleshooting guide provides explicit instructions on assigning or Recover Global Administrator Access in Microsoft 365. Whether you are delegating full control to an IT colleague or attempting to regain access after a lockout or a lost multi-factor authentication (MFA) device, these sequential actions will restore operational control over your environment.

Assigning Global Administrator Privileges to an Existing User

To grant the highest-level permissions to a colleague, you must currently possess and be logged in with Global Admin rights. assigning or Recover Global Administrator Access in Microsoft 365 begins with proactive delegation to prevent single points of failure. Having at least two administrators ensures that one can always recover the other.

  1. Navigate to the Microsoft 365 Admin Center and sign in with your current administrator credentials.
  2. On the left navigation pane, click Users to expand the menu, and then select Active users.
  3. Locate the target employee in the user list and click directly on their display name.
  4. In the flyout panel that appears on the right side of your screen, select the Account tab.
  5. Scroll down to the Roles section and click the Manage roles link.
  6. Change the selection from User (no admin center access) by selecting the Admin center access radio button.
  7. Check the box explicitly labeled Global Administrator.
  8. Click Save changes at the bottom of the panel.

To verify the assignment, instruct the newly assigned user to log into the Admin Center. They should now see many advanced navigation options on the left pane, including the Billing, Security, and Compliance centers.

Self-Service Recovery for a Locked Global Administrator Account

Illustrated steps for Assigning or Recover Global Administrator Access in Microsoft 365
Key actions for Assigning or Recover Global Administrator Access in Microsoft 365.

If you are locked out due to a forgotten password but still possess your MFA device, you must use the self-service password reset (SSPR) mechanism. When querying assigning or Recover Global Administrator Access in Microsoft 365, this is the most common diagnostic path for a single locked account.

  1. Go to the standard Microsoft online sign-in page.
  2. Enter your administrator email address and click Next.
  3. Click the Forgot my password link located directly beneath the password entry field.
  4. Complete the CAPTCHA challenge on the subsequent screen to prove you are human.
  5. Choose your pre-configured verification method. This will typically be an alternate email address, a mobile phone text message, or an authenticator app code.
  6. Input the verification code received via your chosen method.
  7. Establish a new, strong password and confirm it.

Upon completion, the expected result is immediate restoration of access. Return to the Microsoft 365 Admin Center and authenticate using the newly created credential.

Escalation Path for Lost MFA Devices or Complete Tenant Lockouts

When SSPR fails—usually because the primary administrator lost the smartphone containing their authenticator app and no backup administrator exists—standard recovery workflows fail. In this severe scenario, working to assign or recover Global Administrator access in Microsoft 365 requires direct intervention from Microsoft's internal security teams.

  1. Contact Microsoft Business Support by phone. Dial the specific toll-free business support number for your region. In the United States, dial 1-800-865-9408.
  2. Navigate the automated voice system by stating clearly that you are experiencing an "Admin account lockout" and require immediate escalation to the Data Protection team.
  3. Provide your exact tenant domain (e.g., yourcompany.onmicrosoft.com) and organizational billing details to the frontline agent.
  4. Wait for a secure callback from the Data Protection team.

The Data Protection team will run diagnostic checks requiring you to verify identity through external domain control. You will be asked to log into your DNS registrar (e.g., GoDaddy, Cloudflare) and add a specific TXT record to your domain. Because this is a manual security process, expect it to take between three to five business days before your MFA is wiped and access is restored.

Alternative Method: Using Delegated Administration Partners

If your organization purchased Microsoft 365 licensing through an external Managed Service Provider (MSP), that provider likely holds Granular Delegated Admin Privileges (GDAP). In this case, you can bypass the Microsoft support queue entirely. Contact your MSP's helpdesk; their engineers can log into their Microsoft Partner Center, navigate to your specific tenant portal, and reset your password or assign the Global Administrator role to another active user in your directory without requiring your current password.

Use WPS Office for Local Files Related to Assigning or Recover Global Administrator Access in Microsoft 365

WPS Office options related to Assigning or Recover Global Administrator Access in Microsoft 365
How WPS Office can support related document work.

Because complete tenant lockouts sever access to cloud-hosted Office applications and OneDrive synchronization, productivity often halts. WPS Office cannot alter Microsoft cloud administration settings or bypass Active Directory restrictions when you are working to assign or recover Global Administrator access in Microsoft 365. However, it serves as a highly effective localized solution for your underlying document generation needs during a cloud outage.

If your organization relies heavily on continuous document editing, WPS Office allows your team to continue working without active Microsoft account validation or cloud licensing checks.

  • Local File Editing: Open, edit, and save existing Word (.docx), Excel (.xlsx), and PowerPoint (.pptx) files stored on local hard drives. WPS Office maintains strict layout compatibility, ensuring that your data remains intact and formatted correctly while your cloud access is suspended.
  • Integrated PDF Tools: Use the built-in PDF toolkit to merge, digitally sign, and convert PDF documents into editable text formats. This ensures critical contract negotiations or administrative paperwork continues smoothly during the lockout period.
  • WPS AI: Utilize built-in artificial intelligence to generate reports, summarize lengthy local documents, or draft external communications directly within the local Writer application, bypassing the need for Microsoft Copilot.

By installing WPS Office on your Windows, macOS, or Linux devices, you grant your workforce immediate operational capacity, decoupling your daily document workflow from the status of your Microsoft 365 administrative recovery.

WPS Writer app icon
WPS Presentation app icon
WPS Spreadsheets app icon
WPS PDF app icon
Use Word, Excel, and PPT for FREE

Frequently Asked Questions

Can a standard user recover a locked Global Administrator account?

No. Standard users completely lack the directory permission sets required to reset passwords or modify roles for elevated accounts. If a standard user is working to assign or recover Global Administrator access in Microsoft 365, they must physically locate another active Global Administrator within the organization to perform the reset, or request that the registered business owner contact Microsoft Support directly.

How long does the Microsoft Data Protection team take to restore access?

If you are the sole administrator and lose your MFA device, the escalation to the Data Protection team is not instantaneous. Verification, security review, and actual recovery often take between three to five business days, and occasionally longer depending on how quickly you can update external DNS records. This extended timeline underscores the critical need for a secondary break-glass account.

What is the recommended number of Global Administrators for a tenant?

Microsoft officially recommends maintaining between two and four Global Administrators per tenant. Having fewer than two creates a severe single point of failure during an MFA loss. Having more than four dramatically increases the security surface area and risk of a tenant breach. Balancing this number reduces the frequency with which you must research assigning or Recover Global Administrator Access in Microsoft 365.

Does resetting an entire tenant require recovering the original administrator account?

Yes. You cannot simply delete and recreate a Microsoft 365 tenant if you are locked out, because the associated custom domain names remain bound to the locked tenant. Before you can release a domain to use elsewhere, you must successfully complete the process of assigning or Recover Global Administrator Access in Microsoft 365, log in, remove the domain dependencies, and manually deprovision the tenant.

Chanuka Geekiyanage

With over 13 years of hands-on experience in office software and tech, I help users navigate the digital world with ease. From mastering Excel to exploring cutting-edge productivity tools, I break down complex features into simple, actionable steps.