How to Recover a Locked Microsoft 365 Global Administrator Account
Question details
The user is entirely locked out of their only Microsoft 365 Global Administrator account due to an MFA loop, an Authenticator app failure, or error 500121, preventing them from accessing the tenant or opening a standard support ticket.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Attempting to sign in to the Microsoft 365 admin center or Entra ID portal but failing due to multifactor authentication (MFA) blocks or Access Denied messages.
- Observed behavior
- The user is trapped in an authentication loop where recovering the account requires admin access, but the locked account is the only admin, making standard online support ticket creation impossible.
Gather your Microsoft 365 Tenant ID, registered domain names, and any alternate email addresses or phone numbers associated with your administrator account before reaching out to support.
Contact the Microsoft Data Protection Team via Phone
When you are the sole global administrator and cannot access your account to create a support ticket, you must call Microsoft's dedicated Data Protection Team to verify your identity.
Because the standard support portal requires an active admin login, a complete tenant lockout (such as Error 500121 or an MFA loop) requires phone verification. The Microsoft Data Protection Team specifically handles these tenant-level lockouts for Entra ID and Microsoft 365.
Locate the global customer service phone number for your specific country or region on the official Microsoft Support website under business contact numbers.
Call the support number and navigate the automated system by clearly stating you are a business customer experiencing a 'Global Admin Account Lockout' or a 'Data Protection' issue.
Provide your Microsoft 365 Tenant ID and registered domain name to the support agent so they can locate your account and initiate the strict identity verification process.

Reset MFA Using an Alternate Global Administrator Account
If your Microsoft 365 tenant has more than one global administrator, the secondary admin can bypass the need for Microsoft support and reset your MFA settings directly.
Switch to WPS Office for a Hassle-Free Productivity Experience
Dealing with complex admin lockouts and MFA loops in Microsoft 365 can severely disrupt your workflow. If you are looking for a lightweight, easy-to-use alternative that does not require complicated cloud tenant management for document editing, try WPS Office. It provides powerful local and cloud tools while maintaining full compatibility with Microsoft file formats.
- 1. Download the software: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the lightweight installer and follow the simple on-screen prompts to complete the setup in minutes.
- 3. Open your files: Launch WPS Office and open your existing Microsoft Office documents to continue working without interruption.

Frequently Asked Questions
What does Microsoft 365 error code 500121 mean?
Error 500121 indicates that authentication failed during the multifactor authentication (MFA) request. This usually happens if the Microsoft Authenticator app is not configured properly, the approval notification timed out, or the account is being blocked by a strict Conditional Access policy.
How can I avoid being locked out as a single global admin in the future?
Microsoft highly recommends creating a 'break-glass' or emergency access account. This is a highly privileged, cloud-only global admin account that is intentionally excluded from standard Conditional Access MFA policies. It should be securely stored and used solely for recovery when the primary admin is locked out.
Can I open a Microsoft 365 support ticket without logging in?
No, standard online support tickets via the Microsoft 365 admin center require an active administrator session. If you are entirely locked out of the tenant, your only option is to call the regional Microsoft business support phone number to reach the Data Protection Team.




