logo
search
MFA & Verification Issues

How to Recover Microsoft 365 Admin Access When MFA is Linked to a Former Employee

Maira MehtabMaira Mehtab Sep 21, 2026 869 views

Question details

The organization cannot access their Microsoft 365 administrator account because the Multi-Factor Authentication (MFA) codes are sent to a former employee's phone.

Product
Microsoft 365
Device & OS
not provided
Scenario
A network manager left the company without transferring Microsoft 365 admin access, leaving the company with the username and password but no access to the MFA device.
Observed behavior
The login process is blocked at the MFA verification step, as the required authentication codes are sent to an unavailable phone number.
Before you start

Gather your Microsoft 365 subscription details, company information, and domain registration credentials, as Microsoft Support will require these to verify tenant ownership.

Solution 1Recommended

Contact Microsoft Business Support to Reset Admin MFA

Since you do not have access to the registered MFA phone, you must contact Microsoft Support to bypass or reset the administrator authentication method.

Only authorized Microsoft support personnel can assist with administrator MFA lockouts when the original authentication method is unavailable.

1
Call Microsoft Business Support

Dial the Microsoft business support phone number for your specific country or region.

2
Navigate the Phone Menu

Select the automated options related to Authenticator, Office 365 for business, company account, administrator, and service request.

3
Request Escalation

Once connected to a representative, explain that the sole administrator left the company and ask them to escalate the case to the Data Protection team.

4
Verify Ownership

Provide your company information, subscription details, and proof of ownership as requested by the data protection team to verify your identity.

5
Update MFA Settings

After Microsoft restores your access, immediately update the tenant's administrator accounts and configure organization-controlled MFA methods to prevent future lockouts.

Verification Timeframe: Identity verification by the Data Protection team can take several days depending on the provided proof of ownership.
Free Microsoft Office alternative

Looking for a Hassle-Free Office Suite? Try WPS Office

While you are resolving complex administrative and MFA issues with Microsoft 365, consider WPS Office as a lightweight, free alternative for your organization's daily document needs. It offers seamless compatibility with Microsoft formats without the complicated backend tenant management.

  1. 1. Download WPS Office: Visit the official WPS Office website to download the free installer.
  2. 2. Install the Suite: Run the downloaded file and follow the simple on-screen instructions to complete the setup.
  3. 3. Start Creating: Launch WPS Office to seamlessly open, view, and edit your existing Microsoft Office documents.
Highly compatible with Microsoft Word, Excel, and PowerPoint formats.Free and lightweight office suite with no complex tenant management required.Familiar user interface for easy employee transition and minimal learning curve.Built-in PDF editing tools to handle all your document workflows.
QA img-10

Frequently Asked Questions

Can I bypass Microsoft 365 MFA without contacting support?

No, if you are the only global administrator and you lose access to your MFA device, you must contact Microsoft Data Protection to verify your identity and securely reset the authentication method.

What information is needed to prove ownership of a Microsoft 365 tenant?

You will typically need to provide your company details, billing information, the credit card numbers used for the subscription, or you may be asked to add a specific TXT record to your organization's DNS settings.

How can I prevent getting locked out of the Microsoft 365 admin center in the future?

It is highly recommended to set up at least two Global Administrator accounts (often called 'break-glass' accounts) and ensure MFA methods are tied to company-controlled devices or shared authenticator apps rather than personal employee phones.