How to Recover Microsoft 365 Admin Account After Losing MFA Access
Question details
The user is unable to sign in to their Microsoft 365 administrator account because they lost access to their Multi-Factor Authentication (MFA) device or method.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Attempting to sign in to the Microsoft 365 Admin Center without the required MFA code generator (such as a lost or broken mobile phone).
- Observed behavior
- Sign-in fails entirely because the required MFA code cannot be provided, resulting in a complete block of administrative access to the tenant.
Before proceeding, check if you previously set up an alternative authentication method (like SMS or a backup email), and ensure you are trying to sign in from a standard supported browser without InPrivate or Incognito mode interference.
Ask Another Administrator to Reset Your MFA
If your organization has multiple global admins, this is the fastest and easiest way to regain access.
Microsoft highly recommends maintaining at least two Global Administrator accounts for this exact scenario. A secondary admin can bypass your lockout by resetting your MFA requirements.
Reach out to another user in your organization who currently holds Global Administrator privileges.
Have the co-administrator sign in to the Microsoft Entra admin center (formerly Azure AD) using their credentials.
Navigate to 'Users' > 'All users' from the left sidebar and select your locked admin account from the list.
Click on 'Authentication methods' in the left menu, then select 'Require re-register MFA'. This clears your old lost device.
Sign in to your Microsoft 365 admin account. You will be prompted to set up Multi-Factor Authentication again using your new device.
Contact Microsoft Data Protection Team (For Solo Admins)
If you are the only global administrator for your subscription, you must contact Microsoft support directly for account recovery.
Run the Microsoft Support and Recovery Assistant
Use this tool to rule out browser cache issues or device compliance blocks masquerading as MFA failures.
Experience Hassle-Free Productivity with WPS Office
While waiting for Microsoft support to recover your admin account, you do not have to pause your work. WPS Office provides a lightweight, highly compatible, and free alternative to Microsoft Office that doesn't rely on complex tenant administration or strict cloud lockouts.
- 1. Download the Software: Visit the official WPS Office website to download the free installation package.
- 2. Install WPS Office: Run the installer and follow the simple on-screen instructions to set up the software on your device.
- 3. Open Your Documents: Launch WPS Office and open your existing Microsoft Office files to resume working instantly without cloud sign-in barriers.

Frequently Asked Questions
How long does it take for Microsoft to recover an admin account?
If you are the only global admin, the Data Protection Team handles your case. This strict verification process typically takes between 3 to 7 business days to ensure no unauthorized access occurs.
Can I bypass MFA if I lost my phone?
No, administrators cannot bypass MFA on their own once enforced. You must either use an alternative authentication method (like a pre-configured SMS or backup email) or have another administrator reset your MFA status.
Why does InPrivate or Incognito browsing cause sign-in errors?
InPrivate browsing blocks certain tracking cookies and prevents device compliance checks required by Microsoft's Conditional Access policies, which can result in immediate sign-in failures regardless of your MFA status.




