logo
search
Password & Account Recovery

How to Recover Microsoft 365 Global Admin Account After Employee Leaves

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

The organization needs to regain administrative access to their Microsoft 365 tenant after the only global administrator left the company without providing access credentials or authentication methods.

Product
Microsoft 365
Device & OS
not provided
Scenario
The sole global administrator for an organization has left, and the mobile phone previously used for Multi-Factor Authentication (MFA) is unavailable, locking the organization out of the admin portal.
Observed behavior
The organization is entirely locked out of the Microsoft 365 admin center, preventing them from renewing user licenses, managing accounts, or performing any administrative tasks.
Before you start

Before calling support, gather your organization's official documentation, such as billing invoices, domain registration details, and company incorporation papers, as Microsoft will require these to verify your legal identity.

Solution 1Recommended

Contact Microsoft 365 Business Support by Phone

Since this is a sensitive security issue, the only official method to regain access to a tenant with no remaining global administrators is to contact Microsoft's Data Protection team directly.

Public forums and standard self-service password reset portals cannot resolve an issue where the only admin account's MFA is inaccessible. Microsoft must perform manual identity verification.

1
Locate the support number

Visit the official Microsoft 365 Admin support contact info page online to find the dedicated business support phone number for your specific country or region.

2
Navigate the automated system

Call the support number and follow the automated prompts, clearly stating that you are completely locked out of your global administrator account and have no other admins available.

3
Provide tenant details

Give the initial support agent your tenant name, associated custom domain (e.g., yourcompany.com), and basic organizational details to open a support ticket.

4
Verify identity with Data Protection

Wait for a callback from the Microsoft Data Protection team. They will guide you through the process of submitting legal documentation to prove you own the organization before manually restoring access.

Free Microsoft Office alternative

Switch to WPS Office for a Hassle-Free Experience

While managing complex administrative roles and user licenses in Microsoft 365 can be challenging and restrictive, WPS Office provides a free, lightweight, and incredibly easy-to-use alternative. Perfect for individuals and teams, it lets you focus on your work rather than dealing with complex tenant management and access lockouts.

Fully compatible with Microsoft Office formats including .docx, .xlsx, and .pptx.No complex global administrator setup or tenant management required for everyday document tasks.Lightweight suite that runs smoothly across Windows, Mac, Linux, iOS, and Android.Familiar user interface ensuring a seamless migration from Microsoft Office.
microsoft office alternative - wps office

Frequently Asked Questions

How long does it take for Microsoft to recover a global admin account?

The recovery process can take anywhere from a few days to a couple of weeks. Because Microsoft treats tenant takeovers as a highly sensitive security matter, the Data Protection team must thoroughly review your legal documentation before granting access.

Can I reset the global admin password if I have access to our custom domain's DNS?

No, simply having access to your domain's DNS records or web hosting is not enough to reset a global admin password if you do not have the required Multi-Factor Authentication (MFA) device. You must go through official Microsoft support to bypass the MFA requirement.

What is a break-glass account in Microsoft 365?

A break-glass account is an emergency global administrator account that is rarely used. It is typically excluded from standard conditional access policies that require personal mobile MFA, instead using a highly secure password stored in a physical or digital safe to prevent complete organization lockouts.