When you lose entry to your primary administrative account, managing user licenses, resetting employee passwords, and configuring Exchange email settings immediately comes to a halt. Lockouts typically occur due to a forgotten password, a lost multi-factor authentication (MFA) device, or the sudden departure of the sole IT administrator. This troubleshooting guide explains the exact workflows on restoring Global Administrator Access to a Microsoft Business Account based on your tenant's configured recovery methods.
Method 1: Use Self-Service Password Reset (SSPR)

The fastest route for restoring Global Administrator Access to a Microsoft Business Account is using the automated self-service portal. This method only works if you previously registered an alternate email address or a mobile phone number within your Azure Active Directory security profile before the lockout occurred.
Navigate directly to passwordreset.microsoftonline.com in an incognito or private browsing window to avoid conflicting cached credentials. Type your full administrator email address into the User ID field, complete the CAPTCHA characters, and click Next. The portal will present your pre-configured verification options. Select either Email my alternate email or Text my mobile phone.
Retrieve the verification code from your secondary device, input it into the text field, and click Next. Enter your new secure password twice to confirm it. Once the portal displays a success message, open a new browser tab and navigate to admin.microsoft.com. Sign in with the new credentials. The expected result is immediate access to the admin dashboard, verifying that your privileges are fully restored.
Method 2: Leverage an Alternate Administrator Profile
If self-service recovery is not configured, the next logical step in determining restoring Global Administrator Access to a Microsoft Business Account is to utilize another active user who holds Global Admin privileges. Microsoft best practices dictate maintaining at least two independent administrative accounts specifically for this "break glass" scenario.
Instruct the secondary administrator to log into the Microsoft 365 Admin Center at admin.microsoft.com. On the left-hand navigation menu, click Users, then select Active users. Use the search bar to locate your locked administrator account. Click directly on the display name to open the user properties flyout pane on the right side of the screen.
Click the Reset password icon (represented by a key). Select the radio button for Let me create the password and type a temporary credential. Check the box labeled Require this user to change their password when they first sign in to ensure security compliance. Click Reset password at the bottom of the pane. The secondary admin must then securely provide you with this temporary password. Log in, establish your permanent password, and verify that you can access the billing and security centers.
Method 3: Contact the Azure Data Protection Team via Domain Verification
When you are the sole administrator and SSPR is unavailable, you must escalate the issue directly. To resolve restoring Global Administrator Access to a Microsoft Business Account under a total lockout, you must prove domain ownership to the Azure Data Protection team so they can manually bypass the security lock on their backend.
Dial the Microsoft Business Support phone number specific to your region. When the automated voice system prompts you for the reason for your call, state exactly: Cannot access admin account. The routing system will direct you to the Data Protection team. Explain that you are the sole Global Admin and are entirely locked out. The agent will require you to prove ownership of the business domain linked to your tenant (e.g., yourcompany.com).
The agent will generate a unique TXT record value (typically starting with MS=). Log into the control panel of your domain registrar (such as GoDaddy, Cloudflare, or Namecheap). Navigate to the DNS Management or Zone Editor page. Add a new record, set the type to TXT, set the name/host to @, and paste the Microsoft-provided string into the Value field. Save the DNS settings. The support agent will query your domain; once the TXT record propagates and verifies your identity, they will generate a temporary password and send it to an alternate email address. This security verification process generally takes between 24 and 72 hours.
Managing Local Business Documents with WPS Office During Lockouts

While you wait for Microsoft support to process your request regarding restoring Global Administrator Access to a Microsoft Business Account, you will temporarily lose the ability to manage cloud-hosted SharePoint files, assign Microsoft 365 licenses, or access web-based Office applications. WPS Office cannot change that Microsoft-side setting, unlock Azure Active Directory accounts, or bypass MFA requirements. However, if your underlying goal is to keep your business running by editing local contracts, spreadsheets, or presentations during this administrative lockout, WPS Office provides a highly capable offline workflow.
WPS Office installs locally on your Windows, Mac, or Linux machine and operates independently of Microsoft 365 cloud authentication. To continue working on critical files, locate the existing `.docx`, `.xlsx`, or `.pptx` files on your local hard drive. Right-click the document, select Open with, and choose WPS Writer, Spreadsheet, or Presentation. You can edit formatting, run formulas, and adjust slide layouts directly. Because WPS Office utilizes a standalone licensing model (including a free tier), you do not need to authenticate against your locked Microsoft business tenant to save your progress.
If you need to execute client contracts while your cloud email is inaccessible, open the document in WPS Writer and use the built-in PDF tools. Click the Export to PDF button on the top ribbon, apply a digital signature using the PDF toolkit, and save the finalized file to your desktop. You can then attach this PDF to a secondary business email or send it via a local client, bypassing the locked cloud infrastructure entirely.
Frequently Asked Questions
Can a standard user reset a Global Administrator account?
No, a user assigned standard permissions cannot reset an administrative password or alter security settings. Only another user explicitly assigned the Global Administrator or Privileged Authentication Administrator role within the Azure Active Directory can reset the credentials of a peer administrator.
How long does the Data Protection team take to verify domain ownership?
While adding the required DNS TXT record at your domain registrar typically propagates across global servers within 15 to 30 minutes, the Microsoft Data Protection team requires a rigorous manual security review to prevent unauthorized tenant takeovers. Expect the entire identity verification, review, and password reset process to take anywhere from one to three full business days.
Will resetting the admin password log out active sessions?
Yes, changing the password via the self-service portal, through a secondary administrator, or via Microsoft support automatically invalidates existing authentication tokens. All devices, browsers, and mobile applications currently signed into the affected administrator account will prompt the user to authenticate with the new password within approximately one hour.
What if my business domain is managed by a third-party partner?
If your Microsoft 365 business tenant was purchased and provisioned through a Cloud Solution Provider (CSP) or an IT reseller, that partner holds delegated administrative privileges over your environment. You must contact the third-party reseller's support desk directly. Their technicians can access your tenant through their partner portal and immediately execute a password reset without needing to escalate the ticket to Microsoft's Data Protection team.




