Locked out of new Microsoft Tenant due to Authenticator
Posted by AmbassadorSerious450@reddit | sysadmin | View on Reddit | 11 comments
Hi everyone,
First off, I feel incredibly foolish having done this.
A few hours ago, I bought some Power BI Pro licenses and set up my tenant using a new domain. I only set it up for business emails for now and don't have a live website yet. During the setup, when it asked if I had a website, I selected no (which, in hindsight, was a mistake), so it created the tenant with the default onmicrosoft.com domain.
During this process, I also configured 2FA using Microsoft Authenticator for the global admin account under that default domain.
Later on, I decided to add and verify my custom domain before bringing in my users. Once that was successfully done, I went ahead and updated the admin account to use the new custom domain just to get it out of the way.
Then, for some reason, I decided to remove the old admin account from my Authenticator app before adding the updated one. Now, Authenticator is asking for an app verification code just to let me add the account back, so I'm completely stuck in a loop.
Current status: I am actually still signed in to the admin account in my browser right now, but I can't change or reset any security info because any modifications require a 2FA prompt.
Here is what I have tried so far to recover access:
- "Can't access your account" link: I can pass the first step (email verification) without any issues. However, when I enter my business number for the next step, the dialog just fails/errors out and won't let me move forward.
- Global Customer Service support line: I tried calling the official support number listed for Mozambique, but I keep getting a "this number doesn't exist" network error.
Since I am the sole administrator on this brand-new tenant, I am completely locked out. Is there any other way to recover the account or escalate this to the Data Protection team?
Thanks in advance for any help!
Adamackk@reddit
If youre still logged in, create a new user on the .onmicrosoft.com domain and assign Global Admin.
Sign in to that, set up MFA.
Require MFA reset on the account you removed the authenticator app.
AmbassadorSerious450@reddit (OP)
Thank you. I did exactly this since u/No_Crab_4093 recommended it and it worked great.
iamrolari@reddit
Oof. This is why you always need a break glass GA account
AmbassadorSerious450@reddit (OP)
It's my first time setting up a tenant, but I'll definitely remember the lesson. What do you mean by a break glass account?
No_Crab_4093@reddit
if you are signed in as an admin account, are you able to just create a new user and grant it Global Administrator role and use that??
AmbassadorSerious450@reddit (OP)
Thank you! You are truly a gentleman/woman and a scholar.
I went into full panic mode and this didn't even cross my mind. Worked like a charm, no 2FA required.
djDef80@reddit
Yes make a new account give it global admin role and you should be golden. It does not need a license for this purpose.
xendr0me@reddit
Isn't it going to ask for MFA for this action?
Brilliant-Advisor958@reddit
No once you're signed in you have unfettered access .
He could also go into entra id and just reset his mfa.
english-23@reddit
Unless they setup pim to require MFA but that would surprise me
Watsonwes@reddit
https://www.reddit.com/r/Office365/s/9uPXkBRrIl