Locked out of new Microsoft Tenant due to Authenticator

Posted by AmbassadorSerious450@reddit | sysadmin | View on Reddit | 11 comments

Hi everyone,

First off, I feel incredibly foolish having done this.

A few hours ago, I bought some Power BI Pro licenses and set up my tenant using a new domain. I only set it up for business emails for now and don't have a live website yet. During the setup, when it asked if I had a website, I selected no (which, in hindsight, was a mistake), so it created the tenant with the default onmicrosoft.com domain.

During this process, I also configured 2FA using Microsoft Authenticator for the global admin account under that default domain.

Later on, I decided to add and verify my custom domain before bringing in my users. Once that was successfully done, I went ahead and updated the admin account to use the new custom domain just to get it out of the way.

Then, for some reason, I decided to remove the old admin account from my Authenticator app before adding the updated one. Now, Authenticator is asking for an app verification code just to let me add the account back, so I'm completely stuck in a loop.

Current status: I am actually still signed in to the admin account in my browser right now, but I can't change or reset any security info because any modifications require a 2FA prompt.

Here is what I have tried so far to recover access:

Since I am the sole administrator on this brand-new tenant, I am completely locked out. Is there any other way to recover the account or escalate this to the Data Protection team?

Thanks in advance for any help!