Unable to reset MFA for Azure/Entra tenant linked to Azure Free / MSDN subscription

Marco Macca 21 Reputation points
2026-08-06T08:42:09.7533333+00:00

Hello,

I can access my personal Microsoft account without any issue, including its security settings and recovery methods.

However, when I access Azure Portal and try to open Microsoft Entra ID, I am prompted for a Microsoft Authenticator MFA code that I no longer have access to.

The MFA requested by Azure / Entra is different from the verification methods currently configured on my personal Microsoft account.

No alternative verification methods are available on the MFA prompt.

Because of this, I cannot access Microsoft Entra ID and I cannot manage or reconfigure my authentication methods.

I also cannot open a regular support request because the support flow redirects me back to Azure, where I am blocked by the same MFA challenge.

Could a moderator please help me engage the appropriate team for MFA recovery?

I can provide tenant details, subscription details and proof of ownership through private message if required.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Jerald Felix 18,200 Reputation points Volunteer Moderator
    2026-08-07T01:48:23.7466667+00:00

    Hello Marco Macca,

    Greetings! Thanks for raising this question in the Q&A forum.

    This is a known scenario, and it happens specifically because your personal Microsoft account and the Microsoft Entra ID work/school identity tied to your Azure Free or MSDN subscription are two separate identities with separate security settings. Resetting MFA on your personal account does nothing for the Entra tenant identity, and since you are the sole Global Administrator of that tenant with no other admin available to reset your authentication methods from the portal, this becomes a tenant lockout scenario rather than a normal account recovery. Self-service password reset does not help either, because the block is the MFA challenge, not the password. This specific situation can only be resolved by Microsoft's Data Protection / Tenant Recovery team, who manually verify tenant ownership and reset the MFA registration, since there is no self-service or portal-based way to bypass an MFA challenge when no alternate verification method and no second admin exist.

    Do not rely on the standard in-portal support request flow, since as you found, it routes back through Azure and hits the same MFA wall. This is expected in this scenario and is not something a moderator can fix directly from the forum either, since no one outside Microsoft's internal identity recovery team can reset MFA on your tenant.

    Call Microsoft support by phone rather than trying to open a ticket through the portal. Go to the Customer service phone numbers page for your region and call in directly. This bypasses the portal MFA wall entirely since it does not require you to be signed in first.

    When speaking to the agent or navigating the IVR, state the situation precisely. Say that the issue is with Microsoft Authenticator and MFA, that this involves a Microsoft Entra ID tenant tied to an Azure Free or MSDN subscription, that you are the sole Global Administrator, and that there are no alternate verification methods or other admins available to reset it for you. Explicitly ask to be routed to the Data Protection or Tenant Recovery team, since this is the specific team with tools authorized to reset MFA for a sole locked-out Global Admin after identity verification.

    Have your tenant identification ready before the call. This includes your tenant's default domain name (the .onmicrosoft.com name), your Azure subscription ID if you have it recorded anywhere outside the portal, and any billing or account details tied to the subscription, since the Data Protection team will need to verify tenant ownership before making any change.

    If the phone route is difficult to get through or you get disconnected before reaching the right team, a documented workaround some people in your exact situation have used is to sign up for a separate temporary Microsoft 365 trial tenant just to get a working sign-in, and open a support ticket from inside that new trial tenant's admin center. That new tenant does not give you access to your original locked tenant, it only gives you a working session to reach support and explicitly request escalation to Data Protection for your original tenant by domain name.

    Do not post your tenant ID, subscription ID, or any proof of ownership publicly in this thread or offer to send it by private message here. Microsoft Q&A moderators cannot perform a tenant MFA reset regardless of what verification you provide them, since that authority sits only with the internal Data Protection team reached through the phone support path above, so sharing sensitive tenant details in this forum would not speed up resolution and is unnecessary exposure.

    Once you regain access, set up more than one recovery path immediately so this cannot happen again. Add a second verification method such as a phone number in addition to Authenticator, and if possible add a second user with an admin role, since a sole admin with only one MFA method is exactly the configuration that causes unrecoverable self-service lockouts.

    If this answer helps you kindly accept the answer which will help others who have similar questions.

    Best Regards,

    Jerald Felix.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.