Unless you work in a complex authentication environment where your admin sit in some sort of special group that can no longer be accessed via Azure AD (out of my knowledge depth), for common M365 tenants, I would assume an act of sabotage or admin take over, and all admins are now removed by the attacker and replaced with their own. Misconfigured access policies do not result in not able to find the admin user account, just unable to login. The most highly suspect is sabotage or account takeover. The next step in the attack playbook is to download your data, attempt BEC, or find other information to exploit, eg emailing your customers or suppliers with compromise emails using real email domain etc. In such a case, using the 8D template for problem solving, this is what I might do. You can use your own incident playbook if you have one -
8D – Tenant incident (assume compromise)
D2 – Problem
Admin sign-in: “This username may be incorrect”
Normal users can still sign in
Working assumption: admin accounts deleted after compromise; treat as possible BEC
D3 – Contain now (I used AI to generate this, check details for accuracy)
Call Microsoft Data Protection / Tenant Recovery. Restore a known Global Admin only.
Lock domain registrar, DNS, billing, and partner/CSP portal.
Warn all staff out of band (WhatsApp, SMS, phone, in person). Do not rely on email.
Confirm every person received the message. Chase anyone who does not reply.
Warn customers, banks, vendors, and payroll out of band: ignore payment-change or urgent-wire requests from us until verified by phone.
Confirm those third parties received the warning.
Staff must not approve MFA prompts, app consents, or new mail forwarding.
Stop extra admin login attempts from random devices.
When one admin is restored: clean PC → reset password → wipe MFA → revoke sessions → disable unknown admins.
D4 – Root cause
After access is back, check audit logs for deleted users, new Global Admins, and new app consents.
D5 – Correct
Remove attacker admins, apps, guests, unknown users, forwarding, and inbox rules.
Restore legitimate admins from Deleted users if present.
D6 – Verify
Only known admins remain.
Sign-in and audit logs look normal.
D7 – Prevent
Two break-glass admin accounts (will not prevent take-over, but can help in other lockouts).
Physical token based MFA for all admins.
D8 – Close
Short incident write-up.
Quickest way is either to call (if possible) or via demo account admin - tell them exactly what you suspect. Your registered global admin for the locked account need to create the demo account and raise the ticket.
Good luck