Locked out of Microsoft 365 admin account by Authenticator loop: MFA reset request (lss.edu.pk)

Aamir Jabbar 0 Reputation points
2026-10-08T07:15:13.5066667+00:00

Dear Microsoft Support Team,

My name is [Moderator note: Personally Identifiable Information removed] . I am the owner of Lahore School System, Islamabad Campus, and the administrator of our Microsoft 365 organization on the domain lss.edu.pk. I am locked out of our work accounts by a multi-factor authentication loop, and I am requesting that this case be routed to the Data Protection team for an MFA reset.

Affected accounts:

  • [Moderator note: Personally Identifiable Information removed] @lss.edu.pk (my main administrator account)
  • [Moderator note: Personally Identifiable Information removed] @lss.edu.pk
  • [Moderator note: Personally Identifiable Information removed] @lss.edu.pk

What happens:

  1. Whether I sign in from a PC, a mobile phone or a tablet, I am asked for a code from the Microsoft Authenticator app.
  2. In the Authenticator app, all three accounts are listed, but they are not properly linked. When I tap any of them, no code is shown. Instead, the app asks me to verify with a code from the Authenticator app, which is the same app I am already in. It also keeps prompting me to set up a passkey.
  3. If I choose "Sign in another way" or "I can't use my Microsoft Authenticator app right now", I am returned to the same two Authenticator options. "Approve a request" shows a number on the sign-in screen, but no notification arrives in the app.
  4. No SMS or phone call option is offered, so I have no alternative method.

My personal Microsoft account ([Moderator note: Personally Identifiable Information removed] @hotmail.com) works normally in the same Authenticator app on the same phone, so the phone and the app themselves are working. The problem is only with the lss.edu.pk accounts.

Because I cannot sign in, I cannot reach the Microsoft 365 admin center to reset the sign-in methods myself or to open a support ticket from inside our organization. There is no other administrator who can do this for me.

My request:

Please reset the MFA registration (authentication methods) for the accounts above so that I can register Microsoft Authenticator again from scratch. I am ready to complete any verification of my identity and of my ownership of the organization and the domain.

All of our school's email runs through these accounts, so this is urgent for us.

You can reach me at:

Email: [Moderator note: Personally Identifiable Information removed]

Thank you for your help.

Kind regards,

[Moderator note: Personally Identifiable Information removed]

Owner, Lahore School System, Islamabad Campus

lss.edu.pk

Microsoft 365 and Office | Subscription, account, billing | For education | Other

1 answer

Sort by: Most helpful
  1. Kristen Tran 2,285 Reputation points Independent Advisor
    2026-10-08T08:01:33.8866667+00:00

    Hi Aamir,

    Thank you for sharing the detailed information.

    Based on your description, it appears that the Multi-Factor Authentication (MFA) registration for your Microsoft 365 administrator accounts is still associated with your previous mobile device. Since the old phone is no longer available and the new device has not been fully registered as an authentication method, the sign-in process may be repeatedly requesting approval from Microsoft Authenticator without providing a valid way to complete verification. This can result in the MFA loop you're currently experiencing, where no authentication codes or notifications are available and no alternative verification methods are offered.

    As you are the only Global Administrator for your organization and currently cannot access the Microsoft 365 admin center to manage authentication method, then the only way to regain access is contact Microsoft support. Please try locating the appropriate hotline for your region here: Customer service phone numbers - Microsoft Support 

    Screenshot_20261008_145858_Chrome

        

    In this situation, the Microsoft Data Protection team has tools and processes in place to verify identity and regain access to administrator accounts. 

    When contacting Microsoft, be prepared to verify ownership of the subscription. You may be asked for information such as:

    • Organization name
    • Billing or payment information
    • Registered phone number
    • Alternate email address

    Once your identity is verified, the privacy team will be able to reset your MFA settings. You can then reset your account in the Microsoft Authenticator app on your new device or choose a different authentication method to sign in.

    Here are some tips and an example of a prompt to help you navigate the IVR more effectively: 

    (When you call the support number, you may hear an introduction of about 30 seconds such as "you can visit the link...". You can ignore this introduction and wait until you are presented with the options. Then press "1" as a business email user, and again "1" for technical help.)   

    In some regions, the initial interaction may be automated, so here’s a general idea of how the conversation might go to help you prepare:     

    • IVR: What problem is bothering you?
    • Client: Authenticator        
    • IVR: What product do you use?
    • Customer: Office 365 for business
    • IVR: School or Business Account?
    • Client: Companies
    • IVR: Are you an administrator?
    • Client: Yes
    • IVR: Is there another administrator in your organization?
    • Client: No. I am the only admin in my tenant    
    • IVR: Do you need to create a support ticket?
    • Client: Yes. I need to create a ticket. Please send me direct to the Data Protection Teams.

    I also recommend calling during business hours. In my experience, it can be difficult to get through to the correct support queue, and automated systems don't always work as expected. If you can't get through on your first try, I suggest trying again later or at a different time.

     

    In case you are unable to contact the frontline support:

    Consider signing up for a trial subscription to create a new tenant: Microsoft 365 Business Plans and Pricing | Microsoft 365

    Once set up, you can access the new tenant's admin console and submit a support ticket to speak with the data protection team on behalf of the previous tenant. Once your issue is resolved, please remember to cancel the trial subscription to avoid any unintended charges.

    If your organization's subscription is from a partner or reseller: Contact the reseller's support provider to help open a service request on behalf of you instead.

    I hope this helps point you in the right direction. If you have any updates or additional questions, feel free to reply back and I'll do my best to assist further.

    Best regards.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.