Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
For anyone else reading this and hoping to avoid the same lockout.
This usually follows from how the tenant was set up, not from Authenticator itself.
Microsoft’s normal small-business setup is:
- At least two Global Admin accounts, each with its own authenticator. Ideally also one emergency admin account that is cloud-only, unlicensed, on the .onmicrosoft.com domain, and not dependent on the same phone. Admin-only accounts do not need a license. Keep those details somewhere the business can reach if a phone is lost.
- One license per person. On a business plan the five-device allowance is that person’s own devices, not one login shared by five people. Sharing the login is outside the product terms, and it also means one lost phone locks every person who was using that account.
- Optionally, give your Microsoft reseller delegated admin (GDAP), including rights to reset MFA. That only helps if the relationship is still active.
In this case one license is being shared, and that same account is the only Global Admin. It costs less, until the authenticator is lost. Then there is no second admin who can reset MFA.
Recovery is a tenant-lockout case with Microsoft’s Data Protection team, raised by phone or from a temporary trial tenant. It often takes days to a few weeks, and it depends on proving ownership (billing, domain, company details). Informal setups sometimes cannot produce that proof, and then recovery stalls or fails. The data is still there. Nobody can get in to administer it.