Locked out of Azure Portal – personal Microsoft account (Gmail-based MSA), Authenticator shows 8-digit code but Azure requires 6-digit code, no other Global Administrator (tenant lockout)

Claudio Marcos da Silva 0 Pontos de reputação
2026-09-20T14:53:18.3133333+00:00

I am the sole owner and Global Administrator of a personal Azure tenant created from my personal Microsoft account (MSA), which is based on a Gmail address. Since the mandatory MFA enforcement for the Azure portal I can no longer sign in, and I have no second administrator who could reset my MFA registration.

Environment

  • Account type: personal Microsoft account (MSA), Gmail-based e-mail (not a work or school account, no Microsoft 365 business license)
  • Azure subscription: name "Laboratorio", Pay-As-You-Go, ID xxxxxxxx-xxxx-xxxx-xxxx-xxxxecc79abb
  • Tenant: the default directory created for this MSA. I do not know its name or ID, since I cannot reach any page that shows it
  • Sole user and sole Global Administrator in that tenant

Symptoms

  1. Signing in to portal.azure.com (also entra.microsoft.com) with e-mail and password succeeds, then Entra asks for a 6-digit verification code from Microsoft Authenticator.
  2. My Microsoft Authenticator app only has this account registered as a personal account, which generates 8-digit codes. The 6-digit field rejects them.
  3. The alternative "Approve a request on my Microsoft Authenticator app" option never delivers a push notification (there is no Entra-side device registration for this account, only the MSA-side one).
  4. "Sign in another way" offers no SMS, phone call or e-mail option — only the code and the notification.
  5. All other Microsoft services (Outlook.com, OneDrive, account.microsoft.com, Microsoft 365 Family) work normally with the 8-digit codes and push notifications, so the MSA side is healthy. The problem is confined to the Entra ID layer used by the Azure portal.

What I have already tried

  • Re-registering the account in Microsoft Authenticator as a personal account: still 8-digit codes only.
  • aka.ms/mfasetup and mysignins.microsoft.com/security-info: they resolve to the MSA security page (account.microsoft.com), not to the Entra tenant, so there is no way to add an Entra-side method.
  • admin.cloud.microsoft.com in an InPrivate window: returns "Login is not supported for consumer users without business presence".
  • Discovering the tenant ID via the login flow / public discovery endpoints: not successful.
  • There is no other Global Administrator or break-glass account in the tenant, so I cannot use "Require re-register MFA" on my own user.

Understanding of the root cause

The MSA and the Entra tenant share the same e-mail but are two independent MFA systems. My Authenticator registration exists only on the MSA side (proprietary 8-digit code). The Azure portal enforces MFA at the Entra level and expects a method registered in Entra (6-digit TOTP or Entra push), which was never registered. This matches several resolved threads here, e.g. "Locked out of Azure Portal -- Authenticator generates 8-digit code but Azure requires 6-digit code" and "Reset Personal Azure MFA", where the accepted answer was a tenant-lockout ticket handled by the Data Protection team.

Request

Could a Microsoft moderator please engage the Data Protection / tenant recovery team to reset the MFA registration for my account in this tenant, so that I can sign in and register Microsoft Authenticator and a second method on the Entra side? I am available for identity verification by e-mail and can provide the account e-mail, subscription ID and any other details via private message.

Thank you.

Azure | Vida e segurança do Azure
Azure | Vida e segurança do Azure

Vida e Segurança: Um programa da Microsoft que ajuda os clientes de Vida e Segurança a adotar soluções de Nuvem da Microsoft.


Sua resposta

As respostas podem ser marcadas como ‘Aceitas’ pelo autor da pergunta e ‘Recomendadas’ pelos moderadores, o que ajuda os usuários a saber a resposta que resolveu o problema do autor.