Dallas, TX · serving Dallas–Fort Worth · remote across Texas Remote support 24/7/365, including US holidays connect@crossrivertechnology.com

IT emergencies

Locked out of your Microsoft 365 admin account

The admin password left with an employee or an old IT provider, or the authenticator was on a phone nobody has any more. Here is what recovery actually looks like, and how to structure admin accounts so it cannot happen twice.

Written and reviewed by Anthony Omini, Cross River Tech·11 min read·Published · Updated

How do I regain control of our Microsoft 365 tenant?

First find out whether any other account still has Global Administrator rights, because another admin can reset the password and the MFA methods in minutes. If nobody does, Microsoft's route is a support case proving you own the domain, usually by adding a TXT record at your registrar. So check who controls your domain name today. I handle these for Dallas businesses regularly.

Answered by Anthony Omini, Cross River Tech, Dallas

Hands typing at a laptop showing a sign-in screen

Key takeaways

  • Before anything else, work out whether any account in the business still holds Global Administrator rights. One surviving admin turns a crisis into a ten-minute fix.
  • Control of the domain name is control of the tenant. Whoever can add a DNS record at the registrar is the person who can prove ownership to Microsoft.
  • Microsoft's recovery process for a tenant with no reachable admin is a support case with proof of domain ownership. It works, and it is not instant, so start it the same day.
  • A former IT provider's access is removed by ending the partner relationship in the admin center, but licenses bought through them have to be moved before you cut the cord.
  • Two owner-held admin accounts with separate MFA methods, used for nothing else, prevent every version of this problem.

Nobody can get into the Microsoft 365 admin account. What do you do first?

Find a way in that already exists before you go to Microsoft. Most lockouts turn out to have a door standing open that nobody thought to try. Work through this in order.

  1. List every account that might have admin rights. The owner, the office manager, a bookkeeper, an old shared account like info or admin, the person who first set the tenant up, and any account the IT provider created. Include people who have left, because their accounts often survive.
  2. Try signing in to the admin center with each one at the Microsoft 365 admin portal. An account only shows the admin center if it has an admin role, so this is a fast test.
  3. Check whether self-service password reset is switched on. If it is, and the account has a recovery phone or an alternate email you can still receive, you may be able to reset it yourself.
  4. Look for a break-glass or emergency account. Some setups have one, often with an unusual name, and its password may be in a safe, a password manager or the original setup paperwork.
  5. Check who controls the domain name. Log in to the registrar where the domain is registered. This is the pivotal question, because it decides whether Microsoft's recovery route is available to you at all.
  6. Gather your proof of ownership documents: the billing account details, the invoice or credit card used for the subscription, the business name and address on the account, and registrar access.
  7. Open a case with Microsoft support if no admin account is reachable, and be ready to prove domain ownership.
  8. Do not delete anything, cancel anything, or let the subscription lapse while you are working on this. A suspended subscription makes everything harder.

Meanwhile, everyone else keeps working. A locked admin account does not stop email or files; it stops changes. That is a relief when the phone starts ringing, and it means you can do this properly rather than at panic speed.

Why does this happen to small businesses so often?

Because the admin account is created once, at the very beginning, usually by whoever happened to be setting things up, and then nobody thinks about it for years. There are five common versions.

  • A departed employee. The office manager who set everything up left, the account was disabled or deleted during offboarding, and nobody noticed it was the only admin. This is the same failure described in an emergency offboarding, seen from the other side.
  • An old IT provider owns the tenant. They created it under their own account, or under a partner relationship, and the business never held credentials of its own. When the relationship ends, so does access.
  • MFA on a phone that is gone. The authenticator app lived on a handset that was lost, wiped, replaced or upgraded without moving the codes across. The password is known and useless.
  • An unmanaged or shadow tenant. Someone signed up for a free or trial Microsoft service with a work email address, which quietly created a tenant on your domain that nobody administers. You discover it the first time you try to add the domain properly.
  • A dead billing method. The card on file expired, the subscription lapsed, and the one mailbox receiving the warning emails belongs to someone who no longer works there.

None of these are unusual, and none of them mean anyone was careless. They are all the same underlying issue: administrative control resting on a single individual or a single device with no second route in.

What recovery routes does Microsoft actually offer?

Five, and they run in order of how much proof they demand. Start at the top and only move down.

RouteWhat it needsRealistic outcome
Another Global Administrator resets the accountOne surviving admin in the businessMinutes. Password and MFA methods both reset from the admin center.
Self-service password resetThe feature enabled beforehand, plus a recovery phone or alternate email you can still receiveImmediate, if it was set up. It cannot be enabled retroactively while locked out.
Microsoft support case with proof of domain ownershipAbility to add a DNS TXT record at the registrar, plus billing and account detailsThe standard route when no admin is reachable. Expect verification steps and more than one contact.
Admin takeover of an unmanaged tenantDomain control, through the same DNS verificationWorks for shadow tenants created by a self-signup. You become the admin of the tenant on your domain.
Remove a partner or delegated relationshipAn admin account of your own, or the support route firstEnds an old provider's access, but licenses bought through them must be handled first.

Two honest notes. Microsoft does not publish a fixed timescale for identity recovery cases, and I will not invent one for you, so open the case early in the day and keep the case number visible. And the process is designed to be hard, which is the point: anything easy enough to rush would be a way for a stranger to take your tenant. Expect to prove things, and have the paperwork ready before you start.

What does proving domain ownership actually mean?

It means adding a record to your domain's DNS that only someone with control of the domain could add. Microsoft gives you a specific TXT record, you add it at the registrar where the domain lives, and their system checks for it. Because DNS is the public phone book for your domain, the ability to write in it is treated as proof that the domain is yours.

Which puts the real question in a different place. Not "who has the Microsoft password?" but "who controls the domain name?". Work through this now, before you need it:

  • Where is the domain registered? A public WHOIS lookup will name the registrar even when privacy protection hides the contact.
  • Who can log in there? If the answer is a web designer from years ago, a former employee's personal account or an old IT provider, that is a bigger problem than the Microsoft lockout and it should be fixed first.
  • Whose name and email is on the registration? It should be the business, with a contact address that at least two people can read.
  • Is auto-renew on, and is the card current? A domain that expires takes your email with it and is far harder to recover than an admin password.

If you cannot get into the registrar either, start there rather than with Microsoft. Registrars have their own account recovery processes based on the registration details and the payment method, and until that is resolved the Microsoft route is closed. This is the same untangling described in who owns your passwords, domain and equipment, and it is worth reading even if today's problem is only the admin account.

What if an old IT provider holds the keys?

Then two separate things have to be dealt with: their access, and your licenses. Cutting one without handling the other causes an outage.

Their access usually comes through a partner relationship, where a provider is granted delegated administration over your tenant. If you have any admin account of your own, that relationship can be viewed and removed in the admin center under partner relationships. Remove it, then review the list of Global Administrators for any individual accounts they created for themselves, and remove those too. Also check for service accounts and app registrations that nobody in your business recognises.

Your licenses are the trap. If the provider sold you Microsoft 365 through a reseller arrangement, they own the subscription billing. Removing them without moving the subscription first can leave your licenses unpaid, and unpaid licenses eventually stop mailboxes from working. The safe order is: establish your own admin account, arrange new licensing directly or through another provider, transfer the subscriptions, confirm every user still has a license, and only then end the partner relationship.

If the provider has simply stopped responding rather than handing over, the practical playbook is in what to do when your IT guy stops answering. The short version: prove domain ownership, rebuild admin control from the top down, then change everything they knew.

Be careful with tone here. Most providers hand over politely when asked in writing, and a firm, specific email asking for a documented handover by a date works more often than people expect. Keep it professional even if you are angry, because the fastest route out is usually through them.

MFA is on a phone nobody has any more. What now?

Multi-factor authentication is doing its job, which is why it is inconvenient. The password alone will not get you in, and that is the correct behaviour.

If another admin exists, this is quick: they open the user in the admin center and require the account to re-register its authentication methods, then the locked-out person sets up the authenticator on their new phone at the next sign-in. Total time, a few minutes.

If the affected account is the only admin, you are on the support route with domain ownership proof, the same as a forgotten password. There is no back door and you should be glad there is not.

What prevents it costs nothing:

  • Register at least two methods on every admin account: the authenticator app plus a phone number, or a hardware security key.
  • Save the recovery codes where the business can find them, not on the phone itself.
  • Move the authenticator before replacing a phone, not after. Most authenticator apps have a backup and transfer function, and once the old handset is wiped it is too late.
  • Keep a second admin account with its own separate method, held by an owner.

Every part of this is standard Microsoft 365 administration work, and it is the sort of thing worth doing on a calm afternoon rather than during a lockout.

How should admin accounts be structured so this cannot happen again?

The pattern below is what I set up for small offices. It is not complicated, and it survives a resignation, a lost phone and a change of IT provider.

AccountWho holds itRules
Emergency admin (break-glass)The business ownerGlobal Administrator. Not used day to day, not linked to any person's mailbox, MFA registered on the owner's own phone, password in a sealed record or password manager the business owns.
Second emergency adminA partner, spouse in the business, or a trusted principalSame rights, different MFA method and device, so no single lost phone locks the business out.
Day-to-day adminOffice manager, or whoever does user changesNamed to a person, MFA on, rights limited to what the role needs rather than full Global Administrator.
IT provider accessYour providerThrough a documented delegated relationship or a named account you can remove yourself, never through a shared login.
Regular user accountsEveryone elseNo admin rights at all. Admin work happens on a separate account, even for the owner.

Add four habits. Put a recovery email on the admin accounts that lives outside the domain, so a domain problem does not also block recovery. Keep the domain registered to the business with billing on a company card and auto-renew on. Review the admin list twice a year and remove anyone who no longer needs it. And write down, on one page, who holds what, so the answer to "who can get into Microsoft 365?" is never a shrug.

The wider security settings that belong alongside this are covered in Microsoft 365 security for a small business.

What can still be done while you are locked out?

More than you would think, and a few things you should avoid.

Still working: mail keeps arriving and sending, files stay available, Teams and calendars carry on, and existing users can change their own passwords if self-service reset is enabled. Nobody outside the office will notice anything.

Blocked: creating or disabling users, resetting other people's passwords, changing licenses, altering security settings, adding a domain, and every kind of emergency response. That last one matters, because if a lockout coincides with a security incident you have no way to disable a compromised account.

Do not: cancel the subscription and start a new tenant, because you will lose mail history and the domain cannot be attached to two tenants at once. Do not let the billing lapse. Do not create a second tenant on a different domain as a workaround. And do not hand your registrar credentials to anyone who contacts you offering to fix it, because a lockout is exactly when people become easy to defraud.

Treat the lockout as urgent even though nothing is visibly broken. The day it becomes serious is the day you need to lock someone out and cannot.

Who can help regain a Microsoft 365 tenant in Dallas?

I can, and it is hourly work with no contract. My name is Anthony Omini and I run Cross River Tech, a small, owner-led IT company in Dallas. On a lockout I start by mapping what access still exists, because the fastest fix is nearly always an account somebody forgot about. If there is genuinely no way in, I run the Microsoft support case with you, handle the DNS verification at the registrar, and sit through the verification steps so your office manager does not have to.

Once control is back, the work that matters is making sure this is the last time: two owner-held emergency admin accounts with separate MFA methods, day-to-day admin rights trimmed to what people actually need, the domain registration in the business's name with billing that will not silently expire, and a one-page record of who holds what.

Rates are published: $100 per hour remote and $150 per hour onsite Monday to Friday, 8 AM to 5 PM Central, and $150 remote or $225 onsite after hours, weekends and holidays, with a one-hour minimum. Almost all of this is remote work, so location makes little difference; I work onsite across Dallas–Fort Worth and support businesses remotely anywhere in Texas. Ongoing tenant administration is part of managed IT support if you would rather it was simply handled.

If you are not locked out today but you cannot immediately say who holds the Global Administrator account, get in touch. Checking takes fifteen minutes and it is a much better use of your money than the alternative.

Questions people ask

Nobody has the admin password for our Microsoft 365. Can we get back in?

Usually yes. First check whether any other account holds Global Administrator rights, because that person can reset everything in minutes. If no admin is reachable, Microsoft's route is a support case where you prove you own the domain, normally by adding a TXT record at your registrar. Have the billing details and business information ready before you open it.

What if our old IT provider controls the Microsoft 365 tenant?

Their access comes through a partner relationship or accounts they created, and both can be removed from the admin center once you have an admin account of your own. Handle licensing first: if they sold you the subscriptions, move the licensing before removing them, or mailboxes can stop working when the billing relationship ends.

Our admin MFA was on a phone that no longer exists. What now?

Another administrator can require that account to re-register its authentication methods, and the person sets the authenticator up again on a new phone at the next sign-in. If the locked account is the only administrator, you are on the Microsoft support route with proof of domain ownership. There is deliberately no shortcut around multi-factor authentication.

What does proving domain ownership involve?

Microsoft gives you a TXT record to add to your domain's DNS at the registrar. Because only someone with control of the domain can add it, that acts as proof. This makes registrar access the real key to your tenant, so check now who can log in to the registrar and whose name and billing details the domain is registered under.

Will email stop working while we are locked out of the admin account?

No. Mail, files, Teams and calendars keep working normally, and users can carry on. What stops is administration: adding or disabling users, resetting passwords, changing licenses and responding to a security incident. Keep the subscription paid and do not cancel or start a second tenant, because that causes real damage while the lockout itself does not.

How do we stop this happening again?

Keep two emergency Global Administrator accounts held by owners, with separate MFA methods on different devices, used for nothing else. Give day-to-day admin rights only to the roles that need them. Register the domain in the business name with auto-renew and a company card. Review the admin list twice a year and record who holds what on one page.

Anthony Omini

Written and reviewed by

Anthony Omini, founder of Cross River Tech

Over 15 years in IT across many industries, now running Cross River Tech, a small owner-led managed IT company in Dallas. Every article is written from his own client work and checked by him before it is published.

Locked out of your own tenant? Call (214) 612-7080. I will map what access still exists and run the Microsoft recovery case with you.

Let's fix it — or plan it.

Call, or send a short request and I will get back to you personally.

Call now Get a quote

Free, no-obligation quote

Tell me what is going on

Three quick steps. I read every request myself and reply personally, usually the same business day.

What can I help with?

Pick the closest option. There is room to explain in a moment.

or call (214) 612-7080