r/MSFTAzureSupport • • Aug 24 '26

Technical Question Locked out of my tenant

Solved!

TLDR: create a new microsoft account that can raise a service request to fix the other account.

It turned out that the only thing I could do was contact Microsoft Support to reset the 2FA for that account. To make it a bit more weird it was that the problematic account was really an old hotmail.com account. 🙄

Here's what I did, and there are probably easier ways to do this, but my first approach was to try to initiate an internal admin takeover or an external admin takeover:

  1. Logged in with that account at account.microsoft.com, removed all the other email addresses associated with it. Logged out.
  2. Signed up my domaiin for a free trial of O365, that gave me an <name>@<domain>.onmicrosoft.com account.
  3. Logged into azure with the onmicrosoft.com account, added my domain as a custom domain, used the details to verify that I own and control the domain (created a TXT record) and tried to initiate a tenant takeover.
  4. This failed with no helpful message onscreen, but using browser devtools I saw it wouldn't let me because there was still an active tenant for domain.
  5. Through the O365 admin portal I tried to claim the domain and that failed for the same reason, but with a more helpful error message.
  6. Using that account I raised a service request to get help with the domain take over.
  7. That got rerouted to get someone who could reset my 2FA for the old account
  8. That took a few days. They had me verify I owned that email address, but then it was done, I had to re-setup 2FA and I could get access to that tenant again.
  9. Problem solved.

I'm now doing the clean up, importantly cancelling the O365 account, and switching everything to real accounts on my domain, also having a couple of backup admins, in case I get locked out again.

Detail of problem follows.

I'm trying to get into my personal tenant directory in Azure, but I can only get half way logged in.

I think it's trying to authenticate me with my personal domain, but that doesn't work

Here's what happens:

  1. I go to portal.azure.com and log in with my personal microsoft account, auth via the Authenticator app
  2. Sometimes I get prompted to re-authenticate but I don't get a notification from the authenticator app, I try another way and get prompted to enter a 6 digit code, I can't generate one in the app
  3. If I don't get prompted to re-authenticate, or cancel out of it, I end up on the portal home page. However instead of my default tenant under my user name (top right of screen) I have this f8cdef31-a31e-4b4a-93e4-5f571e91255aas my Directory and Domain
  4. If I try to switch to the tenant associated with my own domain (my default) I get stuck in step 2.
  5. If I go to to the Entra ID blade I get a series of messages saying "Interaction required" and suggesting I re-login, which doesn't help because then I get stuck in step 2 again
  6. After clicking "Ignore" a bunch of times I get details for f8cdef31-a31e-4b4a-93e4-5f571e91255a including that its license is "Microsoft Entra ID Free"
  7. From there I can click on "Manage Tenants" (more "Interaction required") messages, and 3 tenants, the one for my domain, one for my employer, and one for a place I used to work about 10 years ago.
  8. If I try to switch to my personal one I get stuck in step 2 again. I can switch to my employer's one, but my personal account doesn't have a subscription there.

When I get asked to re-authenticate I get it has the email address of my personal Microsoft account (myname@mydomain). There are some flows where I get prompted to enter my email address, if I enter it there I get an error saying it's not valid, or I get this:

ADSTS50020: User account 'myname@mydomain' from identity provider 'live.com' does not exist in tenant 'Microsoft Services' and cannot access the application '74658136-14ec-4630-ad9b-26e160ff0fc6'(ADIbizaUX) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account.

If I try to raise a support request I get stuck in step 2. If I try to buy support, I get stuck in step 2.

I think the problem is that myname@mydomain is both a Microsoft personal account (also tied to hotmail and gmail accounts) and an account for my personal domain's tenant. When it tries to authenticate for the one on my tenant I no longer have access to the 2FA method. I get prompted to contact my admin, I'm the only admin.

After many hours chatting with the AI assistant, it seems I need to raise a request to recover the account, but I can't do that without logging in.

On the plus side: I own and manage the domain. I can add MX (etc) records to verify that.

Where do I go from here?

4 Upvotes

4 comments sorted by

2

u/SandwichMean2965 Aug 24 '26

Been stuck in the same loop forever now, nothing helped me yet

1

u/baralong Aug 31 '26

Hey, I've updated my question with the answer. TLDR is I had to create a new Microsoft account to raise a service request from there. The support guy I spoke with said that the only way to fix it was to get them to do it in the back end.

The whole thing was a massive pain, and it shouldn't be that hard. Burt I got a good result in the end.

1

u/SandwichMean2965 Sep 03 '26

I tried to do that but even the new account results in the same , I will try again once ig