How to get back into entra tenant after beeing locked out via conditional access

00732089 20 Reputation points
2024-10-28T17:41:37.3+00:00

Hello community and experts,

While testing some stuff with conditional access on my test tenant I accedentily locked myself out of the tenant. I tried a couple of routes but I can't log in with any account now. I set the minimum login requirement for all users to passkey, but no user has an passkey so noone can log in.

So my question is: What is the right procedure with Microsoft to get back into the account?

Thanks for any answers :)

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,475 questions
Microsoft Entra
0 comments No comments
{count} votes

Accepted answer
  1. Akhilesh Vallamkonda 11,355 Reputation points Microsoft Vendor
    2024-10-28T18:13:33.4+00:00

    Hi @00732089

    Thank you for reaching Microsoft Q&A!

    If you have one account with admin role and if you are blocked entirely, you can reach out to our support team. You can look into below article to get support numbers depending on your country.

    https://support.microsoft.com/en-us/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2

    or creating a ticket through a different account:  https://learn.microsoft.com/en-us/microsoft-365/admin/get-help-support?view=o365-worldwide#phone-support

    Create a ticket with Microsoft support team. Give them the tenant ID which is locked out in your description. Tell them that no admin account has access anymore and your partners also have no access anymore.

    Once you create a ticket with support team you will have to work with our data protection team. You will have to first prove your identity against your tenant for security purpose. Post that this team will help you with help you in getting access to your tenant or unlock your account depending on your scenario.

     Also, for the future, you can create an emergency access account (break glass) in Azure AD. This account will help prevent being accidentally locked out of your Azure Active Directory (Azure AD) organization because you can't sign in for any reason.

    https://docs.microsoft.com/en-us/azure/active-directory/roles/security-emergency-access

    Hope this helps. Do let us know if you any further queries by responding in the comments section.

    Thanks,

    Akhilesh.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

     

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.