Share via

Lost access to Entra External ID in Azure Admin panel after switching domains on account

AdminUser LFKSolutions 0 Reputation points
2026-06-02T18:36:56.7566667+00:00

Our primary administrator account was still set to .onmicrosoft.com. We recently changed it to use our company domain instead (kflintegrations.com).

The primary administrator is also the administrator for our Entra External ID domain under the .onmicrosoft.com domain.

The .onmicrosoft.com account was registered in MS Authenticator as well since we have been using it for some time now. The support steps in MS' documentation to register the account under the new domain indicate that the MFA should be reset in the Entra administration portal. A separate admin user did so which seemed to work properly on the company domain (kflintegrations.com)

Since this change/reset MFA validation works on the company domain but fails in MS Authenticator when the primary admin attempts to switch to the External ID domain in the Azure portal. Additionally, verification codes do not work.

Is there a way to get this corrected? Currently no other admin is configured to access the Entra External ID domain.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-02T18:37:09.2066667+00:00

    The scenario describes a tenant lockout of the only administrator for a specific Entra External ID domain (no other admin can access that External ID domain, and MFA for the primary admin is now broken there). In this situation, self-service fixes in the portal are no longer possible and the issue must be escalated to Microsoft support for tenant recovery.

    The documented pattern for similar cases is:

    1. If there is another global admin with access to that tenant/domain, that admin can:
      • Sign in to the Azure portal → Microsoft Entra ID → Users → select the affected admin user → Authentication methods → choose Require re-register multifactor authentication so the admin can re-enroll MFA and regain access.
      • This is the standard fix when at least one other global admin exists.
    2. If there is no other global admin with access to that Entra External ID domain (which matches the described situation):
      • The case is treated as a tenant lockout.
      • Resolution requires opening a support case so Microsoft’s Data Protection / Tenant Recovery team can verify ownership and reset the admin’s MFA/restore access.
      • In similar cases, moderators escalate to Data Protection via a support ticket; the Data Protection team then contacts the verified owner (email/phone) and assists in restoring access to the tenant.
    3. If the tenant itself is blocked or inaccessible (for example, due to inactivity), the documented guidance is that:
      • A tenant administrator must contact Microsoft support (for example, via the global support phone numbers) to request reactivation or recovery.
      • Administrators are advised not to open multiple concurrent requests for the same issue.

    Given that:

    • MFA works on the new company-domain sign-in but fails when switching to the External ID domain.
    • No other admin is configured for that External ID domain.

    The only supported path is to:

    • Use any available admin access (for example, via another tenant or subscription) to open a Microsoft support ticket, or
    • Use the published global support phone numbers for Microsoft cloud services, so that the case can be escalated to the Data Protection/Tenant Recovery team, who can then:
    • Verify ownership of the tenant/External ID domain, and
    • Reset MFA or otherwise restore administrative access to that External ID domain.

    There is no documented self-service method to fix this when the only admin for that External ID domain is locked out by MFA and no alternate admin exists.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.