20+ years with Microsoft 1,100+ organisations under management 131 countries invoiced locally 4 of 6 Solutions Partner designations 4-hour first response
IT Partner.Microsoft Solutions Partner +44 20 8142 5752 Talk to us Get a quote

HomeBlog › Conditional Access

Guide · Conditional Access

Locked out of Microsoft 365 by Conditional Access: recovery order, and the fifteen minutes that prevent it

When no administrator can sign in there is one supported path back, and it is slow. What to try first, how to reach Microsoft when you cannot open a ticket from the locked tenant, and the emergency accounts every tenant should already have.

By Alex Makey · 6 September 2026 · 8 min read · Verified against Microsoft documentation, September 2026

The forum threads have the word URGENT in the title. Someone tightened a Conditional Access policy, or Microsoft’s mandatory MFA for the admin centre kicked in, and now no administrator can sign in. Here is the recovery order, from least to most painful, and the fifteen minutes of setup that would have made all of it unnecessary.

First: is anyone still in?

Before anything else, find a session that works. Check every administrator, on every device, in every browser. A session that was open before the policy took effect often survives it. So does a browser that already holds a token. Try:

A different network — mobile hotspot instead of the office — if the policy is location-based. A personal device if the policy requires compliant devices. An incognito window if the trouble is a cached token. A different administrator account, including service and automation accounts with Global Administrator, and the break-glass account if one exists.

If any of these get you in, go straight to Entra admin centre → Protection → Conditional Access, find the policy from the sign-in logs (the error is usually 53003), and switch it to Report-only. Do not delete it; you will want to fix it, not lose it.

Second: nobody is in

This is a tenant lockout, and there is exactly one supported path: Microsoft’s Data Protection team, sometimes called Tenant Recovery. It is slow, it requires proof of ownership, and it is the only door.

Open a ticket from somewhere. You cannot open one from the locked tenant. Options: your Cloud Solution Provider can open one on your behalf — this is one of the things you pay a partner for. If you have another tenant with an administrator, open it there and describe the locked one. If you have neither, create a free Microsoft 365 trial tenant, sign in to its admin centre, and open the ticket from there, stating clearly that the affected tenant is a different one.

What the ticket needs. The locked tenant’s primary domain, the UPNs of the Global Administrators, the error code, a statement that every administrator is blocked and no emergency account exists. Expect to be asked for a letter of authorisation signed by the billing owner. Expect days, not hours.

What to say to the business. Users are usually still working — the policy blocked administrators, not everyone. Nothing is lost. Nothing can be changed until access is restored.

Third: while you wait

Write down what the policy was supposed to do, and what it did instead. Nine times out of ten it is one of these: a policy scoped to All users with no exclusions; Require compliant device before any device was enrolled; Require MFA on accounts whose MFA method was never registered; a named-location policy after the office IP changed; or blocking legacy authentication while an administrator still used a client that needs it.

Fourth: never again

This is the part that matters, and it takes fifteen minutes.

Create two emergency access accounts. Cloud-only, on the .onmicrosoft.com domain so no federation or on-premises dependency can break them. Global Administrator. Passwords of thirty or more random characters, stored in two physically separate places — a safe, a sealed envelope, a second password manager. Not the same one the compromised administrator used.

Exclude them from every Conditional Access policy. Every one, including the ones you have not written yet. Make a group, put both accounts in it, and exclude the group from each policy as it is created.

Give them a phishing-resistant second factor — a FIDO2 security key kept with the password, not a phone that can be lost or a number that can be ported. Microsoft’s mandatory MFA for admin portals applies to these accounts too; a key satisfies it without depending on Conditional Access.

Alert on their use. Route sign-in logs to a workspace or a mailbox and alert on any sign-in by either account. They should be used twice a year to prove they work, and never otherwise.

Roll out every policy in report-only first. Let it run for a week. Read the sign-in log to see who it would have blocked. Then, and only then, enable it — scoped to a pilot group before All users.

The order for a new policy, every time

1Emergency accounts exist and are excluded
2Policy created in report-only mode
3One week of sign-in logs reviewed
4Enabled for a pilot group with an administrator in it
5Administrator confirms they can still sign in from a fresh session
6Expanded to All users, still excluding the emergency group

Skip step 1 and steps 2 to 6 are how you find out you skipped it.

One email a month, at most

New guides, when there is one worth sending

Postmortems, timelines, licensing changes that cost people money. If a month has nothing worth your time, you hear nothing.

Please enter a work email address.

Related questions

Asked most often

All our Global Administrators are locked out by Conditional Access. What do we do?

First find any session that still works: another administrator, an open browser, a different network or device, a break-glass account. Use it to set the offending policy to report-only. If nobody can sign in, the only supported route is a Microsoft support ticket to the Data Protection team, opened by your CSP partner, from another tenant, or from a new trial tenant.

Can Microsoft support unlock a tenant blocked by Conditional Access?

Yes, through the Data Protection or Tenant Recovery team, after verifying ownership, usually with a signed letter of authorisation from the billing owner. It takes days rather than hours.

What is a break-glass account?

An emergency Global Administrator account, cloud-only on the .onmicrosoft.com domain, excluded from every Conditional Access policy, with a very long password stored offline and a FIDO2 key as second factor. Two of them, monitored for any sign-in, used only in emergencies.

Does mandatory MFA for the admin centre affect break-glass accounts?

Yes, they must satisfy MFA too. A FIDO2 security key does that without depending on Conditional Access, which is why a key rather than a phone is recommended for them.

How should a new Conditional Access policy be rolled out?

Report-only first for at least a week, review the sign-in log for who it would block, enable for a pilot group that includes an administrator, confirm a fresh sign-in works, then expand. The emergency access group is excluded at every step.

Related

Worth reading next

Rather not do this yourself?

We do it several times a month

Describe the situation and you get back a sequence, an honest view of what will be slow, and a fixed price — usually within one business day. Or ask one question and get one answer.