Every Microsoft 365 tenant has a global administrator - the account with the keys to everything. Email, file storage, user accounts, security settings, the lot. In a lot of small businesses, that role sits with one person: the owner, or whoever happened to set the account up years ago. It works fine, right up until it doesn't.
What "locked out" actually looks like
It's rarely dramatic. It's a phone that gets lost, stolen, or replaced without the authenticator app being set up again first. It's a mobile number that changes and nobody thinks to update it in the tenant. It's someone going on holiday somewhere with no signal, right when a password needs resetting urgently.
Multi-factor authentication is protecting that admin account exactly as it should - which is precisely the problem. Once it's the only thing standing between you and access, losing it locks you out just as effectively as it locks anyone else out.
Microsoft's own account recovery isn't fast
If the sole global admin genuinely can't get in, Microsoft's recovery process involves proving who you are and who owns the business, and it isn't quick. While that's being sorted out, nobody in the business can reset a colleague's password, add a new starter, remove someone who's left, or change a single security setting. Email for the whole company can be dead in the water, not because anything actually broke, but because the one account that could fix things is the one that's stuck.
It's not just about someone leaving
People usually think about this risk in terms of an employee leaving on bad terms and still holding the keys. That's real, but it's the smaller problem - it's fixable by removing their access. The bigger, quieter risk is total unavailability through nobody's fault: illness, a broken phone, a SIM swap, or simply being unreachable at the exact wrong moment.
A second admin is the whole fix
Microsoft's own recommendation is at least two global administrators, and for good reason. The simplest version is giving a trusted second person in the business that role too. The better version, if you work with an IT provider, is having them hold a properly secured "break glass" admin account - set up correctly, monitored, and only ever used in genuine emergencies.
That way, if your usual access is ever unavailable for any reason, there's already a legitimate, secure way back in that doesn't depend on Microsoft support, doesn't depend on one person's phone, and doesn't leave your business waiting to find out if it can get back into its own email.
If you're not sure how many global administrators your tenant actually has, or whether there's a proper backup route in if something goes wrong, book a complimentary IT call and we'll check it for you - it's a five-minute thing to look at, and a considerably longer thing to fix once you're already locked out.