A cloud-based identity and access management service for securing user authentication and resource access
The error interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity means the Azure AD/Microsoft Entra tenant behind the Azure subscription is in an inactive (blocked) state and must be reactivated or replaced before sign-in to Azure will work again.
Use these steps depending on your situation:
- If the tenant became inactive recently (within the allowed reactivation window)
- A tenant administrator must contact Microsoft support and request tenant reactivation.
- From the guidance: administrators can request a tenant to be reactivated within 20 days of the tenant entering an inactive state. After that, the tenant is deleted and cannot be recovered.
- The tenant admin should call the global support phone numbers listed in the Microsoft documentation for tenant reactivation.
- Try accessing the tenant directly in the Azure portal
- Sign in using a browser where all Microsoft accounts are signed out and site data is cleared (this has helped some users get back in).
- Then browse directly to the tenant using one of these formats (replace placeholders with your values):
-
https://portal.azure.com/<TenantId> -
https://portal.azure.com/<yourTenantName>.onmicrosoft.com
-
- If the tenant is still blocked, the same AADSTS5000225 message will appear and you must proceed with support as above.
- If the tenant is past the reactivation window or cannot be reactivated
- The tenant is considered deleted and cannot be restored.
- In that case, create or use another tenant:
- Go to https://entra.microsoft.com/ and sign in.
- Navigate to Entra ID → Overview → Manage tenants.
- Create a new tenant and note its domain name (for example,
newtenant.onmicrosoft.com). - Access Azure portal using the new tenant domain or ID, for example:
-
https://portal.azure.com/newtenant.onmicrosoft.com
-
- From this new tenant, resources and subscriptions must be set up again as needed.
- If this is a free/trial Azure account that was never really used
- Some users with a blocked free tenant have been able to:
- Open a clean/incognito browser session.
- Go to
https://signup.azure.com. - Sign in with the same email that shows the error.
- Follow the prompts to continue or “upgrade” to a Pay-As-You-Go account (even at a basic level). This can re-establish access when the tenant is still recoverable.
- Some users with a blocked free tenant have been able to:
If none of the above works and the tenant is still within the 20‑day inactive window, the only supported path is to have a tenant administrator open a case with Microsoft (using the global support phone numbers) and request reactivation. If it is beyond that window, create and use a new tenant as described.
References:
- Troubleshoot connections to Microsoft Entra joined VMs
- Single sign-on with MSAL.js
- Microsoft identity platform and OAuth 2.0 authorization code flow
- Resolve student sign-in problems
- Troubleshoot sign-in issues and account access problems
- "Sorry, but we're having trouble signing you in" when a user signs in to Microsoft 365, Azure, or Intune
- Sign in to an Azure Arc-enabled server using Microsoft Entra ID and Azure Roles Based Access Control
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Can not access Azure - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Azure VM takes over an hour to login - stuck on "Please wait for the User Profile Service" - Microsoft Q&A