A cloud-based identity and access management service for securing user authentication and resource access
The error AADSTS5000225 indicates that the tenant is blocked due to inactivity. When a tenant enters this state:
- It becomes inaccessible for sign-in.
- Administrators have up to 20 days from the time it becomes inactive to request reactivation.
- After 20 days in this state, the tenant is deleted and is not recoverable.
For an inactive tenant:
- If reactivation is desired and the tenant has been blocked for less than 20 days, a tenant administrator must contact Microsoft using the global support phone numbers to request reactivation and then wait for the decision before opening any additional cases.
- If reactivation is not required and the tenant remains inaccessible for more than 20 days, it is automatically deleted and cannot be restored.
Because the tenant is blocked, self-service actions that depend on signing into that tenant (such as accessing the Azure portal, viewing directories, or leaving the organization from that tenant) will not work until either:
- The tenant is reactivated by Microsoft at the request of an administrator within the 20‑day window, or
- The tenant passes the 20‑day period and is deleted automatically.
If sign-in issues or account access problems extend beyond this tenant (for example, inability to manage organizations or confusion between personal and work accounts), the appropriate escalation path is through Microsoft account and data protection support channels, which can reset access or roles where applicable.
For scenarios where a personal Microsoft account is blocked from leaving an organization or closing the account due to tenant linkage, and front-line support has not resolved the issue, the recommended path is escalation via the appropriate product support (for example, Outlook/Microsoft account support rather than Azure-only support) so that the case can reach the correct internal team (such as data protection/escalation) to adjust the directory relationship.
Once the blocked tenant is either reactivated (and then optionally cleaned up and deleted by an administrator) or automatically deleted after the inactivity period, a new tenant can be created from the Azure portal or Microsoft Entra admin center using the same Microsoft account, provided that account is no longer blocked by any organization membership constraints.
References:
- Tenant inaccessible due to inactivity
- Troubleshoot sign-in issues and account access problems
- Troubleshoot problems with the My Apps portal
- Manage organizations for a work or school account in the My Account portal
- Personal Microsoft account cannot be closed due to organization link (Error AADSTS5000225) - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A