AADSTS5000225 - blocked inactive tenant prevents portal sign-in and leaving organization

Ilia Popov 0 Reputation points
2026-03-09T17:05:30.4833333+00:00

My personal Microsoft account ******@outlook.com is associated with tenant

PII.

Azure Portal sign-in fails with:

AADSTS5000225: This tenant has been blocked due to inactivity.

Because of this, I cannot:

  • sign in to Azure Portal
  • access Directories list
  • leave the organization
  • close my Microsoft account, because account closure requires leaving the organization first

The self-service leave link points to the same blocked tenant and does not work.

Phone support routes this issue to password recovery and disconnects, but this is not a password issue.

Tenant ID: PII

Trace ID:

Correlation ID:

Timestamp: 2026-03-09 16:05:06Z

I do not necessarily need tenant reactivation.

I need Microsoft to delete that blocked tenant and help me to create a new one so that I could continue using Azure Portal.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-09T17:05:45.9133333+00:00

    The error AADSTS5000225 indicates that the tenant is blocked due to inactivity. When a tenant enters this state:

    • It becomes inaccessible for sign-in.
    • Administrators have up to 20 days from the time it becomes inactive to request reactivation.
    • After 20 days in this state, the tenant is deleted and is not recoverable.

    For an inactive tenant:

    1. If reactivation is desired and the tenant has been blocked for less than 20 days, a tenant administrator must contact Microsoft using the global support phone numbers to request reactivation and then wait for the decision before opening any additional cases.
    2. If reactivation is not required and the tenant remains inaccessible for more than 20 days, it is automatically deleted and cannot be restored.

    Because the tenant is blocked, self-service actions that depend on signing into that tenant (such as accessing the Azure portal, viewing directories, or leaving the organization from that tenant) will not work until either:

    • The tenant is reactivated by Microsoft at the request of an administrator within the 20‑day window, or
    • The tenant passes the 20‑day period and is deleted automatically.

    If sign-in issues or account access problems extend beyond this tenant (for example, inability to manage organizations or confusion between personal and work accounts), the appropriate escalation path is through Microsoft account and data protection support channels, which can reset access or roles where applicable.

    For scenarios where a personal Microsoft account is blocked from leaving an organization or closing the account due to tenant linkage, and front-line support has not resolved the issue, the recommended path is escalation via the appropriate product support (for example, Outlook/Microsoft account support rather than Azure-only support) so that the case can reach the correct internal team (such as data protection/escalation) to adjust the directory relationship.

    Once the blocked tenant is either reactivated (and then optionally cleaned up and deleted by an administrator) or automatically deleted after the inactivity period, a new tenant can be created from the Azure portal or Microsoft Entra admin center using the same Microsoft account, provided that account is no longer blocked by any organization membership constraints.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.