Additional Microsoft Entra services and features related to identity, access, and network security
The behavior matches a tenant that exists in Microsoft Entra ID but is currently blocked/inaccessible, not a truly “half-created” tenant. The key is to recover or reactivate the existing tenant rather than trying to create a new one with the same details.
Use these steps:
- Confirm the tenant exists and is the one being hit
- Try signing in directly to the tenant in the Azure portal using the tenant ID or tenant name in the URL, for example:
https://portal.azure.com/<TenantId>orhttps://portal.azure.com/<yourTenantName>.onmicrosoft.com - If the tenant is blocked due to inactivity, the sign-in will fail with an error like
AADSTS5000225: This tenant has been blocked due to inactivity.
- Try signing in directly to the tenant in the Azure portal using the tenant ID or tenant name in the URL, for example:
- Check if the tenant is blocked due to inactivity
- When a tenant is blocked for inactivity, sign-in attempts show an error similar to:
AADSTS5000225: This tenant has been blocked due to inactivity. To learn more about ... - Administrators can request reactivation within 20 days of the tenant entering the inactive state. After 20 days in this blocked state, the tenant is permanently deleted and cannot be recovered.
- When a tenant is blocked for inactivity, sign-in attempts show an error similar to:
- If within 20 days: request tenant reactivation
- The tenant administrator must contact Microsoft support using the global customer service phone numbers: see the link in the “Tenant inaccessible due to inactivity” article.
- Provide the tenant ID, primary domain, and explain that the tenant is inaccessible and the admin cannot sign in.
- Do not open multiple cases for the same issue; wait for the decision on the first case.
- If more than 20 days since the tenant was blocked
- The tenant is deleted and cannot be recovered.
- In that case, the only path is to use a different tenant (for example, create a new tenant and reconfigure services there). The original tenant name or domain may not be immediately reusable depending on deletion timelines and backend cleanup.
- If the admin cannot sign in at all to open a ticket
- If there is no access to any admin account in that tenant, use the global support phone numbers route as described in the “Tenant inaccessible due to inactivity” guidance.
- Alternatively, as shown in the Q&A example, a separate temporary tenant can be created (for example via a trial subscription) solely to access the Microsoft 365/Azure admin center and open a support ticket, clearly stating that the problem is with a different, existing tenant that is blocked/inaccessible.
In summary, the tenant is already registered and likely blocked/inaccessible rather than partially created. The resolution is to have the tenant administrator work with Microsoft support to reactivate or confirm deletion status; tenant recreation with the same details is not possible while the existing tenant object still exists.
References: