A cloud-based identity and access management service for securing user authentication and resource access
The error AADSTS5000225 indicates that the Microsoft Entra tenant is blocked due to inactivity. When a tenant is made inaccessible for inactivity, it enters a 20‑day window during which an administrator can request reactivation. After 20 days in this state, the tenant is permanently deleted and cannot be recovered.
To attempt reactivation of the tenant:
- Confirm that the block occurred less than 20 days ago. If more than 20 days have passed since the tenant became inaccessible, it is deleted and cannot be restored.
- As the tenant administrator, contact Microsoft support directly and request tenant reactivation:
- Use the global support phone numbers listed in the documentation to open a support case and provide the tenant ID and primary domain.
- Do not open multiple cases for the same issue; wait for a response and decision on the initial case.
- While the tenant is blocked, authentication requests (including token refreshes for Azure Databricks) to that tenant will continue to fail until the tenant is reactivated.
If the tenant has already been in the blocked state for more than 20 days, it is deleted and cannot be reactivated. In that case, a new tenant must be created and workloads (including Azure Databricks) reconfigured to use the new tenant.
Note: Access to the Azure portal using a tenant‑scoped URL does not override a tenant inactivity block; only Microsoft support can reactivate the tenant within the allowed window.
References: