Entra ID tenant blocked due to inactivity - AADSTS5000225 error, need tenant reactivation

Steve Lysik 0 Reputation points
2026-03-13T01:23:00.2833333+00:00

Hello,

My Microsoft Entra ID tenant has been blocked due to inactivity and I am receiving the following error when trying to access the Entra admin center (entra.microsoft.com):

Error: AADSTS5000225 - "This tenant has been blocked due to inactivity."

Tenant details:

  • Tenant ID: PII
    • Primary domain: PII
      • Admin account: PII
    • Impact:
        • Unable to access the Microsoft Entra admin center
      • Azure Databricks workspace (PII.azuredatabricks.net) is experiencing session timeouts because Azure AD token refresh requests are being rejected
        • The Azure portal (portal.azure.com) is still accessible
      • Steps already tried:
        • Signed into the Azure portal using the tenant-scoped URL: PII(as suggested in similar Q&A posts), but the Entra admin center still shows the blocked error
      • Could a Microsoft engineer please reactivate this tenant? This is an active tenant used for Azure Databricks workloads with a Visual Studio Enterprise Subscription.
    • Thank you.
Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-13T01:23:11.9166667+00:00

    The error AADSTS5000225 indicates that the Microsoft Entra tenant is blocked due to inactivity. When a tenant is made inaccessible for inactivity, it enters a 20‑day window during which an administrator can request reactivation. After 20 days in this state, the tenant is permanently deleted and cannot be recovered.

    To attempt reactivation of the tenant:

    1. Confirm that the block occurred less than 20 days ago. If more than 20 days have passed since the tenant became inaccessible, it is deleted and cannot be restored.
    2. As the tenant administrator, contact Microsoft support directly and request tenant reactivation:
      • Use the global support phone numbers listed in the documentation to open a support case and provide the tenant ID and primary domain.
      • Do not open multiple cases for the same issue; wait for a response and decision on the initial case.
    3. While the tenant is blocked, authentication requests (including token refreshes for Azure Databricks) to that tenant will continue to fail until the tenant is reactivated.

    If the tenant has already been in the blocked state for more than 20 days, it is deleted and cannot be reactivated. In that case, a new tenant must be created and workloads (including Azure Databricks) reconfigured to use the new tenant.

    Note: Access to the Azure portal using a tenant‑scoped URL does not override a tenant inactivity block; only Microsoft support can reactivate the tenant within the allowed window.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.