A cloud-based identity and access management service for securing user authentication and resource access
The error AADSTS5000225: This tenant has been blocked due to inactivity means the Microsoft Entra tenant has been put into an inaccessible state and is on a deletion timeline.
Key points from the service behavior:
- When a tenant is blocked due to inactivity, sign-ins are intentionally blocked and the error you see is expected.
- Administrators can request reactivation only within 20 days from when the tenant entered the inactive (blocked) state.
- After 20 days in this state, the tenant is permanently deleted and cannot be recovered.
Because portal access is blocked, the only supported way to request reactivation is to contact Microsoft support directly as the tenant administrator:
- Have the tenant’s global administrator call Microsoft using the global support phone numbers listed here:
global support phone numbers(see reference below). - Provide tenant-identifying information (such as tenant ID or domain name) and explain that the tenant is blocked due to inactivity and needs reactivation.
- Do not open multiple cases in parallel; wait for the decision on the first case before submitting another request.
If the tenant has already been in the blocked state for more than 20 days, it is deleted and cannot be reactivated. In that case, a new tenant must be created and configured.
As a workaround to at least access a portal context when possible, some users sign in directly with the tenant identifier in the URL, for example:
-
https://portal.azure.com/<TenantId> -
https://portal.azure.com/<yourTenantName>.onmicrosoft.com
However, for a tenant that is already blocked due to inactivity, the supported recovery path is through Microsoft support as described above.
References: