A cloud-based identity and access management service for securing user authentication and resource access
The error interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity means the tenant was marked inactive and then blocked. What can be done depends on how long it has been in this state.
- If the tenant has been inactive/blocked for less than 20 days
- Administrators can request reactivation.
- The tenant administrator must contact Microsoft support using the global support phone numbers listed in the documentation.
- Do not open multiple support cases for the same issue; wait for the decision on the first case.
- If the tenant has been inactive/blocked for more than 20 days
- After 20 days in the inaccessible state, the tenant is permanently deleted and cannot be recovered.
- In this case, recovery of that specific tenant is not possible.
- A new tenant must be created if Microsoft Entra services are still needed.
- Creating a new Microsoft Entra tenant
- Sign in to the Azure portal: https://portal.azure.com.
- Go to Microsoft Entra ID → Overview → Manage tenants.
- Select Create.
- On the Basics tab, choose the tenant type (for example, Microsoft Entra ID for a standard organization tenant).
- On the Configuration tab, provide:
- Organization name
- Initial domain name (
<name>.onmicrosoft.com) - Country/region
- Complete the wizard and wait for the tenant to be created.
- Note: Only paid customers can create a new workforce tenant from the Entra admin center; free or trial-only users who need a new tenant must sign up for a new free Azure account as described in the documentation.
- If access to the old tenant is also blocked because of account/admin issues
- Recovery of tenant access (for example, if the global admin left or credentials are lost) must go through Microsoft 365/Microsoft Entra support with identity verification.
- Microsoft cannot bypass identity verification or change tenant ownership outside these processes.
In summary: if the tenant has been blocked for fewer than 20 days, contact Microsoft support immediately to request reactivation. If it has been more than 20 days, the tenant is deleted and a new Microsoft Entra tenant must be created and configured.
References:
- Tenant inaccessible due to inactivity
- Quickstart: Create a new tenant in Microsoft Entra ID
- Quickstart: Use your Azure subscription to create an external tenant
- Set up a new Microsoft Entra tenant
- Tenant access recovery
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A