A cloud-based identity and access management service for securing user authentication and resource access
The error AADSTS5000225 indicates that the Microsoft Entra tenant is blocked due to inactivity. When a tenant is made inaccessible for inactivity, no one can sign in to it, including to the Azure portal, until it is reactivated or deleted.
Key points from the service behavior:
- When a tenant becomes inaccessible due to inactivity, sign-ins return
AADSTS5000225: This tenant has been blocked due to inactivity. - Administrators can request reactivation only within 20 days of the tenant entering the inactive state.
- After 20 days in this blocked state, the tenant is permanently deleted and cannot be recovered.
To proceed:
- If the tenant has been blocked for less than 20 days:
- A tenant administrator must contact Microsoft Support directly using the global customer service phone numbers: https://support.microsoft.com/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2.
- Request tenant reactivation due to inactivity block (AADSTS5000225).
- Do not submit multiple assistance requests for the same issue; wait for the Data Protection/Support team’s decision on the case.
- If the tenant has been blocked for more than 20 days:
- The tenant is deleted and is not recoverable.
- In this case, a new tenant must be created and configured.
If locked out and unable to open a ticket from the affected tenant itself, the supported path is to contact Microsoft via the global support phone numbers so the Data Protection team can assist with regaining access or confirming the tenant’s status.
References:
- Tenant inaccessible due to inactivity
- Discover your Microsoft cloud footprint FAQ
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A