Lost access to Azure tenant and subscription after creating new Microsoft 365 tenant - AADSTS160021

Thinoshan Sivakumaran 0 Reputation points
2026-04-08T06:41:58.4833333+00:00

Hello,

I have lost access to my original Azure tenant and

subscription since March 20, 2026 (19 days ago).

SITUATION:

I had a fully working Azure environment with:

  • Active subscription (ID: 45b88962-3518-47c3-938f-494744a10be7)
  • Web App (thino-dev) with live domain thino.dev
  • Virtual Machines
  • Resource Group: rg-thino-dev (Switzerland North)

After creating a new Microsoft 365 tenant on

March 20, 2026, my original Azure tenant became

completely inaccessible.

CURRENT BEHAVIOR:

  • Azure Portal shows "Sie haben kein Abonnement"
  • Error: AADSTS160021 (user session does not exist)
  • No subscriptions or directories visible
  • Microsoft Entra shows no accessible tenant

WHAT I HAVE TRIED:

  • 2 support tickets opened (2603200050002437, 2603240050002861) - no resolution after 19 days
  • Multiple phone calls - phone assistant unhelpful
  • Multiple live chats - redirected each time
  • Escalation via @AzureSupport on X - escalated but still no resolution
  • Engineer assigned (SCIM team) but suggested creating a new tenant - NOT the right solution

MY QUESTION:

How can I get the Azure Data Protection /

Tenant Recovery Team to locate my original tenant

and restore my admin access?

My subscription is still active and I continue

to be billed. I cannot afford to create a new

tenant as this would mean losing all my resources

and my live website thino.dev.

Any help is greatly appreciated!

Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-04-08T06:42:24.42+00:00

    Based on the described symptoms, the tenant is either:

    • Inaccessible/blocked at the directory level (for example, due to inactivity or an account/commerce flag), or
    • No longer associated with the account currently used to sign in (for example, wrong directory or changed relationship), while the subscription is still billing in the background.

    Locating and restoring access to the original tenant and subscription requires direct Microsoft intervention; this cannot be fixed from the portal alone. The relevant teams are the Microsoft 365/Azure support and Data Protection teams, not product engineering.

    Actionable steps, aligned with documented processes:

    1. Verify directory and sign-in path (if any access remains)
      • In the Azure portal, explicitly try switching directories as described in the “No subscriptions found” guidance:
        1. Select the account avatar in the top-right.
        2. Select Switch directory and check all listed directories.
      • If any directory shows but still no subscriptions, the documented next step is to have the Owner role assigned to the account in that directory, which requires an existing admin. If no admin is accessible, proceed to support escalation.
      • If no directory or subscription appears at all, proceed directly to support escalation.
    2. Check for tenant blocked due to inactivity
      • The error AADSTS5000225: This tenant has been blocked due to inactivity is the standard signal for an inaccessible tenant due to inactivity. Tenants in this state:
        • Can be reactivated only within 20 days of entering the inactive state.
        • Are permanently deleted after 20 days and cannot be recovered.
      • Administrators must contact Microsoft using the global support phone numbers to request reactivation. While the exact error code in the question is different, the recovery path for an inaccessible tenant is the same: direct support engagement.
    3. Engage Microsoft via phone specifically for tenant reactivation / data protection
      • Call the global support phone number for the region (see “global support phone numbers” / “Customer service phone numbers”).
      • When interacting with the IVR or agent, clearly state:
        • The issue is loss of access to an existing Azure tenant and subscription after creating a new Microsoft 365 tenant.
        • The subscription ID and that billing is ongoing.
        • That there is no other global administrator with access.
        • That the request is for the Data Protection / Tenant Recovery team (or equivalent) to verify identity and restore admin access.
      • Follow the pattern used in the Q&A examples for sole-admin lockout:
        • Identify as a business/organization account.
        • Confirm being the only administrator.
        • Ask the frontline to open a service request and route it to the Data Protection team.
      • Do not open multiple parallel cases; the tenant-inaccessible guidance explicitly recommends avoiding duplicate requests while one is in process.
    4. If unable to reach effective support from the locked tenant, use a temporary tenant only to open a ticket
      • As shown in the Q&A examples for sole-admin lockout:
        1. Create a trial Microsoft 365 or Azure tenant.
        2. Sign in to the Microsoft 365 Admin Center or Azure portal for this new tenant.
        3. Use Help & Support to open a support ticket.
        4. In the ticket, clearly specify that:
          • The problem concerns a different, pre-existing tenant.
          • Provide the original subscription ID, tenant name/domain, approximate creation date, and all error messages.
          • Request escalation to the Data Protection / Tenant Recovery team to restore admin access to the original tenant.
      • This temporary tenant is only a channel to reach support; it does not give access to the original resources. Remember to cancel any trial once the original issue is resolved to avoid charges.
    5. If a partner is involved or can be added
      • If a Cloud Solution Provider (CSP) or partner has (or can establish) a GDAP relationship with the original tenant, they can:
        • Create a service request on behalf of the customer if they have the Service Support Administrator role.
        • Help with tenant lockout scenarios and password/role recovery where GDAP roles permit.
      • If no GDAP relationship exists and no other global admin is available, the documented path remains: the tenant owner/global admin must contact Microsoft support directly.
    6. For nonprofit or special-tenant cases
      • If the tenant is part of a Microsoft for Nonprofits setup, that team cannot bypass identity verification or directly restore access, but can:
        • Help confirm eligibility and documentation.
        • Assist with preparing materials for support escalation.
      • In all cases, actual tenant ownership and access decisions are made only through Microsoft 365/Azure support and identity verification.
    7. Information to prepare for the Data Protection / Tenant Recovery team
      • Organization name and any known domains (for example, the custom domain used for the web app and any *.onmicrosoft.com domain).
      • Subscription ID and approximate subscription start date.
      • Proof of ownership of the domain(s) and organization (business registration, billing records, etc.).
      • Any prior support case numbers already opened.

    The only supported way to have the original tenant located and admin access restored is through Microsoft support’s identity-verification and tenant-recovery process, typically handled by the Data Protection team, using the phone and/or a temporary tenant to open and escalate a case. Self-service tools and creating a new tenant will not reconnect the existing subscription or resources.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.