Additional Microsoft Entra services and features related to identity, access, and network security
Based on the described symptoms, the tenant is either:
- Inaccessible/blocked at the directory level (for example, due to inactivity or an account/commerce flag), or
- No longer associated with the account currently used to sign in (for example, wrong directory or changed relationship), while the subscription is still billing in the background.
Locating and restoring access to the original tenant and subscription requires direct Microsoft intervention; this cannot be fixed from the portal alone. The relevant teams are the Microsoft 365/Azure support and Data Protection teams, not product engineering.
Actionable steps, aligned with documented processes:
- Verify directory and sign-in path (if any access remains)
- In the Azure portal, explicitly try switching directories as described in the “No subscriptions found” guidance:
- Select the account avatar in the top-right.
- Select Switch directory and check all listed directories.
- If any directory shows but still no subscriptions, the documented next step is to have the Owner role assigned to the account in that directory, which requires an existing admin. If no admin is accessible, proceed to support escalation.
- If no directory or subscription appears at all, proceed directly to support escalation.
- In the Azure portal, explicitly try switching directories as described in the “No subscriptions found” guidance:
- Check for tenant blocked due to inactivity
- The error
AADSTS5000225: This tenant has been blocked due to inactivityis the standard signal for an inaccessible tenant due to inactivity. Tenants in this state:- Can be reactivated only within 20 days of entering the inactive state.
- Are permanently deleted after 20 days and cannot be recovered.
- Administrators must contact Microsoft using the global support phone numbers to request reactivation. While the exact error code in the question is different, the recovery path for an inaccessible tenant is the same: direct support engagement.
- The error
- Engage Microsoft via phone specifically for tenant reactivation / data protection
- Call the global support phone number for the region (see “global support phone numbers” / “Customer service phone numbers”).
- When interacting with the IVR or agent, clearly state:
- The issue is loss of access to an existing Azure tenant and subscription after creating a new Microsoft 365 tenant.
- The subscription ID and that billing is ongoing.
- That there is no other global administrator with access.
- That the request is for the Data Protection / Tenant Recovery team (or equivalent) to verify identity and restore admin access.
- Follow the pattern used in the Q&A examples for sole-admin lockout:
- Identify as a business/organization account.
- Confirm being the only administrator.
- Ask the frontline to open a service request and route it to the Data Protection team.
- Do not open multiple parallel cases; the tenant-inaccessible guidance explicitly recommends avoiding duplicate requests while one is in process.
- If unable to reach effective support from the locked tenant, use a temporary tenant only to open a ticket
- As shown in the Q&A examples for sole-admin lockout:
- Create a trial Microsoft 365 or Azure tenant.
- Sign in to the Microsoft 365 Admin Center or Azure portal for this new tenant.
- Use Help & Support to open a support ticket.
- In the ticket, clearly specify that:
- The problem concerns a different, pre-existing tenant.
- Provide the original subscription ID, tenant name/domain, approximate creation date, and all error messages.
- Request escalation to the Data Protection / Tenant Recovery team to restore admin access to the original tenant.
- This temporary tenant is only a channel to reach support; it does not give access to the original resources. Remember to cancel any trial once the original issue is resolved to avoid charges.
- As shown in the Q&A examples for sole-admin lockout:
- If a partner is involved or can be added
- If a Cloud Solution Provider (CSP) or partner has (or can establish) a GDAP relationship with the original tenant, they can:
- Create a service request on behalf of the customer if they have the Service Support Administrator role.
- Help with tenant lockout scenarios and password/role recovery where GDAP roles permit.
- If no GDAP relationship exists and no other global admin is available, the documented path remains: the tenant owner/global admin must contact Microsoft support directly.
- If a Cloud Solution Provider (CSP) or partner has (or can establish) a GDAP relationship with the original tenant, they can:
- For nonprofit or special-tenant cases
- If the tenant is part of a Microsoft for Nonprofits setup, that team cannot bypass identity verification or directly restore access, but can:
- Help confirm eligibility and documentation.
- Assist with preparing materials for support escalation.
- In all cases, actual tenant ownership and access decisions are made only through Microsoft 365/Azure support and identity verification.
- If the tenant is part of a Microsoft for Nonprofits setup, that team cannot bypass identity verification or directly restore access, but can:
- Information to prepare for the Data Protection / Tenant Recovery team
- Organization name and any known domains (for example, the custom domain used for the web app and any
*.onmicrosoft.comdomain). - Subscription ID and approximate subscription start date.
- Proof of ownership of the domain(s) and organization (business registration, billing records, etc.).
- Any prior support case numbers already opened.
- Organization name and any known domains (for example, the custom domain used for the web app and any
The only supported way to have the original tenant located and admin access restored is through Microsoft support’s identity-verification and tenant-recovery process, typically handled by the Data Protection team, using the phone and/or a temporary tenant to open and escalate a case. Self-service tools and creating a new tenant will not reconnect the existing subscription or resources.
References:
- Tenant inaccessible due to inactivity
- No subscriptions found sign in error for Azure portal
- Preventing tenant lockouts
- Tenant access recovery
- Understand Microsoft 365 support case creation and data access
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- Can't find the subscription - Microsoft Q&A