A cloud-based identity and access management service for securing user authentication and resource access
The error indicates that the live.com account is being sent to the default “Microsoft Services” tenant, where it has no directory and therefore can’t administer any Entra tenants or Azure resources. In this state, normal portal sign-in won’t let you reach or fix either tenant.
Based on the documented patterns, recovery requires direct Microsoft support intervention; self-service options are not available when all admin access is lost or misconfigured.
Use the following approach:
- If any other global admin exists in either tenant
- Have that admin sign in to the Microsoft Entra admin center (https://entra.microsoft.com).
- Navigate to Entra ID → Users and verify that the affected accounts exist and are not blocked.
- If the issue is MFA-related, that admin can reset MFA for the locked-out account by using Authentication methods → Require re-register multifactor authentication, then the affected user signs in again and re-registers MFA.
- If the account was accidentally converted or removed, the admin can re-invite or recreate the user and reassign roles and access.
- If there is no other global admin (only locked-out admins)
- This is treated as a tenant lockout / data-protection scenario. Microsoft’s Data Protection team must verify identity and restore access.
- Open a support case with Microsoft:
- If still able to access any Microsoft 365/Azure tenant (even a new trial), sign in to the admin portal for that tenant and create a support ticket clearly stating that:
- Access is lost to a different Entra tenant where you are the only global admin.
- Provide the locked tenant’s domain name and admin UPN, and describe the sign-in error.
- If no admin portal is accessible at all, contact Microsoft support by phone using the global customer service numbers and request escalation to the Data Protection / Tenant Recovery team for an Entra/Azure tenant lockout.
- If still able to access any Microsoft 365/Azure tenant (even a new trial), sign in to the admin portal for that tenant and create a support ticket clearly stating that:
- Be prepared to provide business documentation and proof of ownership of the affected tenants and domains. The Data Protection team can:
- Reset credentials of an administrator account, or
- Help reclaim ownership of the tenant if needed.
- If a tenant was blocked or deleted due to inactivity
- If any of the tenants show
AADSTS5000225: This tenant has been blocked due to inactivity, the tenant can only be reactivated by Microsoft within 20 days of entering the inactive state. After 20 days, the tenant is permanently deleted and cannot be recovered. - In that case, the tenant administrator must contact Microsoft support (again via support ticket or global support phone numbers) and request reactivation, supplying tenant details.
- If any of the tenants show
- For the live.com personal account scenario
- When signing in with a personal Microsoft account (Outlook/Hotmail/OneDrive/live.com), the account is associated with the Microsoft Services tenant, which no longer automatically creates a linked directory for administration.
- To have a directory where that personal account is a global admin, a new Azure account and tenant must be created via the Azure account site (for example, using Try Azure for free). This creates a new tenant with that account as Global Administrator.
- That new tenant does not automatically fix access to the existing locked tenants, but it gives an admin context from which to open a support ticket to the Data Protection team as described above.
Given that both original tenants are now inaccessible and the account relationships are misconfigured, the practical path is:
- Create or use any tenant where sign-in still works (including a new Azure/Microsoft 365 trial if necessary).
- From that tenant, open a support ticket explicitly for Entra tenant lockout and request Data Protection / Tenant Recovery assistance for the affected tenants.
- Alternatively or additionally, call Microsoft’s global support phone number and request escalation to the Data Protection team, providing tenant IDs/domains and error details.
Once Microsoft support restores access or reassigns a global admin, that admin can correct user types (guest vs. member), re-establish the correct sign-in identities, and then resume management of Azure Trusted Signing resources.
References:
- Error AADSTS50020 - User account from identity provider does not exist in tenant
- Troubleshoot problems with the My Apps portal
- Discover your Microsoft cloud footprint FAQ
- How to troubleshoot Microsoft Entra sign-up errors
- Problems signing in to a Microsoft application
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A