Additional Microsoft Entra services and features related to identity, access, and network security
The error interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity indicates that the Microsoft Entra tenant is in an inactive, blocked state and sign-in to Azure (and other services using that tenant) is currently prevented.
Key points from the tenant lifecycle behavior:
- Tenants that are inactive past a certain period are blocked from sign-in with error
AADSTS5000225. - Once blocked, administrators have up to 20 days to request reactivation.
- If the tenant remains in this blocked state for more than 20 days, it is permanently deleted and cannot be recovered.
To proceed, depending on role and timing:
- If administrator access to this tenant exists and the block started less than 20 days ago:
- Contact Microsoft support to request tenant reactivation using the global support phone numbers: see global support phone numbers in the “Tenant inaccessible due to inactivity” guidance.
- Do not submit multiple support requests for the same tenant while a case is in progress.
- If the tenant has been blocked for more than 20 days:
- The tenant is deleted and cannot be restored.
- A new tenant must be created to continue using Azure/Entra services.
- If sign-in is needed only to create or use another tenant:
- Sign in to the Microsoft Entra admin center at
https://entra.microsoft.com/(if the account itself is valid) and use Entra ID → Overview → Manage tenants to create a new tenant. - Then access Azure with the new tenant context (for example, by specifying the new tenant’s domain or ID in the Azure portal URL as shown in the referenced Q&A).
- Sign in to the Microsoft Entra admin center at
If the account was created as a free Azure subscription and is immediately blocked for inactivity, the same tenant-inactivity rules apply: the only supported recovery is via Microsoft support within the allowed reactivation window; otherwise, a new tenant/subscription is required.
References: