Life and Safety: A Microsoft program that helps Life and Safety customers adopt to Microsoft Cloud solutions.
The error interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity indicates that the Microsoft Entra (Azure AD) tenant associated with the account has been marked inactive and blocked. Inactive tenants are then permanently deleted if not reactivated within a defined window.
Key points from the error and tenant lifecycle behavior:
- When a tenant is blocked due to inactivity, sign-ins to Azure and related services fail with AADSTS5000225.
- Administrators can request reactivation only within 20 days of the tenant entering the inactive (blocked) state. After 20 days, the tenant is deleted and cannot be recovered.
To proceed, depending on role and timing:
- If tenant admin and the block started less than 20 days ago:
- Contact Microsoft support using the global support phone numbers to request tenant reactivation: see the “global support phone numbers” link in the tenant-inaccessible documentation.
- Do not open multiple support cases for the same issue; wait for the decision on the existing case.
- If the tenant has been blocked for more than 20 days:
- The tenant is deleted and is not recoverable. In this case, a new tenant must be created to continue using Azure services.
- If access is needed only for training or a free subscription and the tenant cannot be reactivated:
- Create a new tenant from the Microsoft Entra admin center (if able to sign in with the account at https://entra.microsoft.com/ as described in the Q&A example) and then access Azure using the new tenant.
- If sign-in issues persist but the tenant is not yet deleted:
- Try signing in directly with the tenant identifier in the Azure portal URL, for example:
-
https://portal.azure.com/<TenantId>or -
https://portal.azure.com/<yourTenantName>.onmicrosoft.com
-
- If that still fails and the tenant is within the 20‑day window, tenant admin must work with Microsoft support to unblock it.
- Try signing in directly with the tenant identifier in the Azure portal URL, for example:
If the account is a personal Microsoft account that appears linked to an inaccessible organization/tenant and cannot be removed via self-service, the appropriate support channel (for example, Outlook/email support rather than Azure-only support) must handle unlinking the account from the tenant, as indicated in the referenced Q&A.
References:
- Tenant inaccessible due to inactivity
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Personal Microsoft account cannot be closed due to organization link (Error AADSTS5000225) - Microsoft Q&A
- Can not access Azure - Microsoft Q&A