A cloud-based identity and access management service for securing user authentication and resource access
The error AADSTS5000225: This tenant has been blocked due to inactivity means the Microsoft Entra tenant has been put into an inactive/blocked state as part of Microsoft’s tenant lifecycle policies.
Key facts from the policy:
- When a tenant is classified as inactive, sign-ins are blocked and this error is expected.
- Administrators can request reactivation only within 20 days of the tenant entering the inactive state.
- If the tenant remains in this inactive/blocked state for more than 20 days, it is permanently deleted and cannot be recovered.
Immediate steps, depending on the situation:
- If the tenant has been blocked for less than 20 days
- A Global Administrator for the tenant must contact Microsoft Support and request reactivation.
- Use the official support phone numbers for your region:
- For Entra/Azure tenant reactivation: see the global support phone numbers referenced in the tenant-inaccessible article.
- For Microsoft 365/Entra scenarios via commerce: see the Microsoft 365 for business support phone numbers by country or region.
- After opening a support case, do not submit duplicate requests; wait for Microsoft’s response and decision on the case.
- If the tenant has been blocked for more than 20 days
- The tenant is deleted and is not recoverable.
- In this case, a new tenant must be created; existing data and configuration in the deleted tenant cannot be restored.
- If unable to sign in to open a ticket
- Try signing in directly with the tenant identifier in the Azure portal URL, for example:
-
https://portal.azure.com/<TenantId>or -
https://portal.azure.com/<yourTenantName>.onmicrosoft.com
-
- If still blocked and within 20 days, the Global Administrator must contact Microsoft Support by phone as described above.
- Try signing in directly with the tenant identifier in the Azure portal URL, for example:
- For partners managing customer tenants (GDAP)
- If a partner has GDAP and appropriate roles, they can help the customer recover access in many lockout scenarios.
- However, for an inactivity-blocked tenant, Microsoft must work directly with a Global Administrator on that tenant.
If the tenant is critical and business-impacting, treat this as urgent and have the Global Administrator call Microsoft Support immediately, explicitly referencing that the tenant is blocked due to inactivity and providing the error code AADSTS5000225 and timestamp.
References:
- Tenant inaccessible due to inactivity
- Keep your Microsoft business billing account active
- Preventing tenant lockouts
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A