A cloud-based identity and access management service for securing user authentication and resource access
The error AADSTS5000225: This tenant has been blocked due to inactivity means the Microsoft Entra tenant associated with the account has been marked inactive and blocked from sign-in.
Key points from the tenant lifecycle behavior:
- When a tenant is inactive, sign-ins are blocked and this exact error is expected.
- Administrators have up to 20 days from when the tenant becomes inactive to request reactivation.
- After 20 days in this blocked state, the tenant is permanently deleted and cannot be recovered.
To proceed:
- If the tenant has been inactive for less than 20 days:
- A tenant administrator must contact Microsoft support and request tenant reactivation. Use the global support phone numbers listed in the documentation.
- Do not submit multiple support requests for the same issue; wait for the decision on the existing case.
- If the tenant has been inactive for more than 20 days:
- The tenant is deleted and cannot be restored. In that case, a new tenant must be created if Azure/Entra services are still needed.
While blocked, authentication attempts to that tenant will continue to fail with this error until Microsoft reactivates it (within the allowed window) or it is deleted.
References:
- Tenant inaccessible due to inactivity
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A