A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The error AADSTS5000225: This tenant has been blocked due to inactivity means the Azure AD (Entra ID) tenant associated with the account has been marked inactive and blocked. Recovery options depend on how long it has been in this state and what access is still available.
Use these steps in order:
- Check if the tenant can still be reactivated
Tenants blocked due to inactivity can be reactivated only within 20 days of entering the inactive state. After 20 days, the tenant is permanently deleted and cannot be recovered. From the tenant lifecycle guidance:- Administrators can request reactivation within 20 days.
- After 20 days in the inaccessible state, the tenant is deleted and is not recoverable.
- If within 20 days: contact Microsoft as tenant admin
If the tenant has been blocked for less than 20 days and there is (or was) admin access:- The tenant administrator must contact Microsoft support using the global support phone numbers: see global support phone numbers in the tenant-inaccessible article.
- Do not open multiple support cases for the same issue; wait for a decision on the first case.
- Try signing in directly with tenant ID or name
In some reported cases, using a direct tenant URL allowed limited access to manage or create a new tenant:-
https://portal.azure.com/<TenantId> - or
https://portal.azure.com/<yourTenantName>.onmicrosoft.com
- Go to Entra ID → Overview → Manage tenants.
- Verify the tenant status and, if needed, create a new tenant and use its domain name in the portal URL to continue working while the blocked tenant is handled.
-
- If the tenant has been inactive for a long time (e.g., >200 days)
For tenants inactive well beyond the billing cycle (example given: over 200 days), Microsoft’s commerce system applies a login block (AADSTS5000225), and 20 days after that block the tenant is permanently deleted.- If more than 20 days have passed since the block was applied, the tenant cannot be recovered.
- If the issue is tied to a free Azure trial
For some free-account scenarios, users have resolvedAADSTS5000225by:- Opening a private/incognito browser session, clearing all browser data.
- Going to
https://signup.azure.comand signing in with the same email that shows the error. - Completing the flow to “upgrade” the existing free account to a pay‑as‑you‑go account (can remain on a basic tier). This reactivated the subscription and allowed portal sign-in again.
- If unable to access anything and tenant is still within 20 days
- Ensure the tenant’s global admin (or account owner) contacts Microsoft using the support phone numbers referenced in the tenant-inaccessible article.
- Provide the error code
AADSTS5000225, the correlation ID, and timestamp when opening the case.
If the tenant has been blocked for more than 20 days, it is deleted and cannot be restored; in that case, the only path is to create and use a new tenant.
References:
- Tenant inaccessible due to inactivity
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A