Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity.

Ken Zarn 0 Reputation points
2026-05-08T15:27:00.1233333+00:00

Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity.

Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-05-08T15:27:11.4866667+00:00

    The error interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity means the Microsoft Entra (Azure AD) tenant is in an inactive, blocked state and sign-ins are no longer allowed.

    Key points and actions:

    1. Reason for the error
      • The tenant has been marked inactive and blocked due to lack of usage and/or billing inactivity.
      • When a tenant is blocked for inactivity, all sign-ins to that tenant fail with AADSTS5000225.
    2. Time limit before permanent deletion
      • After the tenant is blocked for inactivity, there is a 20‑day window during which it can still be reactivated.
      • If the tenant remains inactive for more than 20 days after being blocked, it is permanently deleted and cannot be recovered.
    3. If the tenant has been blocked for less than 20 days (reactivation path)
      • A tenant administrator must contact Microsoft support to request reactivation:
        • Use the global support phone numbers listed in the documentation.
      • Do not open multiple support cases for the same issue; wait for the decision on the existing case.
    4. If the tenant has been blocked for more than 20 days
      • The tenant is deleted and cannot be restored.
      • In this case, a new tenant must be created if continued use of Azure/Microsoft Entra is required.
    5. Additional behaviors seen in Q&A scenarios
      • Some users with recently created free accounts have seen this error and were able to:
        • Sign in via https://signup.azure.com and complete/upgrade their subscription to a pay‑as‑you‑go account, which restored access.
        • Or sign in directly to the tenant using a URL that includes the tenant ID or tenant name, for example https://portal.azure.com/<TenantId> or https://portal.azure.com/<yourTenantName>.onmicrosoft.com, then open a support ticket if they have a paid support-eligible subscription.
      • If the original tenant truly is beyond the 20‑day window and deleted, creating a new tenant and working from there is the remaining option.

    In summary, this error indicates a blocked, inactive tenant. If within 20 days of being blocked, a tenant admin must contact Microsoft to request reactivation; after 20 days, the tenant is permanently deleted and a new tenant is required.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.