A cloud-based identity and access management service for securing user authentication and resource access
The inactive tenant and loss of admin rights cannot be fixed self-service in this situation. The only supported path is to work with Microsoft support / Data Protection so they can verify identity and either restore admin access or help reclaim/clean up the tenant.
Based on the documented behavior and similar resolved cases, use this approach:
- Confirm the tenant state
- The error
AADSTS5000225: This tenant has been blocked due to inactivityindicates the tenant has been blocked due to inactivity. - Administrators can request reactivation only within 20 days of the tenant entering the inactive state. After 20 days in this blocked state, the tenant is deleted and is not recoverable.
- See: tenants inaccessible due to inactivity and the 20‑day reactivation window.
- Open a support case with Microsoft (Data Protection Team) Because there is no remaining Global Administrator and the account is effectively locked in a non-admin state, this is treated as a tenant lockout / admin lockout scenario. The Data Protection team is explicitly documented as the escalation path when:
- There is only one admin and that admin has lost effective admin access (for example, due to MFA or role issues), or
- A tenant owned by the organization cannot be accessed or administered.
Steps:
- Call Microsoft support using the global customer service phone numbers:
- Use the numbers listed under “global support phone numbers” / “Customer service phone numbers – Microsoft Support”.
- Clearly state that:
- This is a Microsoft Entra / Microsoft 365 business or organizational account.
- The tenant is blocked with
AADSTS5000225due to inactivity. - The signed-in account is only a Member, but is the original and only user/admin for the tenant.
- The blocked/orphaned tenant is interfering with guest access and cross-tenant identity.
- Provide the information support will need for Data Protection:
- Tenant ID (directory ID).
- Tenant primary domain (for example,
contoso.onmicrosoft.comand any custom domains). - The affected UPN.
- Proof that this tenant belongs to the same person/organization (business documentation, domain ownership, etc.).
- Ask specifically for the Data Protection team to:
- Either restore Global Administrator rights to the affected account in that tenant, or
- Help reclaim/confirm ownership of the tenant so it can be administered or deleted.
The Data Protection team has documented tools and processes to:
- Reset credentials of an administrator account.
- Help claim ownership of tenants that belong to the organization when normal admin access is not available.
- If the tenant is beyond the 20‑day blocked window If the tenant has been blocked for more than 20 days, documentation states:
- The tenant is deleted after 20 days of being inaccessible due to inactivity and is not recoverable.
In that case, support can still help confirm the state and advise on:
- When the tenant will be or has been fully purged.
- How to handle any remaining cross-tenant identity/guest issues once the directory is gone.
- If needed, use another tenant to open the ticket If there is difficulty opening a support request directly from the blocked tenant context (for example, no active subscription), one documented pattern is:
- Create a new trial Microsoft 365 tenant.
- From that new tenant’s admin center, open a support ticket explicitly about being locked out of a different, pre-existing tenant.
- Provide the locked tenant’s ID, domain, and UPN, and clearly state that the goal is to regain admin access or have the stale tenant cleaned up.
- There is no self-service way to detach the identity The documentation and Q&A patterns do not provide any supported self-service mechanism to:
- Detach a Microsoft account from its “home” Entra tenant, or
- Purge or re-home the identity when the tenant is blocked and there is no admin.
All tenant ownership and access decisions are handled through Microsoft 365 / Entra support and the Data Protection team. They must verify identity and then either:
- Restore admin access so the tenant can be managed or deleted, or
- Confirm and complete deletion/cleanup on their side.
References:
- Tenant inaccessible due to inactivity
- Discover your Microsoft cloud footprint FAQ
- Tenant access recovery
- Preventing tenant lockouts
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- License restoration - Microsoft Q&A