How to detach ID from an expired tenant for which I was/am the sole user/admin but no longer have admin access?

Mark Norwood 0 Reputation points
2026-05-12T00:36:18.6033333+00:00

This is an inactive/dormant Microsoft Entra tenant lifecycle issue, not a standard login problem.

The affected tenant is still associated as the “home organization” for my Microsoft identity and generates:

AADSTS5000225: This tenant has been blocked due to inactivity.

Key details:

  • I can authenticate into the affected tenant.
  • However, my account only has “Member” permissions. I do NOT have Global Administrator access (though I have always been the only user in the tenant).
  • Because of this, there is no self-service remediation path available.

I cannot:

  • delete the tenant
  • remove domains
  • elevate permissions
  • detach the identity association

The tenant is a legacy personal/development tenant from years ago, created, used for a couple of months, and abandoned.

This blocked/orphaned tenant is now preventing proper Microsoft 365 guest access and Teams identity continuity in another organization for my ID.

I need assistance with one of the following:

  • restoring administrative access,
  • removing the stale identity association,
  • detaching the identity from the inactive tenant, or purging the inactive tenant entirely (while maintaining the ID that's hung up).

I can provide:

  • Tenant ID
  • Tenant domain
  • The affected user principal name
  • Pretty much any other info needed related to the original tenant
Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-05-12T00:36:37.9433333+00:00

    The inactive tenant and loss of admin rights cannot be fixed self-service in this situation. The only supported path is to work with Microsoft support / Data Protection so they can verify identity and either restore admin access or help reclaim/clean up the tenant.

    Based on the documented behavior and similar resolved cases, use this approach:

    1. Confirm the tenant state
    • The error AADSTS5000225: This tenant has been blocked due to inactivity indicates the tenant has been blocked due to inactivity.
    • Administrators can request reactivation only within 20 days of the tenant entering the inactive state. After 20 days in this blocked state, the tenant is deleted and is not recoverable.
    • See: tenants inaccessible due to inactivity and the 20‑day reactivation window.
    1. Open a support case with Microsoft (Data Protection Team) Because there is no remaining Global Administrator and the account is effectively locked in a non-admin state, this is treated as a tenant lockout / admin lockout scenario. The Data Protection team is explicitly documented as the escalation path when:
    • There is only one admin and that admin has lost effective admin access (for example, due to MFA or role issues), or
    • A tenant owned by the organization cannot be accessed or administered.

    Steps:

    1. Call Microsoft support using the global customer service phone numbers:
      • Use the numbers listed under “global support phone numbers” / “Customer service phone numbers – Microsoft Support”.
    2. Clearly state that:
      • This is a Microsoft Entra / Microsoft 365 business or organizational account.
      • The tenant is blocked with AADSTS5000225 due to inactivity.
      • The signed-in account is only a Member, but is the original and only user/admin for the tenant.
      • The blocked/orphaned tenant is interfering with guest access and cross-tenant identity.
    3. Provide the information support will need for Data Protection:
      • Tenant ID (directory ID).
      • Tenant primary domain (for example, contoso.onmicrosoft.com and any custom domains).
      • The affected UPN.
      • Proof that this tenant belongs to the same person/organization (business documentation, domain ownership, etc.).
    4. Ask specifically for the Data Protection team to:
      • Either restore Global Administrator rights to the affected account in that tenant, or
      • Help reclaim/confirm ownership of the tenant so it can be administered or deleted.

    The Data Protection team has documented tools and processes to:

    • Reset credentials of an administrator account.
    • Help claim ownership of tenants that belong to the organization when normal admin access is not available.
    1. If the tenant is beyond the 20‑day blocked window If the tenant has been blocked for more than 20 days, documentation states:
    • The tenant is deleted after 20 days of being inaccessible due to inactivity and is not recoverable.

    In that case, support can still help confirm the state and advise on:

    • When the tenant will be or has been fully purged.
    • How to handle any remaining cross-tenant identity/guest issues once the directory is gone.
    1. If needed, use another tenant to open the ticket If there is difficulty opening a support request directly from the blocked tenant context (for example, no active subscription), one documented pattern is:
    • Create a new trial Microsoft 365 tenant.
    • From that new tenant’s admin center, open a support ticket explicitly about being locked out of a different, pre-existing tenant.
    • Provide the locked tenant’s ID, domain, and UPN, and clearly state that the goal is to regain admin access or have the stale tenant cleaned up.
    1. There is no self-service way to detach the identity The documentation and Q&A patterns do not provide any supported self-service mechanism to:
    • Detach a Microsoft account from its “home” Entra tenant, or
    • Purge or re-home the identity when the tenant is blocked and there is no admin.

    All tenant ownership and access decisions are handled through Microsoft 365 / Entra support and the Data Protection team. They must verify identity and then either:

    • Restore admin access so the tenant can be managed or deleted, or
    • Confirm and complete deletion/cleanup on their side.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.