Urgent Request for Tenant Reactivation – AADSTS5000225 (Inactivity Block, no Tenant ID accessible)

Vitaly 0 Reputation points
2026-05-14T05:42:54.6766667+00:00

Hello Microsoft Support team,

I am the Global Administrator (and Microsoft Account owner) of an Azure tenant that was blocked due to inactivity. I am unable to retrieve the Tenant ID directly because:

  • I cannot sign in to the Azure Portal (AADSTS5000225 block)
  • The tenant was MSA-backed (no verified custom domain), so OpenID discovery against <PII removed> returns AADSTS90002
  • The associated Azure DevOps organization is not connected to Entra and contains no service connections referencing the subscription

Below are the unique resource artifacts that should allow your team to identify the tenant in the backend.

Error details (two recent sign-in attempts):

  • 2026-05-13 05:56:00Z — Trace ID <PII removed> / Correlation ID <PII removed>
  • 2026-05-14 04:51:53Z — Trace ID <PII removed> / Correlation ID<PII removed>

Identifiers from the tenant's resources (all globally unique):

  • Application Insights Instrumentation Key: <PII removed>
  • Custom domain mapped to App Service: <PII removed>
  • Staging App Service: <PII removed>
  • Storage account names: <PII removed>

Account info:

  • Global Admin / MSA: <PII removed>
  • Secondary admin: <PII removed>
  • Domain owned (DNS verifiable on request): <PII removed>

Business justification: The tenant was used 2019–2024 to operate a B2B supply-chain platform (timber trading between Russia and China) for a Swiss company. The Azure SQL database and Blob Storage contain five years of trade history, customer documents, and inspection photos — critical assets for the planned 2026 relaunch of the platform. The tenant became inactive when operations paused; we are now restarting the business and need to recover production data and the App Service custom domain mapping.

I commit to maintaining regular sign-in activity going forward and to setting up automated tenant-health monitoring.

Request:

  1. Reactivate the tenant (within the 20-day window from the inactivity block timestamp)
  2. Reinstate the associated subscription if it has been disabled
  3. If any of the resources above have already been deallocated, please advise on backup retention status

I am available for any verification step you require, including DNS TXT record on <PII removed>, signed declaration, or call. I am currently traveling (Switzerland-based, in Thailand this week) — please reach me by email at <PII removed> or through this thread.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-05-14T05:43:46.1533333+00:00

    Tenant reactivation and access recovery cannot be completed through this channel. The documented and supported paths are:

    1. Reactivate a tenant blocked due to inactivity
      • A tenant that shows error AADSTS5000225: This tenant has been blocked due to inactivity is in an inaccessible state.
      • Administrators can request reactivation only within 20 days of the tenant entering this inactive state. After 20 days, the tenant is deleted and is not recoverable.
      • To request reactivation, a tenant administrator must contact Microsoft using the global support phone numbers listed in the documentation. While a case is in progress, no additional assistance requests should be submitted.
    2. If the tenant has already been deleted
      • Tenants that remain inaccessible due to inactivity for longer than 20 days are deleted and cannot be recovered.
      • Once deleted, data and configuration in that tenant cannot be restored; a new tenant and subscriptions must be created instead.
    3. If access to a tenant owned by an organization is lost (general guidance)
      • When locked out of a tenant, the supported path is to open a support ticket so the Data Protection Team can assist with:
        • Resetting credentials of an administrator account.
        • Claiming ownership of normal tenants.
      • Identity and ownership verification (for example, business documentation or domain ownership) is handled directly through Microsoft support channels.
    4. If the scenario involves a Microsoft for Nonprofits tenant
      • Microsoft for Nonprofits cannot bypass identity verification or directly provide tenant access.
      • All tenant ownership and access decisions are handled through standard Microsoft 365 support.

    For the described case (AADSTS5000225, need to reactivate and regain access), the next step is to contact Microsoft support (using the documented global support numbers or Microsoft 365/Azure support entry points) and work with the Data Protection Team, providing any trace IDs, correlation IDs, domain ownership proof, and other identifiers during the support process.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.