A cloud-based identity and access management service for securing user authentication and resource access
To keep the existing resources and reactivate the original (blocked) directory/tenant, the blocked tenant must be unblocked by Microsoft within the allowed window; otherwise it is deleted and can’t be recovered.
Use these steps, depending on how long the tenant has been blocked:
- Confirm the error and status
- The error
AADSTS5000225: This tenant has been blocked due to inactivityindicates the tenant has been marked inactive. - Tenants blocked for inactivity can be reactivated only within 20 days of entering the inactive state. After 20 days, the tenant is deleted and is not recoverable.
- The error
- If it has been less than 20 days since the tenant was blocked
- As an administrator of that tenant, contact Microsoft support to request reactivation:
- Use the global support phone numbers listed in the documentation: see global support phone numbers in the “Tenant inaccessible due to inactivity” article.
- Do not open multiple cases; wait for a response on the first case.
- While waiting, minimize sign-in attempts against that blocked tenant from apps or scripts.
- As an administrator of that tenant, contact Microsoft support to request reactivation:
- If it has been more than 20 days since the tenant was blocked
- The tenant is deleted after it has been inaccessible for more than 20 days and cannot be recovered.
- In that case, the only option is to create a new tenant and rebuild resources in that new directory.
- About subscriptions and directories
- A subscription can be associated with a specific Microsoft Entra directory. If the directory that originally held the subscription is blocked/deleted, that subscription and its resources are effectively unusable until the tenant is reactivated.
- After reactivation, if needed, the subscription can be associated with a different directory using the Change directory operation in the Azure portal (Subscriptions → select subscription → Change directory). This does not change billing ownership but moves the subscription’s association to another directory.
- If the subscription itself was blocked for inactivity
- Unused subscriptions can be blocked and later deleted if not unblocked.
- When a subscription is blocked, a support request is required to unblock it. If it is deleted after the notification period, data and resources in that subscription are also deleted and cannot be recovered.
Given the goal of not rebuilding everything:
- If the tenant has been blocked less than 20 days, immediately contact Microsoft (using the global support phone numbers) and request tenant reactivation.
- Once reactivated, sign in to the Azure portal under that directory, verify the subscription and resources, and then optionally change the subscription’s directory to the active tenant that is used going forward.
References:
- Tenant inaccessible due to inactivity
- Avoid unused subscriptions
- Associate or add an Azure subscription to your Microsoft Entra tenant
- Reactivate a disabled Azure subscription
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A