A cloud-based identity and access management service for securing user authentication and resource access
The error AADSTS5000225 means the Azure AD tenant linked to the account has been blocked due to inactivity.
For an inactive tenant, only the following actions are supported:
- Reactivate the tenant (only possible within 20 days of being blocked)
- Administrators can request reactivation within 20 days after the tenant becomes inactive. After 20 days, the tenant is permanently deleted and cannot be recovered.
- To request reactivation, the tenant administrator must contact Microsoft using the global support phone numbers listed in the documentation. See the guidance under “If you need to reactivate your tenant”.
- While a reactivation request is in progress, no additional assistance requests should be submitted.
- If the tenant is past the 20‑day window
- The tenant is deleted after 20 days of being inaccessible due to inactivity and is not recoverable.
- In that case, the old Azure tenant cannot be reactivated or detached; a new tenant must be created if Azure services are needed again.
- Workarounds seen in similar cases
- Some users with a free trial have been able to proceed by going to the Azure signup page again (for example, via a clean/incognito browser session) and following the flow that recognizes the existing free account and prompts to upgrade to a pay‑as‑you‑go account. This can re-establish access when the system still considers the subscription/credits valid.
- Another documented workaround is:
- Sign in to https://entra.microsoft.com/.
- Go to Entra ID → Overview → Manage tenants.
- Create a new tenant and note its domain name.
- Then sign in to Azure Portal using a URL that targets the new tenant domain (for example, https://portal.azure.com/<newTenantDomain>). From there, administration and support actions can be performed against the new tenant.
- If tenant restrictions or other org policies are involved
- If the sign‑in is being done from a network where “tenant restrictions” are enforced, access to certain tenants can be blocked by organizational policy. In that case, only the work/school organization’s administrator can change that policy. The guidance is to contact the work/school admin if such a policy is suspected.
Given the constraints in the documentation:
- Reactivating the old tenant is only possible if it has been blocked for less than 20 days, and must be done by contacting Microsoft support (phone) as tenant admin.
- If it has been blocked for more than 20 days, the tenant is deleted and cannot be reactivated or detached; creating/using a new tenant is required.
References:
- Tenant inaccessible due to inactivity
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- How to fix the error message "Your network administrator has blocked access"
- Customer Support Portal - Troubleshoot Microsoft Identity Platform login
- I can't sign in to my Microsoft account
- Unblock my Outlook.com account