AADSTS5000225: tenant blocked due to inactivity, cannot sign in anywhere to reactivate (personal MSA admin)

Nurassyl Aldanov 0 Reputation points
2026-05-25T06:10:11.8366667+00:00

Summary

My Azure AD / Microsoft Entra tenant has been blocked due to inactivity

(error AADSTS5000225). I am the sole Global Administrator of this

tenant via a personal Microsoft account (MSA). Every Microsoft portal

that could be used to reactivate it refuses my sign-in with the same

error, so I am unable to either reactivate or delete the tenant

through self-service.

I do not have any Azure resources, subscriptions, or paid workloads in

this tenant — it was auto-created at some point when I first opened

the Azure portal. My personal OneDrive / Microsoft 365 Personal

subscription is on the same MSA and works normally; only the tenant

itself is the problem.

What I am trying to do

I want to register an Azure AD application to use Microsoft Graph

(OneDrive Files.ReadWrite) for a self-hosted n8n integration that

accesses Excel files in my personal OneDrive. This requires App

Registration, which requires sign-in to a tenant.

What I have tried

Each of the following ends with the same error:

| Portal | Result |

|---------------------------------|--------------------------------------------------------|

| https://portal.azure.com | AADSTS5000225, tenant blocked |

| https://entra.microsoft.com | AADSTS5000225, tenant blocked |

| https://admin.microsoft.com | Personal MSA not permitted on this portal |

| https://support.microsoft.com | Support ticket form also fails with the same error |

I cannot create a new tenant from entra.microsoft.com either,

because the create-tenant flow requires an authenticated session,

which fails for the same reason.

Diagnostic details

Latest sign-in attempt:

  • Error code: interaction_required
  • Error message: `AADSTS5000225: This tenant has been blocked due to inactivity. To learn more about tenant lifecycle policies, see https://aka.ms/TenantLifecycle`
  • Trace ID: <PII REMOVED>
  • Correlation ID: <PII REMOVED>
  • Timestamp (UTC): 2026-05-25 05:50:00Z

Earlier attempt on portal.azure.com:

  • Trace ID: <PII REMOVED>
  • Correlation ID: <PII REMOVED>
  • Timestamp (UTC): 2026-05-25 05:48:24Z

What I need

Either of the following would unblock me:

  1. Reactivation of the blocked tenant so I can sign in and either keep using it or delete it manually.
  2. Deletion of the blocked tenant on Microsoft's side, so my personal MSA can sign in to portal.azure.com and have a fresh Default Directory auto-provisioned.

If Microsoft needs additional identity verification, I am happy to

provide it through any verification channel that does not require

signing in to the blocked tenant.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-25T06:10:36.72+00:00

    The error AADSTS5000225: This tenant has been blocked due to inactivity means the Microsoft Entra tenant has been put into an inaccessible state as part of the tenant lifecycle and is now blocked for sign-in.

    For tenants blocked due to inactivity:

    1. Tenants remain in this inaccessible state for up to 20 days.
    2. During this period, administrators can request reactivation.
    3. After 20 days in the blocked state, the tenant is permanently deleted and cannot be recovered.

    To request reactivation while the tenant is still within the 20‑day blocked window:

    1. As the tenant administrator, contact Microsoft support using the global support phone numbers listed in the tenant-inactivity guidance.
    2. Provide the tenant details and the error information (including the AADSTS5000225 error, trace ID, correlation ID, and timestamps) so support can locate and assess the tenant.
    3. Do not submit multiple assistance requests; wait for the decision on the initial case.

    If the tenant has already been blocked for more than 20 days, it will be deleted automatically and is not recoverable. In that case, the only path forward is to use or create a different tenant for App registrations.

    Because sign-in to the blocked tenant is prevented, self-service reactivation or deletion through the portals is not possible; the reactivation decision and any exception handling must be done by Microsoft support.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.