Lost access to Azure AD app registration - urgent renewal needed before July 30, 2026

Stéphanie Keyling 0 Reputation points
2026-05-27T15:25:06.7766667+00:00

We have an Azure AD app registration named "Stafiz-SSO" (Application ID: PII) created several years ago by a former employee.

The app is registered in tenant PII (DILYNX tenant). The current client secret expires on July 30, 2026 (~2 months).

SITUATION:

  • We are Global Administrators of the stafiz.com tenant (ebaec8d1-...)
  • But we have NO admin access to the DILYNX tenant where the app lives
  • We cannot identify which account owns the registration in DILYNX
  • We cannot access the Certificates & secrets page to renew the secret

WHAT WE NEED:

Either:

  1. Identify which account owns the app registration in DILYNX tenant, OR
  2. Grant us admin access to DILYNX so we can renew the secret ourselves

This is urgent as it impacts our production SSO authentication if the secret expires.

Thanks in advance,

Stephanie Keyling

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-05-27T15:25:34.7233333+00:00

    Microsoft can't disclose the owner of an app registration or grant access to a tenant without going through the standard identity and tenant-ownership verification process.

    To avoid SSO outage when the client secret for Stafiz-SSO expires, the only supported options are:

    1. Recover or gain admin access to the DILYNX tenant
    • Follow the tenant access recovery process for the DILYNX tenant:
      • Go to the Microsoft 365 admin portal and attempt to sign in with any accounts that might be associated with DILYNX.
      • If prompted, request admin access and follow the guided steps.
    • If that fails, open a Microsoft 365 support request for tenant access recovery:
      • Go to the Microsoft 365 support page and choose the option related to “I can't sign in or access my tenant”.
      • Be prepared to prove organizational ownership of the DILYNX tenant using:
        • Official business documentation
        • Domain ownership
        • Publicly listed registration data
    • If a Microsoft partner originally created or manages the DILYNX tenant, contact that partner and ask them to assist with tenant recovery.

    Microsoft for Nonprofits (if applicable) or community moderators can't bypass identity verification, reveal app owners, or directly grant access; all tenant ownership and access decisions are handled only through Microsoft 365 support.

    1. Reactivate an inaccessible or blocked tenant (if applicable)

    If the DILYNX tenant is blocked due to inactivity and shows error AADSTS5000225 when accessed:

    • A tenant administrator must contact Microsoft using the global support phone numbers to request reactivation within 20 days of the tenant entering the inactive state.
    • After 20 days in blocked state, the tenant is deleted and can't be recovered.
    1. Once access to DILYNX is restored

    After regaining admin access to the DILYNX tenant:

    1. Sign in to the Microsoft Entra admin center or Azure portal for the DILYNX tenant.
    2. Go to Entra IDApp registrations and locate Stafiz-SSO by name or Application ID.
    3. Open the app registration and navigate to Certificates & secrets.
    4. Create a new client secret:
      • Select New client secret.
      • Set an appropriate description and expiry.
      • Copy the secret value immediately and store it securely; it can't be retrieved later.
    5. Update the SSO/service configuration in the stafiz.com tenant (or application code) to use the new client secret.
    6. After verifying successful sign-ins, remove the old client secret from Certificates & secrets.

    If the DILYNX tenant or app registration can't be recovered (for example, tenant permanently deleted), a new app registration must be created in a tenant where admin access is available, and SSO must be reconfigured to use that new app.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.