Additional Microsoft Entra services and features related to identity, access, and network security
The error AADSTS5000225 indicates that the Microsoft Entra tenant is blocked due to inactivity.
Key points from the tenant lifecycle behavior:
- When a tenant becomes inactive, sign-ins are blocked and the error
AADSTS5000225: This tenant has been blocked due to inactivityis expected. - Administrators can request reactivation only within 20 days of the tenant entering the inactive state.
- If the tenant remains in this inactive/blocked state for more than 20 days, it is permanently deleted and cannot be recovered.
To attempt reactivation (only possible if the tenant has been inactive for less than 20 days):
- Have a tenant administrator contact Microsoft using the global support phone numbers listed at the support page: see global support phone numbers in the referenced article.
- Do not submit multiple assistance requests for the same tenant while a case is in progress; wait for Microsoft’s response and decision.
If the tenant has been blocked for more than 20 days:
- The tenant is deleted and cannot be reactivated.
- A new tenant must be created if Azure/Entra services are needed again.
For application owners or developers that are hitting this tenant during authentication:
- Minimize authentication requests to the deactivated tenant until it is reactivated or confirmed deleted.
- Review Microsoft’s data protection policies as needed.
References:
- Tenant inaccessible due to inactivity
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Tenant inaccessible due to inactivity - Microsoft Q&A