A cloud-based identity and access management service for securing user authentication and resource access
Hello Rajesh Mamgain,
Greetings! Thanks for raising this question in the Q&A forum
A persistent tenant quota of 500 directory objects is inconsistent with the currently documented Microsoft Entra service limits. Since gngroup.org is verified and the tenant is already at 549/500, this likely requires correction of the tenant’s backend quota assignment.
- Compare the tenant with the documented limits Microsoft currently documents:
- A temporary quota of
600objects during a tenant’s first two days -
50,000objects for a normal tenant without a verified domain -
300,000objects when the tenant has at least one verified domain -
50,000objects for organizations originally created through self-service signup, even after an internal administrator takeover
500does not match any of these documented limits. See Microsoft Entra service limits and restrictions. - A temporary quota of
- Distinguish licensing from the directory service quota Microsoft Entra ID P2 licensing does not directly determine the tenant’s directory service quota. Microsoft also documents that the
500,000-resource pricing-tier limit is separate from the directory service limits described above. However, even if this tenant originated through self-service signup, its documented limit would be50,000, not500. - Capture the backend quota value As a Global Administrator, run the following request in Microsoft Graph Explorer:
The relevant response should resemble:GET https://graph.microsoft.com/beta/organization?$select=id,createdDateTime,verifiedDomains,directorySizeQuota{
"directorySizeQuota": { "used": 549, "total": 500 } }
The `/beta` endpoint is suitable for collecting diagnostic evidence but should not be used as a production dependency. Microsoft documents `directorySizeQuota` as the used and total tenant quota.
1. **Avoid relying on object deletion as the resolution**
Users, groups, devices, applications, and service principals can all consume the directory quota. Soft-deleted resources that remain recoverable can also continue to count. Deleting unused test objects might temporarily permit an urgent user creation, but it will not correct an incorrectly assigned total quota. Do not delete required production objects solely to work around this condition.
1. **Request a backend quota correction**
Open `Azure portal > Help + support > Create a support request`, select Microsoft Entra ID, and describe the issue as:
`Directory object quota incorrectly provisioned as 500. Request backend directory service quota review and correction.`
Include:
- The affected tenant ID
- The Graph response showing `used: 549` and `total: 500`
- Tenant creation date
- Verified-domain status for `gngroup.org`
- Proof of the active Entra ID P2 subscription
- The complete user-creation error, UTC timestamp, request ID, and correlation ID
- A screenshot of the `549 of 500` quota display
Microsoft Q&A contributors cannot change a tenant-side quota. Microsoft Support must verify the tenant type and repair or increase the backend allocation. Tenant identifiers and licensing evidence should be provided only through the private support case.
If this answer helps you kindly accept the answer which will help others who have similar questions.
Best Regards,
Jerald Felix.