A cloud-based identity and access management service for securing user authentication and resource access
Hi 汶徽 何
I think that err shows when the tenant goes inactive and AAD freezes the root chain. If accessing via a tenant-scoped URL works, it’s because that direct hit forces a re-validation of the tenant ID to kick the lifecycle back to active.
If u still have the root obj, that's the fastest way to re‑enable it , but if not, asking MS support to rebuild the trust link is the only way to unfreeze a deep-locked tenant.
I hope this helps u move forward.
and