Additional Microsoft Entra services and features related to identity, access, and network security
The error interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity indicates that the Microsoft Entra/Azure AD tenant is in an inaccessible state due to inactivity and is being processed for deletion.
Key points from the tenant lifecycle behavior:
- When a tenant is marked inactive, sign-ins are blocked and this exact error is expected.
- Administrators have a limited window of 20 days from when the tenant becomes inaccessible to request reactivation.
- If the tenant remains inaccessible for more than 20 days, it is deleted and cannot be recovered.
Next steps depend on the tenant’s state and role:
- If within 20 days of being blocked (tenant admin):
- The tenant’s global administrator must contact Microsoft Support and request reactivation.
- Use the global support phone numbers listed in the documentation and open only one assistance request; do not submit multiple tickets while the first is in progress.
- If more than 20 days have passed since it was blocked:
- The tenant is deleted and is not recoverable.
- Review Microsoft’s data protection policies for details on data handling and retention.
- If accessing as an application owner/developer:
- Minimize authentication requests to the blocked tenant until it is reactivated.
- Do not open multiple assistance requests; wait for the decision on any existing case.
If access to Azure Portal is needed for other work and this tenant cannot be recovered, create or use another active tenant and sign in with that tenant’s domain or ID.
References:
- Tenant inaccessible due to inactivity
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A