A cloud-based identity and access management service for securing user authentication and resource access
The error AADSTS5000228: Tenant access is denied indicates that access to the Microsoft Entra ID (Azure AD) tenant is blocked at the tenant level, so sign-in to that tenant is not allowed.
For a trial tenant, this typically means one of the following:
- The tenant has been made inaccessible (for example, due to inactivity or an internal block), and sign-in is no longer permitted.
- The tenant is in an inactive state and may be on the path to deletion.
When a tenant is made inaccessible due to inactivity, Microsoft Entra returns a similar error and blocks all access. In such cases:
- Administrators can request reactivation only within a limited time window after the tenant becomes inaccessible.
- If the tenant remains inaccessible beyond that window, it is deleted and cannot be recovered.
To proceed:
- Confirm whether the tenant is still within the reactivation window.
- If administrator access is needed and the tenant should remain active, the tenant administrator must contact Microsoft support to request reactivation and review options.
- If the tenant is no longer needed or has already passed the reactivation/deletion window, no further action is required; a new tenant can be created instead.
Because tenant-level access blocks cannot be lifted by end users, resolution always requires working with Microsoft support as a tenant administrator.
References: