Share via

Entra account is blocked

Dennis Witjas 20 Reputation points
2026-03-13T15:11:43.4433333+00:00

What can I do when I have this error?

Sign-in failed

Error code: interaction_required

Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity. To learn more about tenant lifecycle policies, see https://aka.ms/TenantLifecycle Trace ID: aa8787b0-a6df-4873-b2d2-d2f81781cc00 Correlation ID: 019ce7b5-0f7e-7b8a-b07b-d6a2edfd05f0 Timestamp: 2026-03-13 14:58:49Z

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author
  1. Q&A Assist
    2026-03-13T15:11:54.6266667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    The error AADSTS5000225: This tenant has been blocked due to inactivity means the Microsoft Entra tenant is in an inactive, blocked state and sign-in is no longer allowed.

    Actions depend on how long the tenant has been inactive and what role is held:

    1. Determine whether the tenant can still be reactivated
      • Tenants that are blocked due to inactivity can be reactivated only within 20 days of entering the inactive state.
      • After 20 days in this state, the tenant is deleted and not recoverable.
    2. If within 20 days and administrator access exists
      • A tenant administrator must contact Microsoft support to request reactivation.
      • Use the Microsoft global support phone numbers listed here: global support phone numbers.
      • Do not open multiple support cases for the same issue; wait for the response on the existing case.
    3. If more than 20 days have passed
      • The tenant is deleted and cannot be restored.
      • A new tenant must be created if continued use of Microsoft Entra ID or Azure is required.
    4. If only application access is needed (app owner/developer)
      • Minimize authentication requests to this blocked tenant until it is reactivated.
      • Do not submit additional assistance requests; wait for the admin/support decision.
    5. Additional practical steps seen in similar cases
      • If the tenant is still within the recoverable window, sign-in attempts can be made directly against the tenant in Azure portal using:
        • https://portal.azure.com/<TenantId> or
        • https://portal.azure.com/<yourTenantName>.onmicrosoft.com
      • If the original free Azure subscription path is involved and the account is recognized but blocked at portal.azure.com, some users have resolved access by going to https://signup.azure.com and completing the upgrade/activation flow for the existing account (for example, upgrading a free trial to a pay-as-you-go account) so that the tenant becomes active again.

    If none of the above applies (for example, the tenant has been blocked for more than 20 days or support cannot reactivate it), creating a new tenant and reconfiguring resources is required.


    References:

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.