A cloud-based identity and access management service for securing user authentication and resource access
The message AADSTS5000225: This tenant has been blocked due to inactivity means the Microsoft Entra tenant behind the Azure subscription has been marked inactive and access is currently blocked.
Key points from the tenant lifecycle behavior:
- When a tenant is inactive for an extended period, Microsoft blocks sign-ins to that tenant.
- From the time the tenant becomes inaccessible, there is a 20‑day window during which the tenant can be reactivated.
- After 20 days in this blocked state, the tenant is permanently deleted and cannot be recovered.
To proceed, depending on the situation:
- If tenant should be reactivated and it has been blocked for less than 20 days
- A tenant administrator must contact Microsoft support and request reactivation. Use the global support phone numbers listed in the documentation.
- Do not open multiple support cases for the same issue; wait for the decision on the existing case.
- If tenant is not needed anymore
- No action is required. After 20 days of being inaccessible due to inactivity, the tenant is deleted and is not recoverable.
- If only training or a new environment is needed
- If the tenant is already past the 20‑day recovery window (and thus deleted), a new tenant must be created and used for Azure access and training.
If the account is very new and was created as a free trial, and the tenant is still within the recoverable window, the same reactivation path via Microsoft support applies.
References:
- Tenant inaccessible due to inactivity
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A