Managing external identities to enable secure access for partners, customers, and other non-employees
The error AADSTS5000225: This tenant has been blocked due to inactivity means the Microsoft Entra tenant behind the Azure subscription has been put into an inactive state and sign-in is blocked.
Key points from the tenant lifecycle behavior:
- When a tenant is marked inactive, sign-ins are blocked and this error is expected.
- Administrators can request reactivation only within 20 days after the tenant becomes inaccessible.
- If the tenant stays in this inactive state for more than 20 days, it is permanently deleted and cannot be recovered.
To try to reuse Azure with this account/tenant:
- If the tenant has been inactive less than 20 days
- A tenant administrator must contact Microsoft support and request reactivation:
- Use the global support phone numbers listed under “Contact Microsoft” in the tenant-inaccessible guidance.
- Do not open multiple support cases for the same issue; wait for the decision on the first case.
- A tenant administrator must contact Microsoft support and request reactivation:
- If the tenant has been inactive more than 20 days
- The tenant is deleted and is not recoverable.
- In that case, a new tenant must be created to continue using Azure.
- If sign-in is blocked but the account still has a free trial or credits
- Some users have resolved similar issues by going to the Azure signup page (
https://signup.azure.com) in a fresh/incognito browser session (with cookies/site data cleared), signing in with the same account, and following the prompts to continue or upgrade the existing free account to a pay-as-you-go offer. This can re-establish access when the account is recognized as having an existing free subscription.
- Some users have resolved similar issues by going to the Azure signup page (
- If the tenant truly cannot be reactivated
- Create or use another tenant (for example via
https://entra.microsoft.com→ Entra ID → Overview → Manage tenants → Create new tenant) and then access the Azure portal using that tenant’s domain name in the URL as described in the Q&A guidance.
- Create or use another tenant (for example via
If the goal is specifically to reuse the original tenant, step 1 (reactivation via Microsoft support within the 20‑day window) is the only supported path. After that window, only creating/using a new tenant is possible.
References:
- Tenant inaccessible due to inactivity
- Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Error message: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Personal Microsoft account cannot be closed due to organization link (Error AADSTS5000225) - Microsoft Q&A
- Can not access Azure - Microsoft Q&A