Share via

Sign-in failed

Dinesh Arora 0 Reputation points
2026-04-06T11:57:16.8566667+00:00

Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity. To learn more about tenant lifecycle policies, see https://aka.ms/TenantLifecycle Trace ID: 2910e71d-9ba3-402e-b161-446e74654300 Correlation ID: 019d629c-0e66-7175-abc1-5e9284321f40 Timestamp: 2026-04-06 11:44:48Z

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-04-06T11:57:30.58+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    The error interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity indicates that the Microsoft Entra tenant is in an inactive, blocked state due to lifecycle policies and can no longer be used for sign-in until reactivated (if still within the allowed window).

    Key points from the tenant lifecycle behavior:

    1. When a tenant is inactive for an extended period, Microsoft blocks sign-ins to that tenant and returns AADSTS5000225.
    2. Administrators can request reactivation only within 20 days after the tenant becomes inaccessible due to inactivity.
    3. If the tenant remains in this blocked state for more than 20 days, it is permanently deleted and cannot be recovered.

    To proceed, depending on the situation:

    1. If administrator access to the tenant exists and the block started less than 20 days ago:
      • The tenant administrator must contact Microsoft support to request tenant reactivation. Use the global support phone numbers listed in the documentation. While the case is in progress, no additional support requests should be opened for the same issue.
    2. If the tenant has been blocked for more than 20 days:
      • The tenant has been or will be deleted and is not recoverable. In this case, a new tenant must be created to continue using Microsoft Entra ID and Azure services.
    3. If sign-in is needed only to continue working in Azure (for example, training or lab work) and the original tenant cannot be reactivated:
      • Create or use another tenant (for example, via the Microsoft Entra admin center’s Manage tenantsCreate), then sign in to Azure using the new tenant’s domain name in the portal URL (for example, https://portal.azure.com/<yourTenantName>.onmicrosoft.com) as described in the referenced Q&A. From that tenant, normal Azure/Entra operations can continue.
    4. For application owners or developers whose apps are still sending sign-in requests to the blocked tenant:
      • Minimize authentication requests to the deactivated tenant until it is reactivated or replaced.

    If the tenant is still within the 20‑day reactivation window and access to a billing/support-eligible subscription exists, contacting Microsoft support promptly is required to restore access.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.