A cloud-based identity and access management service for securing user authentication and resource access
The error interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity means the Microsoft Entra tenant is in an inactive, blocked state and cannot be used for sign-in.
Key points from the tenant lifecycle behavior:
- When a tenant is inactive past a certain period, a login block is applied and sign-ins start failing with AADSTS5000225.
- Administrators can request reactivation only within 20 days of the tenant entering this inactive/blocked state.
- If the tenant remains blocked for more than 20 days, it is permanently deleted and cannot be recovered.
To proceed, depending on role and timing:
- If acting as the tenant administrator and the block started less than 20 days ago:
- Contact Microsoft support to request tenant reactivation. Use the published global support phone numbers: see “global support phone numbers” in the tenant-inaccessible documentation.
- Do not open multiple support cases for the same issue; wait for a response on the existing case.
- If the tenant has been blocked for more than 20 days:
- The tenant is deleted and cannot be recovered.
- Review Microsoft’s data protection policies to understand what happens to data after tenant deletion.
- If only an application owner/developer using this tenant:
- Minimize authentication requests to this blocked tenant until it is reactivated.
- Do not submit multiple assistance requests; Microsoft will respond once a decision is made.
If the published support phone number is not working, use an alternative Microsoft support channel associated with the subscription or organization (for example, via the Microsoft 365 or Azure support portal) to open a support request, referencing that the tenant is blocked due to inactivity with error AADSTS5000225.
References: