Managing external identities to enable secure access for partners, customers, and other non-employees
The error indicates that invitations from the tenant are blocked by Microsoft due to detected suspicious activity. The unblock and review process can only be done by Microsoft support; it cannot be cleared through portal settings or self-service.
To get the tenant reviewed and the lock removed, an administrator must open a support request with Microsoft and work with the support/Data Protection team. If the tenant is inaccessible or locked, the documented pattern is:
- Have a tenant administrator contact Microsoft Support using the global customer service phone numbers to open a support ticket and request review/unblock of the tenant.
- If no admin can currently sign in to open a ticket from the affected tenant, create or use another tenant (for example, a trial tenant) only as a channel to reach support, then open a support request clearly stating that the issue concerns a different, existing tenant that is blocked.
- Provide all requested tenant-identifying information (tenant ID, primary domain, admin account UPN, error messages, and timeline) so the Data Protection team can verify ownership and investigate the suspicious-activity block.
- Wait for the decision from Microsoft; do not open multiple parallel cases for the same tenant while one is in progress.
Because the block is based on suspicious activity, only Microsoft can review and decide whether to remove the restriction, even if it has been in place for several weeks.
References:
- Discover your Microsoft cloud footprint FAQ
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A