A cloud-based identity and access management service for securing user authentication and resource access
AADSTS5000225 usually means the Microsoft Entra tenant has been blocked because it’s been inactive for too long. This is a tenant-level issue rather than a problem with the user’s sign-in. Microsoft describes this scenario in its guidance for inaccessible tenants: https://learn.microsoft.com/en-us/entra/fundamentals/inaccessible-tenant
If you’re still within the 20-day grace period, the tenant may be recoverable. In that case, the next step is to contact Microsoft Support as soon as possible and share the tenant ID, full error text, and the trace/correlation IDs from the sign-in failure. If support can reactivate the tenant in time, access may be restored.
If you have access to multiple tenants, also double-check that you’re being routed to the correct one. Signing in from an InPrivate/Incognito window and using the right tenant ID or verified domain can help rule out a browser/session mix-up.
If the tenant has already passed the grace period and was deleted, then it can’t be restored and a new tenant will need to be created.
If a personal Microsoft account was linked to the blocked tenant, removing that organization association from the account settings can also help prevent sign-in being redirected to the wrong tenant.