logo
search
list

Table of Content

Clearing the Inactivity Block via Microsoft Entra ID
Alternative: Submitting a Recovery Request via Azure Support
Documenting Your Incident Response Plan with WPS Office
Frequently Asked Questions

How to Restore an Azure Tenant Blocked for Inactivity

Posted by Khadija Khan

calendar

2026-09-08

views

869

likes

4

When a free Microsoft Azure tenant (now managed via Microsoft Entra ID) registers zero administrative activity for 90 days, Microsoft automatically blocks the environment and schedules it for permanent deletion. You will typically receive an automated email notification regarding this inactivity block approximately 30 days before the data is erased. Restoring the tenant requires immediate intervention using global administrator credentials to halt the deletion countdown. This guide explains the exact workflow to clear the inactivity block, reactivate your cloud environment, and regain control over your identity directory.

Clearing the Inactivity Block via Microsoft Entra ID

If your global administrator account is still accessible, the fastest way to resolve the inactivity block is through the self-service portal. Logging in and manually triggering the restore function will immediately update the tenant's status.

Follow these precise steps to restore the tenant through the management interface:

  • Open a private or incognito browser window to prevent your browser from automatically authenticating with a different, active Microsoft account.
  • Navigate directly to portal.azure.com.
  • Enter the username and password for the Global Administrator account specifically associated with the blocked tenant.
  • Once the dashboard loads, locate the search bar at the top of the screen, type Microsoft Entra ID, and select it from the services dropdown menu.
  • In the left-hand navigation pane, click on Overview.
  • Look for a red or yellow warning banner at the top of the Overview screen that states "Your tenant is scheduled for deletion due to inactivity."
  • Click the Cancel deletion or Reactivate link embedded directly inside that warning banner.
  • A confirmation pane will slide out on the right side of the screen. Click the blue Confirm button at the bottom of this pane.

The expected result is an immediate portal notification stating that the reactivation request was successful. To verify the fix, click on Manage tenants in the top menu bar of the Entra ID overview page. Locate your tenant in the list and confirm that the State column now reads Active instead of Deleted or Blocked.

Alternative: Submitting a Recovery Request via Azure Support

Illustrated steps for Restoring an Azure Tenant Blocked for Inactivity
Key actions for Restoring an Azure Tenant Blocked for Inactivity.

In some cases, the inactivity block also locks the sole global administrator account, preventing you from accessing the Microsoft Entra ID overview page. When self-service is impossible, you must escalate the issue to Azure Support using the dedicated recovery form.

  • Navigate to portal.azure.com and log in with any active Microsoft account (even a personal one) just to access the support framework.
  • In the global search bar, type Help + support and select the service with the green question mark icon.
  • Click the Create a support request button located in the top left corner.
  • In the Issue type dropdown menu, select Subscription management.
  • In the Problem type dropdown menu, scroll down and select Reactivate my subscription or tenant.
  • In the text field provided, supply the exact Initial Domain Name (e.g., yourcompany.onmicrosoft.com) or the Tenant ID of the blocked directory. State clearly that the tenant is blocked for inactivity and your admin account is locked out.
  • Submit the ticket and note the case number.

The Azure Data Protection team will contact you via the alternative email address provided in the ticket. They will require you to verify your identity by answering security questions or providing domain ownership validation before they manually clear the inactivity block on their backend.

Documenting Your Incident Response Plan with WPS Office

WPS Office options related to Restoring an Azure Tenant Blocked for Inactivity
How WPS Office can support related document work.

While WPS Office cannot interface with Microsoft cloud servers or manually unblock an Azure tenant, it is an excellent application for documenting your IT recovery procedures. Relying solely on cloud-based documentation is dangerous when your primary cloud environment gets blocked. You need a locally accessible, standardized Disaster Recovery Runbook that details exactly what to do when access is severed.

You can use WPS Writer to draft a comprehensive administrative recovery plan. Start by creating a structured document that records your Tenant ID, the Initial Domain Name, and the emergency contact information for Azure Support. Utilize the built-in heading styles in WPS Writer to organize sections clearly, ensuring that any on-call IT staff can quickly navigate the document during an emergency.

If you are reviewing Microsoft's lengthy compliance and service-level agreement documents regarding data retention, you can leverage the WPS AI assistant to summarize these complex PDFs. Instruct the AI tool to extract only the timelines and critical administrative requirements, transforming dense legal text into actionable bullet points for your internal policies. Once your runbook is complete, use the native PDF export feature in WPS Office to convert the document into a secure, read-only PDF file. Distribute this PDF to your core IT team's local workstations so the step-by-step recovery workflow remains accessible even when your entire cloud directory is offline.

100% secure

Frequently Asked Questions

How long does the recovery window last before permanent deletion?

Microsoft typically provides a 30-day grace period after the initial inactivity block is applied. During this window, the tenant is suspended but the underlying data remains intact. Once the 30-day period expires, the tenant transitions to a permanently deleted state, and the directory data, including user accounts and application registrations, cannot be recovered by you or Microsoft support.

What actions qualify as tenant activity to prevent future blocks?

To prevent the 90-day inactivity timer from expiring, you must perform administrative actions within the tenant. Simply navigating the Azure portal does not always reset the timer. Qualifying activities include creating a new user account, modifying an administrative role, adding an enterprise application, assigning a license, or actively utilizing an authentication token generated by the tenant's directory.

Can I restore a tenant if I lost the original global administrator password?

If you lost the password and the tenant is currently blocked, the self-service password reset tool will likely fail. You must open a ticket with the Azure Data Protection team. They will require strict proof of domain ownership—usually by asking you to add a specific TXT record to your custom domain's DNS settings—before they will grant emergency access to restore the directory.

Will reactivating the tenant automatically restore my linked virtual machines?

No. An inactivity block on a free Entra ID tenant specifically affects the identity directory. If you had an active Azure subscription with deployed resources (like virtual machines or databases) that was cancelled due to billing failures or inactivity, reactivating the tenant only restores the user directory. You must separately navigate to the Subscriptions blade, locate the disabled subscription, and reactivate it to turn your hosted resources back on.

Khadija Khan

Khadija Khan is a tech writer who explores office suites and creates content to simplify everyday tools. She teaches and inspires through clear, engaging writing.