Our business tenant has been deauthenticated, and every user—including the emergency administrator account—receives AADSTS5000224 stating that the tenant is no longer available. Email, OneDrive, SharePoint, Azure-hosted websites, and Teams Phone numbers are all affected. We have opened several support cases, but most have received no response, while the one with progress keeps getting passed between departments. We are also seeing warnings about a short data-retention or deletion window and are urgently trying to preserve our files and phone numbers. We are working on setting up a CSP relationship, but currently cannot access the tenant to authorize it. Has anyone dealt with this situation or found an effective escalation path within Microsoft?
5 Answers
The practical escalation routes are a CSP, an existing Microsoft account manager or customer success contact, and your cyber-insurance or legal contacts. Large customers often get faster attention because they have formal escalation channels, while ordinary support queues can stall. Keep one detailed incident timeline with business impact, affected services, error codes, deletion warnings, and every case number so each escalation starts with the full facts instead of resetting the investigation.
Double-check the exact tenant state and retention deadline. An expired subscription, a suspended tenant, and a deauthentication caused by an abuse investigation can have different timelines. Some ordinary subscription-expiration states retain data for much longer than a few weeks, but that does not necessarily apply to a security or fraud lock. Get Microsoft to confirm the state and deletion date in writing, and preserve any notification emails and case numbers.
Treat the Teams Phone numbers as a separate emergency. Contact Microsoft’s telephone-number support team and your carrier immediately to ask what account, service, and porting details are required. If the numbers are tied entirely to the disabled tenant, porting may be difficult, but starting the process now is better than waiting until the licenses or numbers are removed permanently.
This is a painful reminder not to make one provider the dependency for identity, email, files, websites, phone service, and backups. For recovery, use whatever independent copies exist to stand up temporary email, file sharing, web hosting, and communications elsewhere. Afterward, keep tested backups outside the tenant, maintain infrastructure and website content in portable repositories, document phone-porting details, and have a disaster plan for operating without the primary cloud account.
This sounds similar to cases where Microsoft’s abuse or fraud detection incorrectly disables an entire tenant. The only successful resolutions I’ve heard about involved getting the case in front of a Microsoft escalation engineer. Avoid opening lots of new tickets if possible—keep pushing the case that already has history, request a high-severity escalation, and ask for the assigned engineer and a scheduled callback. A CSP or reseller may also be able to escalate through Partner Center, although that can be difficult if the tenant cannot accept new delegated access.
I’ve already tried phone and online support, a CSP route, and contacting Microsoft representatives through other business relationships. The error is AADSTS5000224, and the tenant is inaccessible from every account, including the emergency admin.

The phone service is billed through the same tenant, and the licenses disappeared when the tenant was deauthenticated. I’m trying to obtain the porting information from Microsoft, but I can’t reach the relevant team without tenant access.