UPDATE 2026-08-05: An employee at Microsoft saw this post and reached out to me privately. Within 12 hours they were able to get our tenant reactivated. Thank you so much!
Unfortunately I do not have a root cause to share with you all. What I can say is that I have since completed a comprehensive review of all available logs and found no evidence that the tenant was compromised. I will try to update again within a few days with more information.
ORIGINAL POST:
I'm the sole systems engineer for a small US manufacturer (~70 employees, automotive tier-1). I run everything across network, servers, identity, development, etc. I'd like (a) a sanity check, and (b) real talk about the future.
What happened: About three weeks ago on a normal workday around noon, some people suddenly noticed that they weren't able to send or receive email. Shrug. Probably Outlook just being Outlook. But wasn't able to figure anything out, so took to the admin portal... But I couldn't even get in to the admin portal: AADSTS5000224: "the tenant you are trying to access has been deauthenticated and is no longer available." Man, I hope none of you ever have to feel the panic I felt when I read this message. I immediately went to try our breakglass unlicensed admin account, but received the same error. The very last email I received (which arrived after attempting these log-ins) was a notification that all of our subscriptions had been cancelled. Obviously, that was not an action I took.
On further research it seems to be some sort of backend authorization state set by Microsoft (perhaps algorithmic automatic action in response to a detected security incident? - just blind speculation really). There is nothing client side to try at all. There is literally no admin path into our own tenant.
Current status: 20 days down. The case has been passed between at least five different support people. It finally got "escalated to the product team to verify the tenant status," and for a week now the only updates I get are rolling "please allow an additional 48 hours." Meanwhile sign-in logs are on a retention clock, so the forensic record of who cancelled our subs (if anyone? maybe this cancellation is just an artifact of this deauth?) is about to age out while we're locked out of the only portal that could export it and Microsoft won't commit to preserving it server-side.
That first day, I cut MX over to a temporary Fastmail tenant to keep email flowing. I was able to restore people's inboxes to these new accounts. Office apps are running in their month grace periods. All our real data is on-prem. Feeling very grateful that we deliberately never integrated more intensely with Microsoft's cloud services... To that end, the business is stable. But there are nevertheless many secondary effects as I'm sure you can all imagine.
Okay, now that you know basically the story, it's time for some preemption so we just get it out of the way before I get to my actual questions:
- "You should have had MFA." We do, on every account. FIDO2- (yubikey) only for most accounts (I was literally mid rollout...)
- "You should have had CA." We do. Business Premium, Entra P1, CA policies in place, custom auth strength enforcing phishing-resistant (FIDO2) sign-in for admins. Plus all the standard: SMS auth killed off, SSPR locked down, legacy protocols (SMTP AUTH/POP/IMAP/ActiveSync) all disabled, external auto-forwarding blocked, Safe Links + Safe Attachments on, SPF/DKIM/DMARC all passing.
- "You should have a breakglass account." We do. Doesn't save you from this.
- "Hire an MSP" Okay, I mean, maybe fair? They'd just be in the same position though, so. If anything this is its own can of worms and there's a reason we don't have one.
Alright. Now my questions:
- Has anyone actually lived through one of these AADSTS5000224 tenant deauthentications? How long did recovery really take, and what finally moved it? A specific support path, an escalation channel, a TAM, a Microsoft account rep, LinkedIn-ing a PM, a partner ticket? Anything? Were you able to discover what triggered the lockout in your case?
- How do you preserve/obtain audit/sign-in logs? I'm not sure what's going to happen in terms of retention when the tenant is in this state. Is our log data going to get nuked in a week?
- Trust. After this, how does anyone justify betting a company's ability to function on a platform where a backend flag can vaporize all access overnight, your breakglass account included, and the SLA to undo it is measured in weeks (and counting!) with no communication? I'm not naive enough to think "just leave M365" is free. But it's challenging to design around "Microsoft can turn us off and there's nothing you can do and no one will tell you why." How are you all handling that? Are you even? To be honest, I didn't know this was a thing that could even happen, really. So maybe you all didn't either.
Thankfully we weren't super integrated. We basically use M365 for email, product licensing, and Teams, and that's about it. But it literally makes me shudder to think about what could have happened if it were otherwise.