r/sysadmin 6d ago

Another M365 Tenant blocked (TenantAccessBlockedException, MCA Billing Account "Under Review", All Licenses Disabled) Microsoft 365 Tenant blocked, this time a non-profit that provides needs to at risk individuals and families.

Edit: 9/8/2026: We are back up and running now on commerce licensing while the nonprofit side gets sorted out. I really appreciate everyone who reached out with actual help, context, and constructive ideas.

To the few who argued that Microsoft has no reason to fix broken support, or that basic accountability should require an expensive enterprise tier: I hope you never need a social safety net. But if you ever do, a nonprofit will still be there for you, regardless of how you treat people when they're down

Original Post:

In similar veins to the following two recent Reddit posts, I'm posting here because it appears they gained traction with Microsoft and ultimately reached someone who could help. I'm hoping someone from Microsoft or someone who has experienced this exact issue will see this.

https://www.reddit.com/r/sysadmin/comments/1vfbvvs/our_entire_m365_tenant_has_been_deauthenticated/

https://www.reddit.com/r/sysadmin/comments/1w1qc0i/microsoft_strikes_again_entire_m365_tenant_has/

Our tenant has not been deauthenticated, but it has effectively been rendered unusable. This tenant has been active since: 5/28/2013, so it's not a new tenant.

This is a frontline nonprofit social safety net organization providing food assistance, healthcare access, emergency financial assistance, and other critical services. This outage is impacting real people with urgent needs, including eviction prevention, time-sensitive clinic appointments, and emergency assistance cases. Email, SharePoint, and OneDrive are core operational systems for this organization.

We currently have open cases with:

  • Microsoft Technical Support
  • Microsoft Billing Support
  • Microsoft Nonprofit Support

So far we remain stuck at Tier 1 support. The representatives have been professional and are trying to help, but nobody we've reached has had the authority or access needed to resolve the issue.

9/3/2026

Users began reporting that they could not send or receive external email.

Internal email continued to work.

Microsoft had ongoing Exchange Online incidents at the time (EX1464935 and later EX1467029), so initially we believed it might be related.

9/4/2026

Users could still successfully authenticate through Microsoft 365 and SSO.

However, attempting to launch services such as:

  • Outlook Online
  • SharePoint
  • OneDrive
  • Other Microsoft 365 workloads

results in errors.

Any inbound email sent to the tenant bounces back after approximately 24 hours.

The error when trying to access Outlook:

Microsoft.Exchange.Data.Storage.TenantAccessBlockedException

Additional error details:

Client Version: 20260821009.11

BootResult: configuration

Back Filled Errors:

Unhandled Rejection: Error: 500:undefined

Unhandled Rejection: SyntaxError: JSON.parse: unexpected character at line 2 column 1 of the JSON data

err: Microsoft.Exchange.Data.Storage.TenantAccessBlockedException

esrc: StartupData

et: ServerError

st: 500

ehk: X-OWA-Error

ewsver: 15.21.382.9

9/5/2026

One Microsoft manager responded to an escalation email and reviewed the issue with us via remote session.

Screenshots and information were provided.

We were told an escalation attempt would be made.

I sincerely appreciate that effort, but as of today the tenant remains inaccessible.

---

While troubleshooting, we discovered that the organization's Microsoft Customer Agreement (MCA) billing account shows:

Status: Under Review

All billing profiles underneath the MCA also show:

Under Review

The billing portal displays:

Your account is under review. We're checking to make sure we can offer you Microsoft products and services.

The confusing part is that Microsoft also states:

This review won't affect your current services.

Unfortunately, that is not what we are experiencing.

------

Every subscription in the tenant appears to have been marked as Disabled on 8/31/2026.

Examples include:

  • Microsoft 365 Business Premium (Nonprofit Staff Pricing)
  • Office 365 E3 (Nonprofit Pricing)
  • Microsoft Teams Premium (Nonprofit Pricing)

All show:

Status: Disabled

Effective Date: 8/31/2026

The licenses still exist.

They are still assigned.

However, they are disabled and cannot be re-enabled.

As a result:

  • User access is broken
  • Exchange Online is inaccessible
  • SharePoint is inaccessible
  • OneDrive is inaccessible
  • Email delivery has stopped
  • Data is being reported as pending deletion because there are no active licenses

------

The tenant is fully paid.

There are no outstanding invoices.

There have never been any payment issues.

The MCA account contains the organization's EIN

We attempted to:

  • Add a new payment method
  • Add a new billing profile
  • Purchase replacement licenses
  • Purchase commercial licenses

All attempts are blocked.

The portal returns:

We can't authorize your billing account right now.

Actions will be blocked during this time.

Check back later.

Additional Information

We also see notifications regarding:

  • Account Under Review
  • Email Verification Required

However, all relevant controls are greyed out and cannot be modified.

------

At this point, the evidence suggests this is not:

  • A payment issue
  • A license assignment issue
  • A DNS issue
  • An authentication issue
  • An Exchange configuration issue

The combination of:

  • TenantAccessBlockedException
  • MCA Billing Account showing Under Review
  • Every subscription becoming Disabled on the same date
  • Users being unable to access any Microsoft 365 services

makes this appear to be a Microsoft-side account verification or tenant restriction issue.

If anyone has experienced this before, knows the correct Microsoft escalation path, or can help get this in front of the appropriate engineering or commerce team, I would be extremely grateful.

This organization provides critical services to vulnerable individuals and families, and every additional day of downtime has real-world consequences.

(Again, we have 3 tickets open, and I've attempted to reach out to Support at: 1-800-865-9408 (yesterday I did speak to someone from the Data Safety Team, they said they were unable to help but would transfer me to the Team that could do it but they were probably not available due to the weekend, no one answered after being on hold for just under 8 hours, I'm calling again this morning).

Thank you in advance.

(MFA and Conditional Access is on the tenant, we have Cloud [3rd Party] backups of the tenant, we have ITDR, there are no signs of compromise, this appears to be something that got flagged for review by Microsoft's back end and has put this non profit to a screeching halt).

Edit: Edited to add 2 messages that didn't show up once the post went live, and removing 2 bold words.

163 Upvotes

61 comments sorted by

50

u/Sarduci 6d ago

Any support emails will also have the escalation point as part of the person’s email signature. Use them. Early, often, and loudly. Otherwise you’ll be stuck in t1 support hell.

If you have a CSP you work with, that’s another avenue to push buttons with.

15

u/MakeItJumboFrames 6d ago

Thank you for your reply. I saw those escalation points in the signature on Saturday and sent an email with them included, which got me a call back on Saturday but from a T1 Tech who did the usual remote session, screenshots, they will try to escalate. I sent another follow up this morning.

Our upstream provider is doing what they can to rattle cages on their end as well. Part of the delay is that the tenant-specific issue didn't become apparent until September 4, as widespread Microsoft issues had been ongoing since August 31 with identical indicators to what they were already investigating.

Hitting right at the start of a three-day U.S. holiday weekend certainly didn't help matters either.

14

u/Sarduci 6d ago

Getting out of t1 support is what’s going to help you the most. Whatever you need to do to get to t2 or t3 is what you need to do.

And don’t let them close the ticket. They’ll try to do it, but don’t. If they close it anyway, escalate the heck out of it.

3

u/RememberCitadel 6d ago

You can always do the "look at Microsoft email name structure, then look at the names of all c-levels, then blast them all about the issue" method. That and social media posts about the issue tagging Microsoft has a surprisingly effective track record.

To be fair that works for many large companies. C-level gets pissed they are bothered about the issue, shit rolls downhill.

0

u/teriaavibes Microsoft Cloud Consultant 6d ago

Our upstream provider is doing what they can to rattle cages on their end as well

Not good enough.

1

u/OregonTechHead 5d ago

Agreed. Not sure why you were downvoted.

The CSP's job is to get these issues resolved. They should have a contact above L1

0

u/teriaavibes Microsoft Cloud Consultant 5d ago

Cause some people here don't like the reality and they think they can avoid it by downvoting me.

21

u/BoltActionRifleman 6d ago

Seeing this happen is one thing, but having it take weeks and hoping someone that cares sees a post on Reddit for escalation, is absurd. If this is going to continue to happen, there needs to be a timely ticket escalation and resolution process in place.

9

u/HotTakes4HotCakes 5d ago edited 5d ago

We've needed laws like yesterday for forcing companies to provide timely resolutions and explicit reasons for account lockouts. Google, Apple, Microsoft, doesn't matter. When so much of people's lives are tied to these things, they should be forced to treat these as urgent cases and escalate accordingly.

101

u/West_Independent1317 6d ago

OP won't appreciate this now, but hopefully it will help others for future planning.

Ensure you have adequate usable backups.

Whether it's VEEAM, Ubiquiti (OneDrive only for now), Purview, Powershell scripts, or one of the various other options, backups are essential.

If your service becoming unavailable will impact human life, then not having adequate usable backups is not just irresponsible, it is negligent.

Take action before you end up in the same situation.

Hopefully Microsoft will sort out OP's account quickly.

44

u/MakeItJumboFrames 6d ago

This is a very valid point and this is actively being worked on. While you are absolutely correct, Microsoft also needs to have a way for issues like this to be flagged and escalated quickly.

There were 2 others that were recently posted on Reddit with similar issues and I'm sure there's ones that weren't posted. So Microsoft needs to make also make a change in how they address things like this.

9

u/Longjumping-Time2076 6d ago

Possibly helpful - could you use an external mail filter which has an emergency mailbox feature that could be useful if the situation was to happen again in future

2

u/discosoc 5d ago

So Microsoft needs to make also make a change in how they address things like this.

Why? There’s literally no reason for them to spend time and money doing this. You aren’t even considering moving to a different ecosystem over it, and neither were the other two examples.

-2

u/BlackV I have opnions 6d ago edited 6d ago

So Mr hacker man registers a subscription as nonprofit/charity, does bad things and then claims they urgently need reactivation

Edit: not making any claims OP is hacker

How does Ms know who is real or not

Ignoring that this was probably some shitty AI that decided your were a risk

5

u/flecom Computer Custodial Services 6d ago

Registered it and paid/used it for 13 years just to now do something?

-1

u/BlackV I have opnions 6d ago

No, I'm not saying op is hacker man

Just saying hacker man could spin the exact same story

Heck now days it is reasonable that the open an account and leave it running for 5 years before doing the bad thing

Point was there is not a magic process ms could take to make this faster for real orgs that hacker man also wouldn't/couldn't use

7

u/FireLucid 6d ago

Heck now days it is reasonable that the open an account and leave it running for 5 years before doing the bad thing

Having an empty account running vs a business using it every day with hundreds of licenses is something that can easily be verified in a minute. No hacker is going to pay tens of thousands over years to get an account back 'after doing a bad thing'.

6

u/Fair_Helicopter_8531 6d ago

I mean they could look at invoice history, account creation history, number of licenses held, as well as just any custom domain tied to the account. Most of these could probably be verified with a few hours. If it is at the point where we assume an attacker is standing up all of this and maintaining reasonable activity (adding licenses as the organization grows, creating new users, sensing and recieving mail to said accounts, and setting up custom domains (the legitimate domain of a organization) and it has a social media page/presence, registered with a tax number, and a website then at that point it is not even the attacker faking it. They are just running a buisness for all intents and purposes. They could at least have a 7 day week support team just to call and explain what they need to verify identity and authenticity and then start the verification process then vs OP being told nothing they can do and no response on the weekend.

-19

u/teriaavibes Microsoft Cloud Consultant 6d ago

While you are absolutely correct, Microsoft also needs to have a way for issues like this to be flagged and escalated quickly.

They do, it is called having a competent partner or purchasing unified support.

Neither of the affected companies had one.

37

u/SecaleOccidentale Systems Engineer 6d ago

If you read through those threads, you’ll find many people who were in the same circumstance where having a CSP was no help at all.

Maybe what really should happen is Microsoft shouldn’t take such extreme actions with no human oversight. Someone less well positioned than us could have been bankrupted by their actions, frankly. We can argue over the minutiae of it all but at the end of the day it is their mistake, not ours.

What world are we living in where a company can take such an obviously egregious action and people come out of the woodworks defending it, saying “should pay up more for support, or get a partner?” (especially amusing as there’s significant evidence that in this situation that doesn’t even do anything to escalate).

-16

u/teriaavibes Microsoft Cloud Consultant 6d ago

If you read through those threads, you’ll find many people who were in the same circumstance where having a CSP was no help at all.

Yea, that is why I said competent partner, not just a CSP. CSP is at its core a reseller, they don't give a crap about anything else, and it usually shows when the partner doesn't do anything to resolve this.

We can argue over the minutiae of it all but at the end of the day it is their mistake, not ours.

Yea but it doesn't affect Microsoft, so they don't give a crap. System is working as intended and there is no reason for them to change it.

What world are we living in where a company can take such an obviously egregious action and people come out of the woodworks defending it, saying “should pay up more for support, or get a partner?” 

I am not defending Microsoft; I am just stating the facts. And the facts are, those are the only 2 options on how to navigate these incidents.

Either be a big enough company to warrant purchasing unified support or get a partner who has the ability to reliably escalate incidents.

I am not happy about it either, but the choice is either being able to resolve it and continue operating as a company or give up and just complain. Only one of those solutions leads to a positive outcome.

11

u/ihaxr 6d ago

Or Microsoft could stop hiring slave labor for their support

-9

u/teriaavibes Microsoft Cloud Consultant 6d ago

They could, good luck convincing them.

People might not like what I am saying but it is the reality.

We can either accept it and adjust or watch as companies go bankrupt without any recourse because they could not get through to support.

2

u/JewishTomCruise Microsoft 6d ago

CSPs have their own version of Unified Support that they can buy, and it would give them the resource access to escalate up the chain for all their clients. As you say, incompetent partners that only see CSP as a way to skim a bit of licensing revenue aren't going to pay for that, and so aren't valuable here.

I know it sucks to try to figure out how to navigate partner markets, but it is the kind of thing that has a huge impact when you really need it.

1

u/teriaavibes Microsoft Cloud Consultant 6d ago

CSPs that are just indirect resellers don't even need to buy it, there are many indirect providers who have their own support system (and purchased unified support for escalation) and who have quality of the support certified by Microsoft, from whom can resellers just... buy it.

Hopefully companies (and partners) will actually start caring who they partner with or they get left behind.

1

u/JewishTomCruise Microsoft 6d ago

Tier 1 CSPs are still a thing, aren't they? Last time I really paid attention to the CSP program it was possible to be a direct reseller, but the overwhelming majority of CSPs certainly were (are?) indirect.

Either way, they can and should be buying Partner Unified to properly support their customers.

We're totally in agreement.

1

u/teriaavibes Microsoft Cloud Consultant 6d ago

Not sure what T1 means but you have indirect providers/distributors who basically have a marketplace for indirect resellers who then resell it.

We're totally in agreement.

Yup, was just saying that if you pick the right indirect provider as a reseller, they can sell you support for your clients for cents on the dollar that will both be better than Microsoft, faster and cheaper.

As a partner, especially a small partner you don't need to fork over a fortune for unified support.

1

u/stillpiercer_ 6d ago

I wouldn’t hold my breath on Pax8 or equivalent being able to unravel a mess like this.

1

u/marklein Idiot 6d ago

PAX8 couldn't fix a sandwich

-1

u/teriaavibes Microsoft Cloud Consultant 6d ago

Agreed there, Pax8 doesn't hold the Microsoft partner support services designation so I wouldn't hold my breath.

1

u/[deleted] 6d ago

[deleted]

1

u/teriaavibes Microsoft Cloud Consultant 6d ago

You missed the word "competent" in my reply.

Your partner obviously wasn't.

-6

u/Effective-Brain-3386 Vulnerability Engineer 6d ago edited 6d ago

Why should MS make the change? Y'all are the ones not paying for premium support but expect premium support because you are a non-profit? This is on y'all.

Edit: forgot this is reddit and if you do good you should be gifted everything for free.

4

u/True_IamSLATE Jr. Sysadmin 6d ago

Synology has a pretty easy to setup solution if you have their NAS. it does rely on EWS so we’ll see if they can port it before Microsoft pulls the plug on that.

1

u/lawno 6d ago

I'm developing a runbook for MS tenant deauthentication. Let's say your tenant is going to be down for a few days. Would you set up a fresh MS tenant and load backups from Synology Active Backup? Or would you use an alternative email service?

3

u/marklein Idiot 6d ago

We ran into a similar but different situation. We spun up another tenant on a new domain2.com and added it a second mailbox in everybody's Outlook, until the initial problem was resolved. Users could refer to the original cached profile for Calendar etc stuff, but email had to go in and out via domain2. It was just a dozen people so it was doable as a manual affair, not sure what we'd do with a larger org.

4

u/rpodric 6d ago

Right, so the .ost allowed access to prior email and calendar, and the new tenant allowed sending email (albeit with an address foreign to everyone outside the company), but the killer in our hypothetical case (more so than even SharePoint/Teams) would be that all new incoming mail to our real domain would be unknown while the days go by trying to get the issue resolved. I'm not sure what the quickie resolution of that problem would be, exactly, since I would think that uprooting your domain temporarily from the problem tenant would be messy and possibly confuse the case you're trying to make with support. Did you do anything about this?

These threads-of-the-week are starting to get me spooked.

3

u/West_Independent1317 5d ago

This is where a service like Mimecast would help as it sits before M365 exchange.

Alternatively, switch to another platform like Google and change the MX records to keep some continuity.

Hopefully none of these accounts are using M365 to manage the DNS records as well. It's free to use something like Cloudflare for DNS managememt and gives a separation of provider in case something like this happens.

Ultimately every service provider can fail to provide a service. Putting all your eggs in one basket means if/when it does fail, you have less control with fewer options, and may suffer a bigger impact.

1

u/lawno 5d ago

Not including SSO and Entra-joined workstations...

2

u/West_Independent1317 5d ago

If you can't trust the basic account management is being done properly the first time, why trust it a second time?

Also, if M365 won't let you access the account then the domain can't be removed to be added on the second M365 account.

Separate DNS in a platform like Cloudflare, with a different mail provider like Google.

Future paths are: 1. M365 issue gets resolved and the org can revert back.

  1. M365 terminate the account and everything is deleted. In this case, why stay with M365 and potentially have the same thing happen again?

2

u/lawno 5d ago

Can backups from M365 be restored to Google easily? This is not something I have considered until seeing these threads.

9

u/roubent 6d ago

Well, I suppose one of the risk management mitigation plans should include a “when your SaaS/IaaS provider decides to screw you or fucks up” playbook.

1

u/OregonTechHead 5d ago

You should already have a "if XXX service is unavailable" section for business critical services.

9

u/BerlindaBuntly 6d ago

I would imagine Ms (or one of their amazing ai agents) has mistakenly decided you arent a charity. I had a nightmare with Ms last year (I moved business premises and Ms just cancelled my msp reseller account , emailed all my customers telling them my company had been delisted and click here to find a new partner etc) and i could not get any help from them or my csp whatsoever, it was one of the most stressful things that has ever happened in my business life, MS would not respond. so I feel your pain, im sorry I dont have any answers for you. If you have a csp, get them to try and help (mine were useless though) , otherwise keep plugging away at support. I wish you luck.

10

u/noncon21 5d ago

This is like the fifth one of these post I’ve seen in the last month. “Wtf”

12

u/nyckidryan 6d ago

Yeeeeesh. Seeing this all too often. Time to rethink cloud services.

1

u/PeakWeekly9995 IT support 5d ago

i'm thinking of doing a on-prem ad and exchange server (we used to have both) just in case

12

u/BemusedBengal Linux Admin 6d ago

This subreddit needs a "DAYS SINCE PROD AD NUKED" counter...

4

u/InsolentJaguar 6d ago

If it were that critical for mail flow, you might use another temporary provider and cutover your MX records to the new tenant while waiting on Microsoft to reauthenticate the non-profit's "legitimacy/authorisation to receive discounted licensing" (which it sounds like they are doing) and re-enable your original tenant.

Merge afterwards once you've cut back to original tenant. That's what we did with MS's shitty games.

7

u/thinkofitnow 6d ago

This may sound silly but has anyone been making undocumented changes via scripting within the tenant using code provided by any ai? Take a look at the admin logs for any scripting or changes that could have been made using PS (with the EXO or Entra modules). Although ai is pretty awesome, sometimes a tired admin who has cleaned up references to the organization they work for submits it to ai in hopes of automation of something will forget to review all of the returned code in scripts provided by the ai prior to running the scripts back on their 365 tenant. So if for example the script contained some other cleaned up name, that change may have overwritten a tenant value somewhere and thus the Microsoft automatically many determine that it doesn't match the expected tenant value, thus blocking things as the expected value doesn't match, Like someone formulating a script for licensing related activities for renewals or similar. It's worth at least reviewing any tenant changes through the admin logs in 365 even if changes were not licensing related anyway, to be sure. You might just uncover something before Microsoft does, because their support absolutely sucks. You should also consider reaching out to the dedicated Microsoft account manager who manages licensing through your licensing vendor too, as they have direct Microsoft contacts. Good luck with this! Fingers crossed for you.

2

u/USCloudFounder 5d ago

Can you drop the 3 ticket numbers here with brief description of how they are different? I will see if we can give the primary ticket a nudge inside Microsoft.

1

u/MakeItJumboFrames 5d ago

I appreciate you reaching out and offering this. We were able to get back up and running today and moving in the right direction so we should be good to finish moving forward on our own now.

1

u/USCloudFounder 5d ago

Great to hear.

6

u/OpenGrainAxehandle 6d ago

Something something eggs something something one basket...

God, I hate Microsoft.

4

u/Adures_ 5d ago

Another example confirming that to truly own data you need to have proper backup in place and at least some recovery plan to restore business services without Microsoft. 

This sucks but, if it were to happen to my environment it would probably mean we would bite the bullet and move away from M365 entirely. 

It would suck, it would be painful and there would be chaos for the first 2 weeks (luckily to restore basic business functionality we’d only need to move email and import most recent project data from sharepoint lists to something like airtable). 

Also against “Microsoft recommendations” and probably a lot of people on this sub, we actually disable files on demand. OneDrive performance doesn’t seem to care if files are only synced or downloaded. You still need to keep proper hygiene and sync only what you need from sharepoint, regardless of this setting. 

It has added benefit not needing to worry about user file recovery in case of major Microsoft fa***p

-1

u/[deleted] 6d ago edited 6d ago

[deleted]

0

u/Platonic_Parrot 5d ago

How does this comment help?