your account has been disabled" entra id fix
Re-enables a disabled Microsoft Entra ID account and finds why it was disabled. Covers admin re-enable, sign-in log review, and the risky-sign-in or lifecycle causes. Use when Entra blocks sign-in with the account-disabled message. Not for locked or deleted accounts.
TL;DR
In the Entra admin center, open the user and flip "Block sign in" back to No, then check the sign-in logs and audit logs to find what disabled it (risk policy, admin action, or HR-driven lifecycle). Fix the cause or it will be disabled again.
The error
Your account has been disabled. Please see your administrator.Steps
- Entra admin center > Identity > Users > the user > Edit properties. Expected: "Block sign in" is set to Yes. Set it to No and save.
- Check Audit logs for the user around the disable time. Expected: you see who or what set Block sign in (an admin, a risk policy, or a provisioning flow).
- Check Identity Protection > Risky users. Expected: risk state if a risk policy did it. Dismiss the risk or require a password change per policy before re-enabling.
- If an HR-driven lifecycle workflow disabled it, confirm with HR whether the person should be active. Expected: a clear yes/no. Re-enabling someone HR offboarded creates a bigger problem than the ticket.
- Have the user sign in. Expected: success. Document the cause in the ticket.
When to use
- Entra sign-in blocked with the account-disabled message
- Admin needs to distinguish disable vs lock vs delete
When not to use
- Account deleted (restore from deleted users, different flow)
- User locked by smart lockout (different message, different fix)
Compatibility
- Microsoft Entra ID (all tiers); Identity Protection features need P2
Variants
Disabled again within a day
A policy or provisioning flow is re-disabling it. Find the automation before re-enabling a third time.
Bulk disables after a directory sync error
Check Entra Connect sync errors; a mis-scoped OU can disable hundreds of accounts at once.
Why it happens
"Block sign in" is the standard offboarding and risk-response lever. It gets set by admins, by risk policies reacting to compromise signals, and by HR lifecycle automation, and each needs a different follow-up.
Edge cases
- Guest accounts: the sponsor or access review may have disabled them; check the guest lifecycle.
- Break-glass accounts must never be left disabled without a documented reason.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_B1VDZ6W70hd39fWXMouy-w