## TL;DR
In the Entra admin center, open the user and flip "Block sign in" back to No, then check the sign-in logs and audit logs to find what disabled it (risk policy, admin action, or HR-driven lifecycle). Fix the cause or it will be disabled again.

## The error
```text
Your account has been disabled. Please see your administrator.
```

## Steps
1. Entra admin center > Identity > Users > the user > Edit properties. Expected: "Block sign in" is set to Yes. Set it to No and save.
2. Check Audit logs for the user around the disable time. Expected: you see who or what set Block sign in (an admin, a risk policy, or a provisioning flow).
3. Check Identity Protection > Risky users. Expected: risk state if a risk policy did it. Dismiss the risk or require a password change per policy before re-enabling.
4. If an HR-driven lifecycle workflow disabled it, confirm with HR whether the person should be active. Expected: a clear yes/no. Re-enabling someone HR offboarded creates a bigger problem than the ticket.
5. Have the user sign in. Expected: success. Document the cause in the ticket.

## When to use
- Entra sign-in blocked with the account-disabled message
- Admin needs to distinguish disable vs lock vs delete

## When not to use
- Account deleted (restore from deleted users, different flow)
- User locked by smart lockout (different message, different fix)

## Compatibility
- Microsoft Entra ID (all tiers); Identity Protection features need P2

## Variants
### Disabled again within a day
A policy or provisioning flow is re-disabling it. Find the automation before re-enabling a third time.
### Bulk disables after a directory sync error
Check Entra Connect sync errors; a mis-scoped OU can disable hundreds of accounts at once.

## Why it happens
"Block sign in" is the standard offboarding and risk-response lever. It gets set by admins, by risk policies reacting to compromise signals, and by HR lifecycle automation, and each needs a different follow-up.

## Edge cases
- Guest accounts: the sponsor or access review may have disabled them; check the guest lifecycle.
- Break-glass accounts must never be left disabled without a documented reason.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_B1VDZ6W70hd39fWXMouy-w
