Azure Sphere device stuck on deleted Azure AD tenant — cannot unclaim or reclaim

ARUNKUMAR PARGUNAN 20 Reputation points
2026-03-17T05:26:46.36+00:00

Hello,

I am facing an issue where my Azure Sphere device is permanently locked to an Azure AD tenant that has been deleted, and I am unable to reclaim it under my current active tenant.


Background

The device was originally claimed by my father using the Azure Sphere Legacy CLI under his Azure AD tenant. That [TENANT ID REMOVED] has since been permanently deleted from Azure Active Directory. We no longer have any credentials, admin access, or any way to authenticate against that tenant.


Device Details

  • Device ID: [DEVICE ID REMOVED]
  • Hardware: MediaTek MT3620 Azure Sphere development board

The Problem

When I attempt to claim the device under my current tenant using the Azure Sphere CLI, it fails because the device is already associated with the old deleted tenant. When I try to authenticate against the original tenant to perform a self-serve unclaim, I get this error:

{
  "error": "invalid_tenant",
  "error_description": "AADSTS90002: Tenant '
  "error_codes": [90002],
  "timestamp": "2026-03-06 21:19:21Z",
  "trace_id": "
  "correlation_id": "
}

So the normal self-serve unclaim flow via CLI is completely blocked — there is no tenant to authenticate against.


What I've Already Tried

  • Attempted azsphere device unclaim — fails because the original tenant no longer exists
  • Attempted to authenticate against the old tenant — returns invalid_tenant / AADSTS90002
  • Raised a support request with the Azure Sphere PG Support team on 6 March 2026
  • The support team confirmed that Azure Sphere is a global service where devices reside within Microsoft-owned Azure Sphere tenants (separate from Azure AD tenants), and asked for clarification on how the device was originally managed
  • I replied on 11 March 2026 clarifying it was claimed via the Legacy CLI, but have not received a response since

My Current Active Tenant

  • Tenant ID: [TENANT ID REMOVED]
  • Primary domain: [MAIL ID REMOVED]

What I Need

I need Microsoft / the Azure Sphere team to manually disassociate the device from the deleted tenant in the Azure Sphere Security Service (AS3), so that I can reclaim it under my current active tenant. This is a development board I am using for learning purposes.

Has anyone else faced this situation? Is there a specific escalation path or additional verification process that the Azure Sphere team requires to authorize a manual device release?

Any help is appreciated. Thank you.

Azure Sphere
Azure Sphere

An Azure internet of things security solution including hardware, operating system, and cloud components.


Answer accepted by question author
Karnam Venkata Rajeswari 5,340 Reputation points Microsoft External Staff Moderator
2026-04-05T18:15:52.3966667+00:00

Hello ArunKumar Pargunan,

Welcome to Microsoft Q&A .Thank you for reaching out.

When an Azure Sphere device is initially claimed, the ownership is recorded within the Azure Sphere Security Service. This ownership record persists independently of identity services. While an Azure AD tenant is used for authentication during device management operations, the actual ownership mapping is stored and enforced by the Azure Sphere backend service. As a result, deletion of an Azure AD tenant does not automatically remove or reset the device ownership record maintained by the Azure Sphere service.

In this case, the device was claimed using the legacy Azure Sphere CLI under an Azure AD tenant that has since been permanently deleted. Because the tenant no longer exists, authentication attempts against that tenant fail with an “invalid tenant” error. Since authentication to the original tenant is required for self‑service unclaim operations, all standard CLI‑based unclaim or reclaim flows are blocked. The device therefore remains in a claimed state that cannot be modified through customer‑side tools.

This behavior is a known edge scenario for Azure Sphere devices that were claimed prior to tenant deletion and currently has no supported self‑service recovery path. The device itself is healthy from a hardware perspective, but ownership remains locked at the service level.

At this stage, resolution requires manual review by the Azure Sphere service operations or engineering team, as ownership changes must be evaluated and performed directly within the Azure Sphere backend service. This is not a configuration issue, CLI issue, or authentication issue that can be resolved locally.

If manual release is approved after review, the device ownership record would be reset at the service level, allowing the device to be claimed again under an active tenant using standard CLI commands. If release is not approved, the support team will confirm the limitation and next available options.

Please note that there is currently no public documentation describing a guaranteed recovery process for this scenario, and all outcomes depend on backend validation and service review.

Thank you

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.