An Azure internet of things security solution including hardware, operating system, and cloud components.
Hello ArunKumar Pargunan,
Welcome to Microsoft Q&A .Thank you for reaching out.
When an Azure Sphere device is initially claimed, the ownership is recorded within the Azure Sphere Security Service. This ownership record persists independently of identity services. While an Azure AD tenant is used for authentication during device management operations, the actual ownership mapping is stored and enforced by the Azure Sphere backend service. As a result, deletion of an Azure AD tenant does not automatically remove or reset the device ownership record maintained by the Azure Sphere service.
In this case, the device was claimed using the legacy Azure Sphere CLI under an Azure AD tenant that has since been permanently deleted. Because the tenant no longer exists, authentication attempts against that tenant fail with an “invalid tenant” error. Since authentication to the original tenant is required for self‑service unclaim operations, all standard CLI‑based unclaim or reclaim flows are blocked. The device therefore remains in a claimed state that cannot be modified through customer‑side tools.
This behavior is a known edge scenario for Azure Sphere devices that were claimed prior to tenant deletion and currently has no supported self‑service recovery path. The device itself is healthy from a hardware perspective, but ownership remains locked at the service level.
At this stage, resolution requires manual review by the Azure Sphere service operations or engineering team, as ownership changes must be evaluated and performed directly within the Azure Sphere backend service. This is not a configuration issue, CLI issue, or authentication issue that can be resolved locally.
If manual release is approved after review, the device ownership record would be reset at the service level, allowing the device to be claimed again under an active tenant using standard CLI commands. If release is not approved, the support team will confirm the limitation and next available options.
Please note that there is currently no public documentation describing a guaranteed recovery process for this scenario, and all outcomes depend on backend validation and service review.
Thank you