Hello everyone,
I would appreciate some clarification from those who have experienced this scenario in a real customer environment.
We have a customer whose Microsoft tenant is currently under a compliance/security hold due to an ongoing investigation following a suspected cyber attack. As a result, the customer is currently unable to renew or reactivate their Dynamics 365 Finance & Operations licenses until Microsoft completes the investigation.
I understand that Microsoft retains the environments and databases for a certain period before permanent deletion. However, I would like to clarify the following points based on real-world experience:
- During the subscription lifecycle (Expired / Disabled), at what point do end users lose access to Dynamics 365 Finance & Operations?
- Is there any grace period during which end users can continue using the application after the subscription expires, or is access blocked immediately?
- During the retention period, are only tenant/global administrators able to access Lifecycle Services (LCS) and the administrative portals while the F&O application itself is unavailable to end users?
- Does this behavior vary depending on the licensing model (CSP, Enterprise Agreement, Microsoft Customer Agreement, etc.)?
- Has anyone encountered a situation where a tenant was under a Microsoft security/compliance investigation? If so, did Microsoft make any exceptions to the standard subscription lifecycle or data retention timeline while the investigation was ongoing?
If anyone has handled a similar case or can share both Microsoft's guidance and their practical experience, I would greatly appreciate your insights.
Thank you in advance!

Report
All responses (
Answers (