B2B guest invitations are blocked for this tenant due to suspicious activity

dvibe 0 Reputation points
2026-09-04T05:04:08.3466667+00:00

Hello Microsoft Support,

We are experiencing a critical issue with B2B guest invitations in our Microsoft Entra ID tenant.

As part of a legitimate customer onboarding / SSO rollout, we invited a large number of external users for our client organisation. After this bulk onboarding, new B2B guest invitations started failing.

Microsoft Graph now returns:

"code": "Forbidden","message": "Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help."

Manual invites in the Azure / Entra portal also fail with:

"User invitation failed. Insufficient privileges to complete the operation."

This happens even when using a Global Administrator account. We have also checked External collaboration settings:

  • guest invitations are enabled
  • invitations are allowed to any domain
  • the affected domains are not blocked

Context:

We are the Global Administrators for this tenant. The invitations were part of a legitimate production customer rollout. The users are legitimate customer users who need access to our application via SSO.

Impact:

  • We can no longer invite new B2B guests.
  • Some legitimate customer users cannot access our application via SSO.
  • This is affecting an active customer rollout.

Request:

  • Please review and remove the "suspicious activity" block on our directory's B2B invitation capability.
  • Please confirm any guidelines or best practices to avoid hitting this block during legitimate customer bulk onboarding.

We can provide the Tenant ID/domain, Global Administrator email, Graph request IDs, timestamps, and business justification privately if needed.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

1 answer

Sort by: Newest
  1. David Broggy 6,801 Reputation points MVP
    2026-09-08T12:23:55.72+00:00

    Hi Dvibe,

    you will need to open a ticket, this site doesn't respond to support requests.

    What to do:

    •         Open a support case as a Global Administrator: Microsoft 365 admin center > Support > Help & support (or Azure portal > Help + support > New support request > Microsoft Entra ID).

    Title it "B2B invitations blocked for directory due to suspicious activity" and include the tenant ID, the exact Graph error text and code, request IDs and timestamps, and a short description of the legitimate onboarding (customer name, expected volume, domains). Support reviews the activity and removes the flag; turnaround is usually a few business days.

    •         While you wait, confirm the basics so nothing else is in the way:

    Entra ID > External Identities > External collaboration settings (who can invite, allowed/blocked domains), and Cross-tenant access settings (inbound/outbound B2B collaboration for the partner tenants).

    Changes there can take 15–60 minutes to apply.

    Avoiding it next time:

    •         Throttle bulk invitations: send them in smaller batches spread over time rather than thousands in one run, and use a dedicated service principal with only the Guest Inviter role.

    •         Prefer email one-time-passcode / direct-link redemption (invitation email suppressed) or self-service sign-up user flows for large customer onboarding instead of mass invitation emails.

    •         Restrict Collaboration restrictions to an allow-list of known customer domains.

    I hope that helps!

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.