External entra id

Ashik J 20 Reputation points
2026-03-07T00:06:20.3766667+00:00

We created a azure external entra id for portal setup after creating external tenant we1000075217

sent invitation to my local email when accepting invitations showing below error


Microsoft Security | Microsoft Entra | Microsoft Entra External ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-07T00:06:38.36+00:00

    The error in the screenshot indicates that the external user is being asked for an additional verification method (for example, MFA) that is not available or not configured for that account in the external tenant.

    In an External ID (CIAM) tenant, customer accounts are meant to be local accounts in that tenant, not your internal corporate account. If the invitation was sent to the same email address that is also used as an admin account or as a work account in another tenant, sign‑in can fail or sign in with the wrong identity.

    Use these steps to fix the scenario:

    1. Verify the correct tenant and tenant details
      • In the Microsoft Entra admin center or Azure portal, switch to the external tenant and confirm its Name, Tenant ID, and Primary domain under Microsoft Entra ID → Overview.
      • Always use the generic https://entra.microsoft.com entry point to sign in as the admin, not a tenant‑specific URL, so that the admin account is selected correctly.
    2. Avoid using the same email for admin and customer
      • If the admin who created the external tenant used the same email address to create a local customer account in that tenant via self‑service sign‑up, the tenant will contain two identities with the same email: one admin and one customer.
      • In that case, sign‑in can land on the least‑privileged customer account, which then cannot satisfy the required verification and cannot administer the tenant.
      Workaround:
      • For customer sign‑up, use a different email address than the tenant admin’s email.
      • If a duplicate customer account already exists with the admin’s email, sign out and then sign back in via https://entra.microsoft.com with the admin account, and manage or delete the customer account from Users.
    3. Re‑invite the external user
      • After confirming that the external user is represented only once in the external tenant (as the intended customer/guest account), send a new invitation from the external tenant.
      • The user should redeem the invitation with that same account and complete any required MFA/verification steps.

    If the error persists for a specific external user, check:

    • Whether their home organization has policies that block external or email‑verified users from being created.
    • Whether there are conflicts with existing identities (for example, proxyAddress collisions) that prevent the external account from being provisioned correctly.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.