Managing external identities to enable secure access for partners, customers, and other non-employees
The error in the screenshot indicates that the external user is being asked for an additional verification method (for example, MFA) that is not available or not configured for that account in the external tenant.
In an External ID (CIAM) tenant, customer accounts are meant to be local accounts in that tenant, not your internal corporate account. If the invitation was sent to the same email address that is also used as an admin account or as a work account in another tenant, sign‑in can fail or sign in with the wrong identity.
Use these steps to fix the scenario:
- Verify the correct tenant and tenant details
- In the Microsoft Entra admin center or Azure portal, switch to the external tenant and confirm its Name, Tenant ID, and Primary domain under Microsoft Entra ID → Overview.
- Always use the generic
https://entra.microsoft.comentry point to sign in as the admin, not a tenant‑specific URL, so that the admin account is selected correctly.
- Avoid using the same email for admin and customer
- If the admin who created the external tenant used the same email address to create a local customer account in that tenant via self‑service sign‑up, the tenant will contain two identities with the same email: one admin and one customer.
- In that case, sign‑in can land on the least‑privileged customer account, which then cannot satisfy the required verification and cannot administer the tenant.
- For customer sign‑up, use a different email address than the tenant admin’s email.
- If a duplicate customer account already exists with the admin’s email, sign out and then sign back in via
https://entra.microsoft.comwith the admin account, and manage or delete the customer account from Users.
- Re‑invite the external user
- After confirming that the external user is represented only once in the external tenant (as the intended customer/guest account), send a new invitation from the external tenant.
- The user should redeem the invitation with that same account and complete any required MFA/verification steps.
If the error persists for a specific external user, check:
- Whether their home organization has policies that block external or email‑verified users from being created.
- Whether there are conflicts with existing identities (for example, proxyAddress collisions) that prevent the external account from being provisioned correctly.
References: