A cloud-based identity and access management service for securing user authentication and resource access
The block on B2B invitations for suspicious activity and any pre-emptive review or whitelisting of tenants cannot be configured or removed using the documented self-service settings in Microsoft Entra ID. The available documentation in the provided context only covers:
- How to control B2B collaboration using cross-tenant access settings and external collaboration settings.
- How to allow or block specific organizations or domains for B2B collaboration.
- How allow/block lists and cross-tenant access settings are evaluated at invitation time.
From the context:
- Cross-tenant access settings control whether users can authenticate with external Microsoft Entra tenants and apply to inbound and outbound B2B collaboration.
- External collaboration settings control which users in the organization can send B2B invitations and allow/block specific domains.
- An allowlist or blocklist can be configured for B2B collaboration domains, but only one policy (allow or block) is supported per organization, and it is enforced at invitation time.
- Both allow/block lists and cross-tenant access settings are checked at the time of invitation.
However, the context does not provide any mechanism to:
- Remove a service-side “suspicious activity” block on invitations.
- Pre-announce or whitelist bulk B2B invitation operations.
- Adjust or bypass Microsoft’s anomaly detection thresholds for B2B invitations.
Because of this, the only supported path to remove such a block or to review/pre-approve tenants for large-scale B2B invitation activity is to work directly with Microsoft Support, as indicated by the error message itself.
For ongoing and future B2B collaboration, the following documented controls should be reviewed and configured appropriately in both tenants:
- Cross-tenant access settings
- Ensure cross-tenant access settings allow inbound and outbound B2B collaboration with the partner organizations that own the invited users.
- Use organization-specific cross-tenant access settings where needed to scope access and trust MFA/device claims.
- External collaboration settings and domain allow/block lists
- Confirm that external collaboration settings allow the appropriate internal roles/users to send invitations.
- If using an allowlist, ensure all partner domains for the migration and future onboarding are included.
- If using a blocklist, ensure partner domains are not blocked.
- Remember that:
- Only one policy (allowlist or blocklist) can be configured per tenant.
- The list does not retroactively affect already-redeemed invitations but will block pending invitations if the domain becomes blocked.
- Both allow/block lists and cross-tenant access settings are evaluated at invitation time.
These configurations help ensure that, once Microsoft removes any service-side block, large-scale but legitimate B2B invitation operations are not further restricted by tenant-level policy.
References: