Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help

Oleg Gliznutsa 20 Reputation points
2026-04-20T09:55:46.53+00:00

Hello Microsoft Support,

Affected tenant ID (Dev): <PIIREMOVED>

Secondary tenant ID (Prod, not currently blocked but we'd like to preempt the same issue): Pii removed

We are experiencing a critical issue with our Microsoft Entra ID tenant. All guest invitations in the Dev tenant are failing with the following error:

Context of Issue:

We are now changing the way we store users in our applications, we have provisioned two new tenants (Dev and Prod) and are migrating our legitimate existing user base from the parent organization's tenant into these new tenants. All users being invited are real users - this is a one-time migration operation, not spam or abuse.

"error": {
    "code": "Forbidden",

    "message": "Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.",

}

Request:

  1. Please review and remove the "suspicious activity" block on tenant pii removed
  2. Please preemptively review tenant pii removed (Prod) to ensure the same block does not trigger when we perform the production migration in the coming weeks.
  3. Please confirm the guidelines and best practices we should follow to avoid hitting this block, both for: a) The remaining user migration (1.5k more users to invite) b) Future B2B customer onboarding scenarios, where we expect to onboard external partners/customers in batches that may exceed the standard anomaly detection thresholds. We would like to understand how to pre-announce or whitelist such operations with Microsoft in advance rather than hitting the block reactively every time. Thank you for your assistance.
Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-20T09:56:05.2633333+00:00

    The block on B2B invitations for suspicious activity and any pre-emptive review or whitelisting of tenants cannot be configured or removed using the documented self-service settings in Microsoft Entra ID. The available documentation in the provided context only covers:

    • How to control B2B collaboration using cross-tenant access settings and external collaboration settings.
    • How to allow or block specific organizations or domains for B2B collaboration.
    • How allow/block lists and cross-tenant access settings are evaluated at invitation time.

    From the context:

    • Cross-tenant access settings control whether users can authenticate with external Microsoft Entra tenants and apply to inbound and outbound B2B collaboration.
    • External collaboration settings control which users in the organization can send B2B invitations and allow/block specific domains.
    • An allowlist or blocklist can be configured for B2B collaboration domains, but only one policy (allow or block) is supported per organization, and it is enforced at invitation time.
    • Both allow/block lists and cross-tenant access settings are checked at the time of invitation.

    However, the context does not provide any mechanism to:

    • Remove a service-side “suspicious activity” block on invitations.
    • Pre-announce or whitelist bulk B2B invitation operations.
    • Adjust or bypass Microsoft’s anomaly detection thresholds for B2B invitations.

    Because of this, the only supported path to remove such a block or to review/pre-approve tenants for large-scale B2B invitation activity is to work directly with Microsoft Support, as indicated by the error message itself.

    For ongoing and future B2B collaboration, the following documented controls should be reviewed and configured appropriately in both tenants:

    1. Cross-tenant access settings
      • Ensure cross-tenant access settings allow inbound and outbound B2B collaboration with the partner organizations that own the invited users.
      • Use organization-specific cross-tenant access settings where needed to scope access and trust MFA/device claims.
    2. External collaboration settings and domain allow/block lists
      • Confirm that external collaboration settings allow the appropriate internal roles/users to send invitations.
      • If using an allowlist, ensure all partner domains for the migration and future onboarding are included.
      • If using a blocklist, ensure partner domains are not blocked.
      • Remember that:
        • Only one policy (allowlist or blocklist) can be configured per tenant.
        • The list does not retroactively affect already-redeemed invitations but will block pending invitations if the domain becomes blocked.
        • Both allow/block lists and cross-tenant access settings are evaluated at invitation time.

    These configurations help ensure that, once Microsoft removes any service-side block, large-scale but legitimate B2B invitation operations are not further restricted by tenant-level policy.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.