Managing external identities to enable secure access for partners, customers, and other non-employees
The described behavior indicates that the tenant is being restricted by Microsoft platform-side protections and not by any configurable Entra ID policy or role setting inside the tenant. This type of restriction cannot be removed through portal configuration, Terraform changes, or standard admin actions, even with Global Administrator permissions.
To proceed, the only supported path is to engage Microsoft support so the tenant can be reviewed and, if appropriate, unblocked or adjusted by Microsoft.
Use one of these approaches:
- Open a support case from an accessible tenant
- Sign in to the Microsoft 365 or Azure portal with an account that has support entitlement (for example, an existing production tenant).
- Create a support ticket describing:
- The affected tenant ID and primary domain.
- That it is a newly created tenant for a hackathon/PoC.
- That external guest invitations are being blocked despite no conflicting policies and Global Admin rights.
- Ask specifically for the case to be routed to the appropriate Microsoft back-end/support team to review tenant-level restrictions on external collaboration/guest invitations.
- Use the phone-based support path
- Call Microsoft’s global customer service/support phone number for the region.
- Clearly state that:
- This is a commercial/organization tenant.
- The caller is a Global Administrator.
- The issue is that the new tenant appears to be restricted from inviting external guest users.
- Request that a support ticket be opened and escalated to the team that can review tenant-level restrictions.
- If no existing tenant has support, create a temporary trial tenant to open a ticket
- Create a new Microsoft 365 or Azure trial tenant (separate from the blocked one).
- From that trial tenant’s admin center, open a support ticket on behalf of the affected tenant, providing its tenant ID and details.
- Clarify in the ticket that the trial tenant is only being used to reach support and that the actual problem is with the other tenant.
Key points:
- Internal configuration (guest policies, admin roles, administrative units) is not sufficient to resolve a platform-imposed restriction.
- Only Microsoft support and back-end operations can review and adjust such restrictions.
- Because this is time-sensitive (hackathon), use phone support plus a portal ticket to accelerate routing to the correct team.
References:
- How to create, invite, and delete users
- Invite an external user
- Design Tenant Configuration
- Add external users to your organization
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Cannot be added to TEAMS CHANNELS - Microsoft Q&A
- I have no other Azure AD account, I cannot add myself as an external user from within the tenant. - Microsoft Q&A