Can no longer invite users to the Tenant

Elian Talenti 5 Reputation points
2026-05-12T16:23:35.8866667+00:00

Our tenant is unable to send guest invitations. All attempts return an "Insufficient Privileges" error.

Guest invitations were working correctly until approximately 10 users had been invited. The error began occurring immediately after that threshold, with no changes made to roles, policies, or admin settings in between.

The user account performing the invitations has not had any role or privilege changes. All external collaboration settings are correctly configured.

What we have verified

  • Role assignments are unchanged
  • External collaboration settings allow guest invitations
  • Other tenants in the organization invite users without issues
  • Issue is isolated to this specific tenant
Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-12T16:23:54.53+00:00

    The behavior matches a tenant-level restriction on guest invitations rather than a per-user role issue. Even if roles and collaboration settings look unchanged, Microsoft Entra can still block invitations when:

    1. Guest invitations are globally disabled in External collaboration settings
      In the affected tenant, verify the exact radio option under “Specify who can invite guests”:
      • If it is set to “No one in the organization can invite guest users including admins (most restrictive)”, all invitations will fail with an “Insufficient Privileges”–type error, regardless of the inviter’s role.
      • To restore functionality, change it to either:
        • “Anyone in the organization can invite guest users including guests and non-admins”, or
        • “Only users assigned to specific admin roles can invite guest users” (for tighter control), and ensure the inviter has User Administrator or Guest Inviter.
      Steps:
      1. Sign in to the Microsoft Entra admin center.
      2. Go to Entra IDExternal IdentitiesExternal collaboration settings.
      3. Under Guest invite restrictions, confirm it is not set to “No one in the organization can invite guest users including admins (most restrictive)” and adjust if necessary.
    2. Collaboration restrictions (allow/block domains) are now blocking the invited domains
      If Collaboration restrictions are configured to allow invitations only to specified domains (most restrictive) and the external domains being invited are not on that allowlist, invitations will fail. Steps:
      1. In the same External collaboration settings page, check Collaboration restrictions.
      2. If set to “Allow invitations only to the specified domains,” ensure all external domains you are inviting are listed. Otherwise, either:
        • Add the required domains to the allowlist, or
        • Temporarily switch to a more inclusive setting if that aligns with security policy.
    3. Cross-tenant/B2B restrictions blocking invitations
      Even when external collaboration settings look correct, cross-tenant access settings or other B2B controls can block invitations and surface as permission errors. For the affected tenant:
      • Review Cross-tenant access settings (inbound and outbound) to ensure B2B collaboration is allowed for the target organizations and users.
      • If SharePoint/OneDrive sharing is involved, ensure that:
        • SharePoint/OneDrive external sharing is aligned with Entra B2B settings, and
        • Integration with Microsoft Entra B2B is enabled so that Entra external collaboration and domain restrictions are respected.
    4. SharePoint/OneDrive-specific external sharing settings (if the error appears when sharing sites/files)
      SharePoint and OneDrive have their own external sharing controls and can block invitations independently of Entra settings. If the “Insufficient Privileges” error appears during site or file sharing:
      • Check that SharePoint/OneDrive external sharing is enabled and not more restrictive than Entra B2B settings.
      • If invitations are blocked with messages like “Guest invitations not allowed for your company” or “This invitation is blocked by cross-tenant access settings,” adjust:
        • External collaboration settings
        • Microsoft cloud settings
        • Cross-tenant access settings
    5. Propagation delay after configuration changes
      If any guest invite or collaboration settings were recently changed (even if reverted), there can be a 15–60 minute delay before the new permissions take effect. If changes were made while inviting the first ~10 users, the later failures may coincide with those changes taking effect.
      • After adjusting settings, wait up to an hour and test again.
    6. Confirm the inviter is actually authorized under current policy
      Even if the account’s roles have not changed, the policy about who can invite may have changed (for example, switched from “anyone” to “only specific admin roles”). In that case, the inviter must:
      • Be in a role allowed to invite guests (for example, User Administrator or Guest Inviter when that option is selected), and
      • Wait for role assignment changes to propagate if they were recently updated.

    Summary of recommended checks for this tenant:

    1. In External collaboration settings:
      • Ensure Guest invite restrictions are not set to “No one in the organization can invite guest users including admins (most restrictive).”
      • Confirm Collaboration restrictions are not blocking the domains being invited.
    2. Review Cross-tenant access settings and, if applicable, SharePoint/OneDrive external sharing and B2B integration.
    3. After any change, wait up to 60 minutes and retry invitations.

    If all of the above are correct and the issue persists only in this tenant, open a support case so Microsoft can check for tenant-specific enforcement or backend issues.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.