Managing external identities to enable secure access for partners, customers, and other non-employees
The block on B2B invitations due to suspicious activity cannot be removed through configuration; it requires direct intervention from Microsoft support.
Because the tenant is seeing a hard block message (HTTP 403 with “Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.”), the only viable path is:
- Open a support ticket from the affected tenant
- Sign in to the Azure portal with a Global Administrator account for the blocked tenant.
- Go to Help + support and create a new support request.
- Choose the appropriate subscription/tenant and select a problem type related to Microsoft Entra ID / External Identities / B2B collaboration.
- In the description, include:
- Exact error text and HTTP status (403 Forbidden).
- Timeframe when the block started.
- Approximate number of invitations sent before the block.
- Sample failed invitation request IDs and correlation IDs from the error responses.
- Tenant ID and contact details for the Global Administrator.
- Work with the Microsoft support / Data Protection team
- The case will typically be escalated to the internal Data Protection or identity protection team (similar to how tenant lockout and MFA-reset issues are handled in other scenarios in the provided context).
- That team will review the suspicious-activity flag on the tenant and, if appropriate, remove or relax the block on B2B invitations.
- After unblocking
- Resume sending invitations in smaller, controlled batches to avoid triggering automated protections again.
- Ensure B2B collaboration settings, cross-tenant access settings, and any allow/block domain lists are configured as intended so that normal policy-based blocks do not interfere with invitations. Relevant configuration areas include:
- External collaboration settings for B2B in Microsoft Entra ID.
- Cross-tenant access settings for B2B collaboration.
- Any allow/block domain lists for invitations.
The unblock itself cannot be performed by tenant administrators; only Microsoft support can clear this specific suspicious-activity block.
References: