B2B guest invitations blocked tenant-wide due to suspicious activity — requesting review and removal of the block (tenant 5c795918-7117-4dae-b2a6-2b758ba62b55)

Paul Cirstean 0 Reputation points
2026-08-21T08:51:53.1866667+00:00

Requesting review and removal of a tenant-level block on outbound B2B invitations.

TENANT Tenant ID: 5c795918-7117-4dae-b2a6-2b758ba62b55 Domain: tssailab.onmicrosoft.com Type: Workforce (AAD), created 2026-07-06, country NL

SYMPTOM Every invitation attempt returns HTTP 403: code : Forbidden message : "Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help." request-id : f920bfd8-19f2-4ae1-91d1-93110cee5b08 client-request-id: f920bfd8-19f2-4ae1-91d1-93110cee5b08 timestamp : 2026-08-20T14:58:41Z

Reproduced against Microsoft Graph POST /v1.0/invitations as Global Administrator, and it also fails from the Entra portal UI. The block began on or about 2026-08-05.

THIS IS NOT A CONFIGURATION ISSUE - ALL SURFACES VERIFIED PERMISSIVE - authorizationPolicy allowInvitesFrom = "everyone" - crossTenantAccessPolicy default b2bCollaborationOutbound = allowed for AllUsers / AllApplications (isServiceDefault = true) - No B2B allow/deny list configured (legacy/policies returns empty)

CAUSE - IDENTIFIED ON OUR SIDE This tenant is the development directory for an internal line-of-business application. On 2026-07-24 a defect in our automated test suite caused it to run against this live tenant with real application credentials instead of a test double. It created nine B2B invitations to addresses at the reserved domains t.example and ext.example (RFC 2606). Because those domains cannot receive mail, none could ever be redeemed and they sat in the directory as PendingAcceptance. We believe that pattern - automated invitations to undeliverable addresses from a tenant only weeks old, with no prior invitation history - is what triggered abuse detection.

REMEDIATION ALREADY COMPLETED

  1. The test defect is fixed. The test host now blanks all provisioner credentials, so the test suite cannot reach Microsoft Graph under any configuration. Fixed 2026-07-24.
  2. All nine undeliverable guest objects were deleted on 2026-08-20. The directory now holds three accounts: one member and two redeemed guests.

BUSINESS JUSTIFICATION AND EXPECTED USAGE Internal line-of-business application for colleagues across business units of one company. Low volume - single figures per month - to named colleagues at corporate email domains. No bulk invitations, no consumer domains, no marketing or outreach.

We have not retried invitations since discovering the block and will not retry until the block is confirmed lifted. I can provide the Global Administrator email address on request. Grateful for an internal review.

Deliberate choices in that text: it opens by naming the ask as escalation rather than troubleshooting, it kills the config-deflection path in the third block, and it names your own defect as the cause. A reviewer approving a "we fixed our bug and cleaned up" case is taking far less risk than one approving "we did nothing wrong.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.