Guest invitations are blocked due to suspicious activity in Microsoft Entra ID

MICHAŁ MATHIAK 0 Reputation points
2026-08-25T12:28:20.7766667+00:00

In our tenant, guest invitations in Microsoft Entra ID B2B collaboration are blocked. Users/admins receive the message: "Invitations to this directory have been blocked due to suspicious activity. Contact Microsoft support for assistance."

Expected behavior: Guest invitations should be sent successfully.

Actual behavior: Invitation flow is blocked before the guest can be invited.

Tenant ID: e36ef28c-086c-4117-92c0-e36e1955feb9

Workload / feature: Microsoft Entra ID, External Identities, B2B collaboration, guest invitations

Troubleshooting already completed: We reviewed recent audit activity related to external user invitations. No recent invitation audit events were returned that could be correlated with a specific failed invitation attempt. The issue appears consistent with a service-side protective block related to suspicious activity.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Bence Weiszmann 1,395 Reputation points
    2026-08-25T19:40:50.25+00:00

    Dear @MICHAŁ MATHIAK

    The error suggests that Microsoft Entra has applied a security restriction to guest invitations in the tenant. This type of restriction is handled on Microsoft’s side as part of their protection against suspicious activity, so it cannot normally be removed by changing the tenant’s B2B or External Collaboration settings.

    The recommended next step is to contact Microsoft Support and ask them to review the restriction on the tenant.

    A Global Administrator can open a support request from the Microsoft 365 admin center:

    Sign in with a Global Administrator account.

    • Open https://admin.microsoft.com.
    • Go to SupportHelp & support.
    • Describe the issue, for example: "Microsoft Entra B2B guest invitations are blocked due to suspicious activity."
    • Select the option to Contact Support / create a support request.
    • When submitting the case, provide the tenant ID, the exact error message, and the error code returned by Microsoft Graph, if available.
    • Explain that the tenant has experienced repeated invitation and deletion activity involving test accounts, but that this activity was intentional and related to testing or automation.
    • Ask Microsoft to review whether a tenant-level security restriction has been applied and, if this is a false positive, to remove the restriction.

    It is worth explicitly asking Microsoft to route the case to the team responsible for Microsoft Entra External ID / B2B invitation security or abuse protection, as this does not appear to be a standard configuration issue.

    While waiting for Microsoft to investigate, I would also verify the relevant Entra configuration. In particular, check the External collaboration settings to make sure guest invitations are permitted, the appropriate administrator roles are allowed to invite guests, and there are no unintended domain restrictions.

    If the tenant uses B2B collaboration with other Entra tenants, the Cross-tenant access settings should also be reviewed to make sure they are not introducing an additional restriction.

    Once Microsoft removes the security restriction, the normal guest invitation process should become available again.

    If there are also broader problems accessing or administering the tenant, mention those in the support case as well, since Microsoft may need to involve a separate tenant recovery or security team.


    If this answers your query, please click Accept Answer and Upvote if you found it helpful. If you have any further questions, feel free to let us know.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.