Microsoft Entra B2B guest invitations blocked for tenant due to suspicious activity

2026-09-11T20:10:43.84+00:00

Issue

Our Microsoft Entra tenant is currently unable to send any new B2B guest invitations.

The issue is tenant-wide and is not limited to SharePoint or to a specific external recipient. We can reproduce the problem when attempting to invite external users directly from the Microsoft Entra admin center, through SharePoint external sharing, Microsoft Teams, Power Automate, and Microsoft Graph.

We previously opened a Microsoft 365 support case regarding this issue. Microsoft Support investigated the problem and concluded that it is not caused by SharePoint Online configuration. They identified it as a tenant-level Microsoft Entra B2B invitation restriction that requires investigation by the Microsoft Entra Identity/B2B support team.

Unfortunately, our current support agreement does not allow us to create the required technical Microsoft Entra support request, leaving us without a direct support path to have the restriction reviewed.

Error message

When attempting to invite a new guest directly from Microsoft Entra, we receive:

Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.

The same underlying error is returned by SharePoint when attempting to share content with a new external user:

At least one invitation failed. Error: ResponseStatusNotOK, message: Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.

The SharePoint SP.Web.ShareObject API returns StatusCode -40.

The restriction is also reproducible through Microsoft Graph using an account with the required permissions, including consent for User.Invite.All.

Impact

This restriction prevents us from onboarding legitimate external users into the tenant.

Because new guest invitations are blocked at directory level, legitimate onboarding involving SharePoint, Teams, and other Microsoft 365 services cannot be completed.

What we have verified

We have performed the following troubleshooting:

The issue affects multiple external email addresses and is not specific to one recipient.

New guests cannot be invited directly from Microsoft Entra admin center > Users > New user > Invite external user.

The same failure occurs through SharePoint external sharing.

The issue is also reproducible through Microsoft Teams and Power Automate.

Microsoft Graph invitation attempts fail with the same directory-level restriction.

The required Microsoft Graph permissions for guest invitations have been granted and consented.

Microsoft Entra External Collaboration configuration allows invitations:

allowInvitesFrom: everyone

Default Cross-tenant access settings allow B2B collaboration for:

  `AllUsers`
  
     `AllApplications`
     
     SharePoint tenant external sharing is enabled:
     
        `sharingCapability: externalUserAndGuestSharing`
        
           `sharingDomainRestrictionMode: none`
           
           No allowed-domain or blocked-domain restriction is configured.
           
           The affected SharePoint site allows external user sharing.
           
           There are no Conditional Access policies configured that explain the restriction.
           
           We reviewed Microsoft Entra Audit Logs for the failed attempts but could not identify a corresponding guest invitation audit event.
           
           The issue is consistently reproducible.
           

Microsoft 365 Support has already reviewed these findings and concluded that the problem is a tenant-level Microsoft Entra B2B invitation restriction, rather than a SharePoint configuration issue.

Request

Could someone from Microsoft please advise how this tenant-level B2B invitation restriction can be escalated for review?

The error explicitly states that the directory has been blocked due to suspicious activity and instructs us to contact Microsoft Support. However, our current support agreement does not allow us to open the required technical Microsoft Entra support case.

We need Microsoft to review the tenant-level B2B restriction and, if appropriate, remove the block or advise what verification or remediation is required from our side.

We can provide the Tenant ID, previous Microsoft support case number, screenshots, timestamps, and other diagnostic information privately to Microsoft if required.

This is currently blocking legitimate Microsoft Entra B2B guest onboarding across the tenant.

Microsoft Security | Microsoft Entra | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.