A cloud-based identity and access management service for securing user authentication and resource access
Hi Samuel,
The good news, such as it is: this is a recognisable pattern rather than something specific to your directory, and the trigger in every case I have seen is the same, a burst of invitations in a short window. Yours was a bulk import, which is the most concentrated form of it.
Two things worth knowing before you open the case, because neither is visible from your own thread.
First, how long this can last. Another user posted last week with eleven invitations sent in a single day, three months ago, and the block is still in place today. He has since verified the Guest Inviter role and the external collaboration settings directly, and neither changed anything. So this does not appear to be a throttle that releases itself, and I would not plan around it clearing on its own: https://learn.microsoft.com/en-us/answers/questions/6005246/error-when-inviting-external-users-in-ms-azure-use
Second, and this is the part that may save you time: you are seeing the real error message because you went through the Graph API. The same block reported from the portal shows up as a generic "User invitation failed, Insufficient privileges to complete the operation", which sends people off checking role assignments for days. Paul Stirpe hit that version back in July and only worked out what was happening by reproducing it deliberately: https://learn.microsoft.com/en-us/answers/questions/5960612/why-is-my-tenant-suddenly-not-allowing-me-to-invit
Keep that Graph error payload exactly as you posted it, request-id included, and open the case with it. A message that explicitly says invitations are blocked for the directory and names support as the route is much harder to close with a documentation link than a permissions error is, and the request-id lets them find the event on their side rather than asking you to reproduce it.
One thing I would add to the case, since you mentioned this directory is already serving other production environments: say that explicitly and say what else depends on it. A block on a directory that is only used for one project reads very differently from one sitting on shared production infrastructure, and it should affect how the case is prioritised.
If you get a resolution, it would be genuinely useful to post what worked here. Three separate people have run into this in the past week and none of the threads has a documented fix yet.