Unable to send B2B guest invitations from Microsoft Entra

Lucy Scott 20 Reputation points
2026-03-31T14:46:38.52+00:00

We are currently unable to send B2B guest invitations from our Microsoft Entra tenant. All attempts to invite external users—both via the Entra Admin Portal and Microsoft Graph (/invitations)—fail immediately with the error: Portal GUI “Insufficient privileges to complete the operation.” or GraphAPI "Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help." No invitation email is sent and no guest user is created.

This is not a permissions or configuration issue. The action is being performed by a Global Administrator, required Graph permissions (e.g. User.Invite.All, Directory.ReadWrite.All) are granted with admin consent, and external collaboration settings are correctly configured to allow invitations. We have also confirmed that Conditional Access policies, domain restrictions, and tenant settings are not blocking the process. The issue persists across multiple admin accounts and for all external domains tested.

Given the above, this appears to be a tenant-level restriction or backend block applied by Microsoft (e.g. security, abuse, or anomaly detection). This issue is currently blocking onboarding of external users into our application. We request that you investigate whether any service-level restrictions are applied to the tenant and remove any blocks preventing B2B invitations from functioning normally.

I can provide details of our tenant and business justification for lifting the block in a DM as requested.

Many thanks

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
Thanmayi Godithi 11,905 Reputation points Microsoft External Staff Moderator
2026-03-31T17:05:10.36+00:00

Hi Lucy Scott,

The behavior described matches a tenant-level restriction that cannot be resolved through local configuration, roles, or Graph permissions. The error message from Microsoft Graph explicitly states that invitations are blocked for the directory due to suspicious activity and instructs to contact Microsoft support. There is no configuration change in Microsoft Entra ID that will clear this condition from the admin side.

We need to send the details asked via Private chat to Data Protection team to resolve the issue from backend.

If the resolution was helpful, kindly take a moment to click on 210246-screenshot-2021-12-10-121802.pngand click on Yes for was this answer helpful. And, if you have any further query do let us know.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.