A cloud-based identity and access management service for securing user authentication and resource access
This issue cannot be resolved through configuration changes in the tenant. The behavior indicates a service-side protection/block that must be reviewed and removed by Microsoft support.
Required next step:
- Open a critical support ticket with Microsoft (Azure/Microsoft 365 support) from the affected tenant and provide:
- Tenant ID
- Error message: “Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.”
- Error code: 403 Forbidden
- Request ID and timestamp
- The case will be escalated to the appropriate Microsoft internal/Data Protection or service team to investigate and remove the block on B2B invitations.
Configuration checks already performed (external collaboration settings, domain restrictions, Graph vs portal) are sufficient; no additional portal-side settings will clear this block.
Once support removes the block, B2B invitations will resume working. For ongoing B2B collaboration, ensure:
- External collaboration settings and cross-tenant access settings are configured according to business needs.
- Any allow/block domain lists and cross-tenant access policies are reviewed, as both are evaluated at invitation time.
Relevant operational points from the documentation:
- External collaboration settings control who can invite guests, domain restrictions, and guest visibility.
- Allow/block lists and cross-tenant access settings are both checked at the time of invitation.
- Cross-tenant access settings are used to manage B2B collaboration with other Microsoft Entra organizations; external collaboration settings are used for non-managed identities.
References:
- Troubleshoot common issues with Microsoft Entra B2B collaboration
- Allow or block B2B collaboration with organizations
- Manage cross-tenant access settings for B2B collaboration
- Overview: Cross-tenant access with Microsoft Entra External ID
- Cross-cloud collaboration with Microsoft 365
- Error: ResponseStatusNotOK when sharing a SharePoint or OneDrive site
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Cannot be added to TEAMS CHANNELS - Microsoft Q&A
- Hello Team, I am using a Microsoft 365 Developer tenant and testing Graph API for automatic meeting scheduling. The issue I am facing: API Endpoint: POST https://graph.microsoft.com/v1.0/me/events?sendUpdates=all Response: 201 Created (event successfu - Microsoft Q&A
- Tried loggin into Teams and Outlook and got this message on outlook, and unable to log into teams. - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A