Managing external identities to enable secure access for partners, customers, and other non-employees
3,910 questions with Microsoft Security | Microsoft Entra | Microsoft Entra External ID tags
AAD Guest User Unable to Redeem Email Invitation
Hi there. My admin is trying to invite my corp email to another organization, but I failed to accept the invite. When I clicked on the invite link, I encountered an error as per the screenshot attached. Have tried all the suggestion able to search from…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
How to unblock My Free Entra Tenant
I need to unblock my free Entra tenant The error message is the following: "Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity. To learn more about tenant lifecycle policies, see…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Invitations for our tenant are blocked due to suspicious activity
Hello, We have invited a set of users (one by one ) or bulk invite (~16 users) but we were not aware about the invitations limit per day. Our Azure tenant is blocked from sending B2B guest invitations with the following error: "Invitations are…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Smart Lockout for Email OTP validation in Entra External ID
We are using Microsoft Entra External ID (CIAM, ciamlogin.com authority) with Email One Time Passcode as our primary authentication method in a sign-in user flow. We have observed that when a user requests multiple OTP codes in succession, all previously…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Issue with the user invitation
When I'm trying to invite a new user on the Azure portal, I get an error - insufficient privileges: <PII REMOVED> When I'm trying to invite a new user via API, I get an error - Invitations are blocked for this directory due to suspicious activity
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Azure asks for 6-digit OTP code meanwhile I don't enable it, so I'm locked out of Azure account
I configured my account signin options as in screenshot #1: Enter password, Email a code, Text a code, Send sign-in notification, Use a passkey, With my Samsung. I can log in to Microsoft account but cannot log in to Azure Portal because it asks for…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Removing an expired payment method from account
When I try to remove it on the Payment Options page, I receive this message: “We couldn’t remove your card ending in... If your payment method is associated with an Azure subscription, remove it in the Azure portal.” However, when I try to sign in to the…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID - Native Authentication - Sign Up Flow - AADSTS55200: The continuation_token is invalid
Got an error when trying to issue an access token after a user was created in Entra External ID. { "error": "invalid_request", "error_description": "AADSTS55200: The continuation_token is invalid. Trace ID:…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Issue propagating MFA context (AMR/ACR) in Azure AD B2C custom policies with multiple federated IdPs - Salesforce
We are implementing Azure AD B2C custom policies with two federated custom Identity Providers. After authentication, we need to ensure MFA context is correctly represented in the token issued by B2C and consumed by Salesforce. We want to ensure that…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
AADSTS500208 Error when user tries to login, I am using Microsoft Entra ID (Azure AD) with MSAL authentication for my web application.
I am using Microsoft Entra ID (Azure AD) with MSAL authentication for my web application. Setup I registered an application with Supported account types set to: All Microsoft account users. I am using a CIAM authority ({tenant}.ciamlogin.com). …
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Runtime Choice Between MFA Email OTP and SMS OTP in CIAM User Flows
In Microsoft Entra External ID (CIAM), I see that I can configure email + password as the first factor and enable both email OTP and SMS OTP as second‑factor MFA methods. However, in built‑in user flows, users don’t appear to get a choice screen at…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Okta as OIDC based external identity provider in Microsoft Entra External ID: provider not appearing on login screen
Environment / context Microsoft Entra External ID (External ID) as the CIAM provider for our tenant Okta configured as an OpenID Connect (OIDC) external identity provider in the External ID tenant Created an External ID user flow and added Okta as a…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Change owner of External account
There is external account created in Azure Entra id. now i want to change that external account owner.
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID: Federated email claim not present in OnAttributeCollectionStart/Submit payload
We are using a federated OIDC identity provider with Microsoft Entra External ID. The email claim is successful: returned from the IdP mapped via OIDC claim mapping (email -> email) correctly prefilled in the UI during sign-up However, email is…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.
We have been creating an application and inviting a pilot set of users (one by one) using invitations for months without any issues. Today, were trying to add in around 800 users so that they could access our application. After adding in users (98…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Language override in SignIn User Flow
I'm trying to override certain (error) messages in my SignIn User Flow in Entra External ID and it looks like language override is the only way for me to do that. I have two issues while doing that. After re-uploading the override JSON some values…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID custom identity sign in with login_hint results in AADSTS165000 Token was not provided
I have an Entra External ID external tenant (CIAM) with a custom identity provider configured using OIDC to an Auth0 identity provider on domain mydomain.uk.auth0.com. To isolate myself from any issues with my own code I'm using the sample code…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Unable to delete External Configuration Tenant applyarc.onmicrosoft.com due to UserCountExceeded error
Hi there, I'm trying to delete an External Configuration Tenant (Microsoft Entra External ID) called applyarc.onmicrosoft.com within my resource group rg - applyarc - prod. When I select the tenant and attempt to delete it through the Azure portal, the…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Error message: interaction_required: AADSTS5000225 when logging into my Azure account
Sign-in failed Error code: interaction_required Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity. To learn more about tenant lifecycle policies, see https://aka.ms/TenantLifecycle
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.
https://learn.microsoft.com/en-us/answers/questions/5876685/invitations-are-blocked-for-this-directory-due-to Getting the same tenant wide block as above when bulk inviting users to a new tenant.
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees