3,910 questions with Microsoft Security | Microsoft Entra | Microsoft Entra External ID tags

Sort by: Updated
1 answer

AAD Guest User Unable to Redeem Email Invitation

Hi there. My admin is trying to invite my corp email to another organization, but I failed to accept the invite. When I clicked on the invite link, I encountered an error as per the screenshot attached. Have tried all the suggestion able to search from…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-05T04:17:02.3333333+00:00
Eric Chai 0 Reputation points
commented 2026-05-06T08:20:52.3733333+00:00
Shubham Sharma 14,500 Reputation points Microsoft External Staff Moderator
1 answer

How to unblock My Free Entra Tenant

I need to unblock my free Entra tenant The error message is the following: "Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity. To learn more about tenant lifecycle policies, see…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-04-15T23:42:00.4966667+00:00
David Savage 0 Reputation points
edited the question 2026-05-06T08:18:45.61+00:00
Alexandra Tanasescu 0 Reputation points Moderator
1 answer

Invitations for our tenant are blocked due to suspicious activity

Hello, We have invited a set of users (one by one ) or bulk invite (~16 users) but we were not aware about the invitations limit per day. Our Azure tenant is blocked from sending B2B guest invitations with the following error: "Invitations are…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-06T07:27:38.7633333+00:00
Adrian-Ionut Buse 0 Reputation points
commented 2026-05-06T07:48:08.73+00:00
Adrian-Ionut Buse 0 Reputation points
1 answer

Smart Lockout for Email OTP validation in Entra External ID

We are using Microsoft Entra External ID (CIAM, ciamlogin.com authority) with Email One Time Passcode as our primary authentication method in a sign-in user flow. We have observed that when a user requests multiple OTP codes in succession, all previously…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-06T06:32:38.8733333+00:00
Ulrik Ejdesgaard 0 Reputation points
commented 2026-05-06T07:22:24.4833333+00:00
Shubham Sharma 14,500 Reputation points Microsoft External Staff Moderator
1 answer

Issue with the user invitation

When I'm trying to invite a new user on the Azure portal, I get an error - insufficient privileges: <PII REMOVED> When I'm trying to invite a new user via API, I get an error - Invitations are blocked for this directory due to suspicious activity

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-04-24T16:14:19.7933333+00:00
Alexander Gershkovich 0 Reputation points
answered 2026-05-06T05:51:00.4666667+00:00
Shubham Sharma 14,500 Reputation points Microsoft External Staff Moderator
1 answer

Azure asks for 6-digit OTP code meanwhile I don't enable it, so I'm locked out of Azure account

I configured my account signin options as in screenshot #1: Enter password, Email a code, Text a code, Send sign-in notification, Use a passkey, With my Samsung. I can log in to Microsoft account but cannot log in to Azure Portal because it asks for…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-03-03T06:39:54.0633333+00:00
Rein Chau 0 Reputation points
answered 2026-05-06T05:45:13.8166667+00:00
Shubham Sharma 14,500 Reputation points Microsoft External Staff Moderator
1 answer

Removing an expired payment method from account

When I try to remove it on the Payment Options page, I receive this message: “We couldn’t remove your card ending in... If your payment method is associated with an Azure subscription, remove it in the Azure portal.” However, when I try to sign in to the…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-05T18:20:59.1633333+00:00
Mario Marinus 0 Reputation points
commented 2026-05-06T01:04:34.9733333+00:00
Shubham Sharma 14,500 Reputation points Microsoft External Staff Moderator
1 answer

Entra External ID - Native Authentication - Sign Up Flow - AADSTS55200: The continuation_token is invalid

Got an error when trying to issue an access token after a user was created in Entra External ID. { "error": "invalid_request", "error_description": "AADSTS55200: The continuation_token is invalid. Trace ID:…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-05T16:49:30.3+00:00
HA 0 Reputation points
commented 2026-05-06T00:37:17.97+00:00
Sridevi Machavarapu 29,290 Reputation points Microsoft External Staff Moderator
1 answer

Issue propagating MFA context (AMR/ACR) in Azure AD B2C custom policies with multiple federated IdPs - Salesforce

We are implementing Azure AD B2C custom policies with two federated custom Identity Providers. After authentication, we need to ensure MFA context is correctly represented in the token issued by B2C and consumed by Salesforce. We want to ensure that…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-04-28T19:38:48.4133333+00:00
Patnala, Ramesh (Consultant) 0 Reputation points
commented 2026-05-05T23:46:18.96+00:00
Sridevi Machavarapu 29,290 Reputation points Microsoft External Staff Moderator
1 answer

AADSTS500208 Error when user tries to login, I am using Microsoft Entra ID (Azure AD) with MSAL authentication for my web application.

I am using Microsoft Entra ID (Azure AD) with MSAL authentication for my web application. Setup I registered an application with Supported account types set to: All Microsoft account users. I am using a CIAM authority ({tenant}.ciamlogin.com). …

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-04T10:38:30.41+00:00
Rishav Mahajan 0 Reputation points
edited the question 2026-05-05T19:12:28.56+00:00
VEMULA SRISAI 12,615 Reputation points Microsoft External Staff Moderator
1 answer

Runtime Choice Between MFA Email OTP and SMS OTP in CIAM User Flows

In Microsoft Entra External ID (CIAM), I see that I can configure email + password as the first factor and enable both email OTP and SMS OTP as second‑factor MFA methods. However, in built‑in user flows, users don’t appear to get a choice screen at…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-04T15:50:29.9666667+00:00
Vaibhav Beohar 0 Reputation points
commented 2026-05-05T13:59:59.5166667+00:00
VEMULA SRISAI 12,615 Reputation points Microsoft External Staff Moderator
1 answer

Okta as OIDC based external identity provider in Microsoft Entra External ID: provider not appearing on login screen

Environment / context Microsoft Entra External ID (External ID) as the CIAM provider for our tenant Okta configured as an OpenID Connect (OIDC) external identity provider in the External ID tenant Created an External ID user flow and added Okta as a…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-03T09:59:03.9866667+00:00
Anuj Sharma 0 Reputation points
commented 2026-05-05T10:09:49.78+00:00
Rukmini 39,110 Reputation points Microsoft External Staff Moderator
1 answer

Change owner of External account

There is external account created in Azure Entra id. now i want to change that external account owner.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-04-30T11:01:28.8833333+00:00
Balwant Jadhav (Admin Cloud) 0 Reputation points
commented 2026-05-05T07:40:08.48+00:00
Shubham Sharma 14,500 Reputation points Microsoft External Staff Moderator
0 answers

Entra External ID: Federated email claim not present in OnAttributeCollectionStart/Submit payload

We are using a federated OIDC identity provider with Microsoft Entra External ID. The email claim is successful: returned from the IdP mapped via OIDC claim mapping (email -> email) correctly prefilled in the UI during sign-up However, email is…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-04-17T14:05:29.75+00:00
Yuliia Bashko 80 Reputation points
commented 2026-05-05T07:34:48.3933333+00:00
Shubham Sharma 14,500 Reputation points Microsoft External Staff Moderator
1 answer

Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.

We have been creating an application and inviting a pilot set of users (one by one) using invitations for months without any issues. Today, were trying to add in around 800 users so that they could access our application. After adding in users (98…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-04-30T11:57:11.3333333+00:00
Manek Ravi 5 Reputation points
answered 2026-05-05T04:01:38.0366667+00:00
Shubham Sharma 14,500 Reputation points Microsoft External Staff Moderator
0 answers

Language override in SignIn User Flow

I'm trying to override certain (error) messages in my SignIn User Flow in Entra External ID and it looks like language override is the only way for me to do that. I have two issues while doing that. After re-uploading the override JSON some values…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2025-10-16T12:05:43.4566667+00:00
Timo Gosemann 15 Reputation points
commented 2026-05-04T16:49:58.79+00:00
Scott Dougherty 20 Reputation points
2 answers One of the answers was accepted by the question author.

Entra External ID custom identity sign in with login_hint results in AADSTS165000 Token was not provided

I have an Entra External ID external tenant (CIAM) with a custom identity provider configured using OIDC to an Auth0 identity provider on domain mydomain.uk.auth0.com. To isolate myself from any issues with my own code I'm using the sample code…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-04-16T15:27:27.3933333+00:00
Philip Hendry 110 Reputation points
accepted 2026-05-04T14:47:51.3733333+00:00
Philip Hendry 110 Reputation points
1 answer

Unable to delete External Configuration Tenant applyarc.onmicrosoft.com due to UserCountExceeded error

Hi there, I'm trying to delete an External Configuration Tenant (Microsoft Entra External ID) called applyarc.onmicrosoft.com within my resource group rg - applyarc - prod. When I select the tenant and attempt to delete it through the Azure portal, the…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2025-10-30T20:49:19.1833333+00:00
A.G 0 Reputation points
commented 2026-05-04T12:27:25.4733333+00:00
Peter Davies 0 Reputation points
1 answer

Error message: interaction_required: AADSTS5000225 when logging into my Azure account

Sign-in failed Error code: interaction_required Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity. To learn more about tenant lifecycle policies, see https://aka.ms/TenantLifecycle

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-02-20T17:48:32.6233333+00:00
Michael li 20 Reputation points
commented 2026-05-04T09:46:08.6466667+00:00
Tristan Matheson 0 Reputation points
1 answer One of the answers was accepted by the question author.

Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.

https://learn.microsoft.com/en-us/answers/questions/5876685/invitations-are-blocked-for-this-directory-due-to Getting the same tenant wide block as above when bulk inviting users to a new tenant.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-01T18:29:50.3266667+00:00
Omar Imami 20 Reputation points
accepted 2026-05-01T18:30:35.9833333+00:00
Omar Imami 20 Reputation points