B2B guest sign-in blocked with error 530035 — "Invitations blocked due to suspicious activity" on tenant PII

Dylan Levsey 0 Reputation points
2026-04-01T15:28:09.9533333+00:00

Issue: Microsoft Entra ID B2B guest users from one external domain are unable to access the application and receive error 530035. Other guest domains appear to work normally. Please review whether invitation access for this tenant or domain is blocked for suspicious activity and advise on next steps.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-01T15:28:32.86+00:00

    The described behavior matches a tenant‑level protection block on B2B invitations/sign‑ins due to detected suspicious or risky activity. This block cannot be removed or bypassed through configuration changes in Microsoft Entra ID; it must be handled by Microsoft support and/or the internal Data Protection/Identity Protection teams.

    From the provided details:

    • External collaboration settings, domain allow/block lists, app role assignments, and group memberships are already correctly configured.
    • Error text from Microsoft Graph (Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help.) is a hard indicator that the directory’s invitation capability has been restricted for security reasons.
    • The fact that Gmail guests work while transferonline.com guests fail is consistent with risk‑based or reputation‑based protections that can selectively affect certain identities or domains.

    Given this, the only supported path is escalation through Microsoft support from within the affected tenant:

    1. Open a support ticket from waltercole1997gmail789.onmicrosoft.com (the affected tenant), selecting Microsoft Entra ID → B2B/External collaboration / Sign‑in issues.
    2. Include the tenant ID, app ID, correlation ID, and the exact Graph error message indicating invitations are blocked due to suspicious activity.
    3. Ask support to engage the Data Protection / Identity Protection back‑end team to review and remove the “suspicious activity” block on B2B invitations for the tenant, if appropriate.
    4. Once the Data Protection team has completed their investigation and unblocked the tenant, B2B invitations and sign‑ins for the affected domain should start working again without further configuration changes.

    This pattern is similar to other tenant lockout scenarios where only Microsoft support and the Data Protection team can restore access; it cannot be resolved solely by tenant administrators.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.