driveItem invite fails with 400 sharingFailed for every new external recipient since the Entra B2B rollout — SharePoint rejects before the Invitation Manager is called

Paul Mallaband 0 Reputation points
2026-10-09T09:39:14.4733333+00:00

Since the SharePoint/OneDrive transition to Entra B2B (MC1243549, rollout completed

17 July 2026), POST /drives/{drive-id}/items/{item-id}/invite fails for any external

recipient who is not already a guest in the resource tenant.

We have had no successful creation of a new external guest through this API since

8 July 2026 — over 1,200 failures between 24 August and 20 September 2026, across every

customer tenant we integrate with.

Setup. Delegated authentication. The signed-in user is a member of the resource tenant

and owns the OneDrive content being shared. (Not app-only, so the documented "new guests

can't be invited using app-only access" restriction does not apply.)

Request:


POST https://graph.microsoft.com/v1.0/drives/{drive-id}/items/{item-id}/invite

{

  "requireSignIn": true,

  "sendInvitation": false,

  "roles": ["write"],

  "recipients": [{ "email": "<external-recipient>" }]

}

Result:

| Recipient already a redeemed guest in the tenant? | Response |

|---|---|

| Yes | 200 OK |

| No | 400 sharingFailed |


{

  "error": {

    "code": "sharingFailed",

    "message": "There was a problem sharing, please try again later.",

    "innerError": {

      "date": "2026-09-16T13:41:41",

      "request-id": "3165e03a-6ef2-4662-97c6-84109e8ea333",

      "client-request-id": "3165e03a-6ef2-4662-97c6-84109e8ea333"

    }

  }

}

Further failed requests for log correlation:

  • 2026-09-06T11:13:00.767Z — request-id 1b4ded1a-2e88-43a4-969b-660df9087c95 — SPLogId 8c8938a2-1010-3001-304b-f37e9767106a
  • 2026-09-14T15:53:43.242Z — request-id b0d4d82e-06a6-4476-b08b-0959bbac17ae — SPLogId ca2c3ba2-6047-3001-304b-feaad2d2b458
  • 2026-09-16T13:41:41.644Z — request-id 3165e03a-6ef2-4662-97c6-84109e8ea333 — SPLogId 07ca3ba2-f0c0-3001-1afb-e6f0480d58e0

What we have ruled out. Testing on 21–22 September 2026 in our own tenant, with

SharePoint and Entra external sharing settings fully open:

  • Not the sendInvitation value — fails identically with true and false.
  • Not our app registration, scopes or SDK — fails identically from Microsoft Graph Explorer.
  • Not tenant sharing configuration — reproduced with everything open, no domain restrictions, sites active and unlocked.
  • Not an Entra guest-invite policy refusal — **the Entra audit log shows no "Invite external user" event for these requests at all.** SharePoint appears to reject the request before the Entra B2B Invitation Manager is invoked.

What works on the same tenant, same folder, same recipient:

  • The OneDrive web UI — succeeds, and the Entra guest is created.
  • SharePoint REST SP.Web.ShareObject, called from a third-party app with a delegated token — succeeds, and the Entra guest is created. This is the method the web UI itself uses.

So the capability is present and the tenant permits it; it is specifically the Graph

invite path that fails.

Expected behaviour. MC1243549, updated 2 October 2026, states that for new external

users "a guest account will be automatically created via the Entra B2B Invitation Manager

and authentication will use Entra B2B". That is what we observe through the UI and through

ShareObject, and not what we observe through Graph.

Questions:

  1. Is driveItem: invite expected to provision a new external recipient as a B2B guest, as MC1243549 describes and as the UI does? If so, the 400 sharingFailed with no corresponding Entra invitation event looks like a defect in the SharePoint-side handling of this operation.
  2. If it is not expected to, what is the supported route for a delegated third-party application to share with a first-time external recipient? We have moved to SP.Web.ShareObject as a workaround, but would rather depend on a documented Graph path.

Happy to supply further request IDs, tenant IDs by private channel, or run controlled

tests.

Microsoft Security | Microsoft Graph
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.