ユーザーがベスト プラクティスに従って Azure のデプロイを最適化するための、パーソナル設定が行われた Azure のレコメンデーション エンジン。
Hello**DICKEY**
Inviting a guest is controlled by your tenant’s External collaboration settings (External Identities). Those settings define who is allowed to send guest invitations (everyone, only specific admin roles, or nobody). Microsoft explicitly documents that external collaboration settings are where you configure who can invite guests.
So, this error typically occurs when the inviting account does not meet the role/authorization requirement enforced by those settings (even if it worked earlier and later stopped after a policy change).
- Verify External collaboration settings allow guest invitations
In the Microsoft Entra admin center, go to:
External Identities → External collaboration settings
Make sure the Guest invite settings are not blocking invitations and are set to a mode that allows your inviter account. Microsoft documents that these settings control “what roles in your organization can invite external users”.
Official doc: Configure external collaboration settings for B2B
- If your tenant is restricted to “Only specific admin roles can invite”, use the Guest inviter role (supported + documented)
If your organization restricts invitations to specific roles, Microsoft’s supported approach is to assign the Guest inviter role and then set External collaboration settings accordingly.
Microsoft provides a step-by-step guide to:
- Create a role-assignable security group
- Assign the Guest inviter role to that group
- Add the appropriate users to the group
- Configure External collaboration settings to allow only those roles to invite.
Official doc: Limit who can invite guest
- Allow time for policy propagation:
If you recently changed cross-tenant access settings, Microsoft notes that changes may take two hours to take effect. So after adjusting collaboration settings/roles, wait for propagation and retry.
Thanks,
Suchitra.