You have an Azure Active Directory (Azure AD) tenant named contoso.onmicorosft.com.
The User administrator role is assigned to a user named Admin1. An external partner has a Microsoft account that uses the user1@outlook.com sign in.
Admin1 attempts to invite the external partner to sign in to the Azure AD tenant and receives the following error message: "Unable to invite user user1@outlook.com- Generic authorization exception."
You need to ensure that Admin1 can invite the external partner to sign in to the Azure AD tenant.
What should you do?
Click on the arrows to vote for the correct answer
A. B. C. D.B
https://techcommunity.microsoft.com/t5/Azure-Active-Directory/Generic-authorization-exception-inviting-Azure-AD-gests/td-p/274742The error message "Unable to invite user user1@outlook.com - Generic authorization exception" indicates that the user Admin1 does not have the necessary permissions to invite an external partner to sign in to the Azure AD tenant. To resolve the issue, you need to assign the appropriate permissions to Admin1.
Option A: From the Roles and administrators blade, assign the Security administrator role to Admin1. This option is not the correct solution, as assigning the Security administrator role to Admin1 is not related to external partner invitation, and it may not be a suitable solution for security reasons.
Option B: From the Users blade, modify the External collaboration settings This option may be a possible solution. You can check and modify the external collaboration settings from the Azure portal to allow external partners to sign in. To do this, follow the steps below:
Option C: From the Organizational relationship blade, add an identity provider This option is not the correct solution, as adding an identity provider to the Azure AD tenant is not related to external partner invitation.
Option D: From the Custom domain names blade, add a custom domain This option is not the correct solution, as adding a custom domain name to the Azure AD tenant is not related to external partner invitation.
In conclusion, Option B is the correct answer as it relates to the external collaboration settings that need to be adjusted to allow the external partner to sign in to the Azure AD tenant.