User gets message "Your account is locked" when accessing SharePoint of another organisation

In_Rainbows 26 Reputation points
2022-02-08T12:02:46.14+00:00

A user in our domain is invited to the SharePoint of another organisation. But when trying to log in, they get the message "Your account is locked" and "We have discovered suspicious activity on your account." Furthermore; "Contact NAME OF USER'S ORG administrator".

This usually happens when users have Risky sign ins, and in those cases, it is easily solved by dismissing user risk, which sets the risk level from high/medium to low.

However, this user has no risky sign ins. That means I can't find the user's risk level or dismiss anything.

Is there a way to dismiss user risk outside of the Risky sign in list? Or am I looking in the wrong place? Are there other factors affecting the user risk? The user is able to log in to our own systems as normal.

SharePoint Server
SharePoint Server
A family of Microsoft on-premises document management and storage systems.
2,422 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Alistair Ross 7,391 Reputation points Microsoft Employee
    2022-02-08T15:30:36.327+00:00

    You are saying that they are accessing SharePoint in another organisation, therefore it is likely their Guest account in that organisation is locked out, preventing them access. When you are invited to another Azure AD tenant, a guest account is created in that tenant associated with the original account.

    https://learn.microsoft.com/en-us/azure/active-directory/external-identities/b2b-quickstart-add-guest-users-portal#:~:text=Add%20a%20new%20guest%20user%20in%20Azure%20AD,to%20the%20guest%20user.%20...%20More%20items...%20

    2 people found this answer helpful.

  2. Yi Lu_MSFT 17,611 Reputation points
    2022-02-23T09:59:11.58+00:00

    Hi @In_Rainbows
    You could check that whether you have set some security policies in your organization: If there are any rules restrict this behavior

    177060-image.png

    177171-image.png

    177048-image.png


  3. Jacobus Burger 0 Reputation points
    2025-03-06T07:44:24.2733333+00:00

    Hi

    Reading these might solve the issue you are experiencing:
    https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/troubleshoot-app-publishing
    https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-b2b

    The main deal is that your tenant has a "Risky Users" policy enabled and is applied to Guests too. You will not see the risks in your list as the issue is on the other side. We (source tenant) cannot control the log-ons from other tenants (Guests).

    So,
    They can perform a secure password reset to gain access or
    The Guest users must be put into a Group on your tenant and excluded from the policy.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.