Admin1 (assigned the User administrator role) tries to invite an external Microsoft account (user1@outlook.com) to the contoso.onmicrosoft.com Azure AD tenant but receives a 'Generic authorization exception'. What should you change so Admin1 can invite the external user?
Choose an answer
Tap an option to check your answer.
Correct answer: From the Users settings blade, modify the External collaboration settings..
Why this is the answer
The correct answer is to modify the External collaboration settings from the Users settings blade. By default, only users assigned the Global Administrator or User Administrator roles can invite guests. However, the External collaboration settings allow you to delegate this permission to other roles or even to all members. Admin1 has the User Administrator role, which should allow them to invite guests, but a 'Generic authorization exception' suggests a more restrictive setting is in place. Adjusting these settings will grant Admin1 the necessary permissions. Adding a custom domain is for managing your organization's domain names, not for external user invitations. Adding an identity provider is for federating with other identity systems, not directly for individual guest invitations. Assigning the Security administrator role is unnecessary as the User administrator role already has the default permission to invite guests, and the issue lies in the external collaboration settings, not Admin1's role itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed