403 Forbidden - Request forbidden by administrative rules

Dominic Johnson 20 Reputation points
2024-05-09T08:53:27.9233333+00:00

I work in the UK. On Microsoft Azure/Microsoft Entra ID, my colleagues who are Member users have their user location set to the UK. Even for those that work for our company who live in the US, Canada and India. When 2 of my colleagues went to China they could still access our company's web portal.

I sent an invite on Microsoft Entra ID to a client as a guest user (with no user location set) who currently has been in China for some while. They seem to have accepted the invitation. However, when they try to access our company's web portal they are greeted with the 403 Forbidden - Request forbidden by administrative rules message.

Is this because they are a guest user in China?

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,672 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,772 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Fabio Andrade 650 Reputation points Microsoft Employee
    2024-05-10T22:55:54.24+00:00

    Hi @Dominic Johnson,

    Thanks for reaching out to Microsoft Q&A Support.

    Since the invite has been accepted, it doesn't seem that the issue relies on the guest user being from Azure China Cloud. In fact, B2B Collaboration between Azure Commercial and Azure China clouds is enabled by default:

    https://learn.microsoft.com/en-us/entra/external-id/cross-cloud-settings

    User's image

    Based on the error message, it looks like the error is coming from the portal / application. Do you have any logs from the portal side that could have more information about this error?

    From Entra ID sign in logs, can you see any sign in errors from the B2B user?

    Thanks,

    Fabio