Entra AD users without email cannot accept organization invite

Hi again!

No, you do not need to select “require admin consent.” Instead, “providing admin consent” refers to an Azure administrator actively clicking a button labeled “Grant admin consent for [Your Organization]” in the Azure Portal.

Without this active grant, Microsoft’s security policies may block the custom claims (like the mapped UPN/email) from ever being sent to Auth0, resulting in the failure you are experiencing.

When an Entra ID user clicks an Auth0 Organization Invite and logs in, Auth0 intercepts the profile data returning from Microsoft. To accept the invite, Auth0 strictly requires the root email property of that returning profile to perfectly match the email address you invited.

If it fails with an error like "the specified account is not allowed to accept the current invitation" , it means one of two things happened:

  1. Entra ID refused to send the email claim because the application lacked administrative consent.
  2. Entra ID sent the UPN, but didn’t output it specifically into the standard email claim, leaving the email field empty on the Auth0 side.

You can confirm this by going to your Auth0 Dashboard > User Management > Users , finding the user who just attempted to log in, and looking at their Raw JSON . You will likely see that the email property is completely missing.

In enterprise environments, standard users often do not have the authority to consent to applications reading their profile data. You must have a Global Admin or Privileged Role Admin grant this on behalf of everyone.

  1. Log into the Azure Portal / Microsoft Entra admin center.
  2. Navigate to Identity > Applications > App registrations and select your Auth0 application.
  3. In the left menu, select API permissions .
  4. Ensure you have email , profile , and User.Read listed.
  5. Click the button at the top of the list that says “✓ Grant admin consent for [Your Tenant Name]” .
  6. The status column for all permissions should change to green checkmarks.

Even with consent granted, if the user physically has no email address configured in Azure, Microsoft might send a null email claim. You must explicitly configure the token to fall back to the UPN.

  1. In your App Registration in the Azure Portal, go to Token configuration in the left menu.
  2. Click Add optional claim
  3. Select ID (and repeat for Access if prompted)
  4. Check the boxes for both email and upn
  5. Click Add

If the Token Configuration step above doesn’t force the UPN into the email field, you can strictly override the claim in the Enterprise Application settings:

  1. In the Azure Portal, go to Enterprise Applications > select your Auth0 app > Single sign-on .
  2. Edit the Attributes & Claims section.
  3. Click on the claim named emailaddress (or http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress ).
  4. Change the Source attribute to user.userprincipalname .
  5. Save the configuration.

Let me know if that does the trick or not!

Kind Regards,
Nik