## TL;DR
Most redemption failures come from the guest signing in with the wrong account type (their personal Microsoft account when they were invited as a work email, or vice versa) or a Conditional Access policy blocking guests. Have the guest open the invite in an InPrivate window and sign in with the exact invited email address; if they use a one-time passcode, make sure the code email is not in spam. Check Entra ID > Users > the guest for the invitation status before digging deeper.

## The error
```text
This invitation has already been redeemed
```
```text
Your account has been blocked from signing in to this tenant
```

## Steps
1. In Entra ID > Users, find the guest and check the invitation status. Expected: "Pending acceptance" means the invite never completed; "Accepted" means the problem is at sign-in, not redemption.
2. Resend the invitation if it is stale; invites expire after 7 days by default. Expected: a fresh redemption link. Do not keep troubleshooting a week-old link.
3. Have the guest open the link in an InPrivate or Incognito window and sign in with the EXACT email address the invite went to. Expected: redemption completes. Account-type mix-ups (personal Microsoft account vs work Entra account on the same email) are the top cause.
4. If redemption uses a one-time passcode: confirm the passcode email arrived and is not in spam or quarantine. Expected: the code arrives within a few minutes and works. Passcodes expire after 30 minutes.
5. Check Conditional Access policies that apply to guest users: Entra ID > Protection > Conditional Access, filtered for guest policies. Expected: no policy blocks the guest's sign-in. A policy requiring compliant devices blocks personal devices outright.
6. Check the sign-in logs filtered to the guest's UPN for the exact failure code. Expected: a concrete error code (for example 50057 for a disabled account) instead of guessing.

## Use this when
- A guest reports the invite link does not work or shows an error
- A guest can redeem but cannot sign in afterwards
- The one-time passcode never arrives

## Not for this skill when
- Employee (member user) login failures (different account type)
- Entra External ID B2C user flows (consumer sign-up, not B2B)
- The guest's own home tenant is down (their IdP, not yours)

## Compatibility
- Microsoft Entra ID B2B collaboration; Conditional Access features need Entra ID P1/P2

## Variants
### "This invitation has already been redeemed" but the user never accepted
Someone else with access to the mailbox redeemed it, or the invite was forwarded. Block the guest's sign-in, revoke, and send a fresh invite to the correct person.
### Guest keeps landing on their personal Microsoft account
Their email is registered as a personal Microsoft account. The InPrivate-window step plus choosing "work or school account" at the picker fixes most cases; if not, invite an alias email.

## Why it happens
Redemption ties the invite to a specific identity. When the invited email maps to both a personal Microsoft account and a work Entra account, the guest may authenticate as the wrong one and redemption fails because the identities do not match. Expired links and guest-blocking Conditional Access policies cover most of the rest.

## Edge cases
- Some orgs block redemption from certain countries via Conditional Access named locations; traveling guests hit this.
- If the guest user object was hard-deleted, resend a new invite rather than troubleshooting the old one.
- Never paste invite links into tickets or chat; anyone who clicks the link can redeem the invitation.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_xmSDsfuGKlGb92-aW9-5Iw
