Stop repeated access requests from an external user
For customers who keep getting messages that an outside person cannot get into a shared system, document, VPN, or app. This guide helps you identify whether the problem is missing access, wrong identity, or an email/login mismatch, then fix it and verify the user can sign in without another support ticket.
TL;DR — If an external user keeps asking for access, the most common cause is that they are signing in with a different email address than the one you granted. Check the exact email on the access request, compare it to the user you added, then either grant access to that exact identity or remove the old entry and re-invite them. Reading time: ~5 min
Goal
When you finish, the external user will be able to sign in with the exact account you approved, and you will be able to confirm in your admin area that their access is active instead of pending, denied, or assigned to the wrong email.
Prerequisites
- Your admin login for the app, site, portal, VPN, or file-sharing system where the user needs access
- Permission to manage users, members, guests, or sharing settings in that system
- The exact email address the external user is using to sign in
- A recent access request email, screenshot, or audit log entry showing the requested identity
- If your system uses a company allowlist (approved domains), the external user's email domain, such as
partner-example.com - If available, access to your identity provider (central sign-in service), such as Microsoft Entra ID, Google Workspace, or Okta
Steps
Step 1: Capture the exact identity the user is using
Open the latest access request and copy the full email address shown in the request.
Use this checklist exactly:
Compare these side by side:
- Email in the access request: first.last@partner-example.com
- Email currently granted access: first.last@client-example.com
- Any alternate sign-in shown by the user: first.last@gmail.com
If your app has an admin area, open your provider's dashboard and go to the user list. Common menu paths are:
Your provider's dashboard → Admin / Users / Members / Guests / Shared with
What you should see: one user record or invitation that matches the exact email from the request, character for character.
Step 2: Check whether the user already exists under a different email
In the admin search box, search for the user's name and then search for each email variant separately.
Use these exact searches:
Search 1: first.last@partner-example.com
Search 2: first.last@client-example.com
Search 3: first.last@gmail.com
If your system supports filtering, use:
Status filters to check: Active, Pending, Invited, Disabled, Expired, Denied
What you should see: either one active user on the exact requested email, or a mismatch such as an old invitation on one email and a new request from another.
Step 3: Grant access to the exact email that is requesting access
If the exact email from the request is not present, add it as a new external user or guest.
Use your provider's dashboard and follow the nearest matching path:
Your provider's dashboard → Admin / Users / Members / Guests → Add user / Invite user
Enter these literal values:
Email: the exact email from the request
Role: Viewer (or the lowest role that lets them do the job)
Access scope: only the project, folder, app, or environment they need
If your system asks whether to notify the user:
Send invite email: Yes
What you should see: a new entry for that exact email with status Invited, Pending, or Active.
Step 4: Remove or expire the wrong invitation if there is a duplicate
If you found an old invitation or access grant on the wrong email, remove it so the user stops trying the wrong identity.
⚠️ If you remove an active user instead of a duplicate invitation, they can lose access immediately. Only remove the entry when the email does not match the current request.
Use your provider's dashboard and follow the nearest matching path:
Your provider's dashboard → Admin / Users / Members / Guests → select wrong email → Remove / Revoke / Delete invite
If your system offers both choices, pick:
For a pending invite: Cancel invite
For an active but wrong external identity: Remove access
What you should see: only the correct email remains in the user list.
Step 5: If your organization restricts outside domains, allow the user's domain
Some systems block external users unless their email domain is approved first.
Check your sharing or guest policy in the nearest matching path:
Your provider's dashboard → Settings / Security / Sharing / External access / Guest access
Add the user's domain exactly as shown after the @ symbol:
partner-example.com
If there is a policy choice, use the least-open option that still works:
Allowed domains only
Add allowed domain: partner-example.com
What you should see: the domain appears in the approved list, and new invites to that domain are accepted.
Step 6: Ask the user to sign in with the exact approved email
Send the user a short message telling them which email must be used.
Copy and paste this:
You now have access with this exact email address: first.last@partner-example.com
Please sign out of all other accounts in your browser, then open the invite again and sign in with that exact email.
If you still see "Request access," send me a screenshot that shows the email in the top-right account menu.
What you should see: the user stops sending new access requests and confirms they can open the resource.
Step 7: If your system uses a central identity provider, confirm the guest account is not blocked
If access is still failing, check your identity provider for a blocked or unredeemed guest account.
Common menu paths are:
Microsoft Entra ID: Users → All users → search exact email
Google Workspace: Directory → Users
Okta: Directory → People
Look for these statuses and actions:
Blocked / Suspended → Unblock or Unsuspend
Pending acceptance / Invitation not redeemed → Resend invitation
Disabled → Enable user
What you should see: the guest or external account is enabled and no longer in a blocked or pending-error state.
Verify it works
Run these checks in order:
1. In the app admin area, the correct email shows as Active or Invited, not Denied or Expired.
2. The wrong email, if any, no longer appears as a member or pending invite.
3. The user opens the resource without seeing "Request access" again.
4. If your app has an audit log, the latest event shows Sign-in succeeded, Access granted, or Invitation accepted for the correct email.
If you have an audit or activity log, use the nearest matching path:
Your provider's dashboard → Audit log / Activity / Security events
Expected result:
User: first.last@partner-example.com
Event: Invitation accepted / Access granted / Successful sign-in
Status: Success
Common pitfalls
The user is signing in with a different email than the one you invited
Mistake: You granted access to one address, but the user clicked the invite while logged into another account in the browser.
Symptom: They keep seeing Request access even though you already added them.
Fix: Remove the wrong invite if needed, grant access to the exact requesting email, and have them sign out and back in with that exact email.
There are duplicate user records for the same person
Mistake: The same person exists as both Pending and Active under different email addresses.
Symptom: Your admin list looks correct at a glance, but the user still cannot enter.
Fix: Search each email variant separately and keep only the record that matches the current request.
External sharing is blocked for that domain
Mistake: Your policy allows only internal users or only approved outside domains.
Symptom: Invitations fail silently, stay pending forever, or are rejected immediately.
Fix: Add the user's domain under Settings / Security / Sharing / External access / Allowed domains.
The invitation expired
Mistake: The user clicked an old invite link after the token (one-time sign-in link) expired.
Symptom: They loop back to Request access or see Invitation invalid.
Fix: Cancel the old invite and send a new invitation to the exact same email.
The guest account is blocked in the identity provider
Mistake: The app access looks correct, but the central sign-in account is disabled or suspended.
Symptom: The user gets a sign-in error before reaching the app.
Fix: In your identity provider, search the exact email and change the status to enabled or resend the guest invitation.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI