Microsoft Entra cross-tenant access settings control B2B collaboration with other Microsoft Entra organizations: which of their users can come into your tenant and which of your apps they reach (inbound), where your users can go (outbound), and whether your Conditional Access policies trust a partner's MFA and device claims. To set up a trusted partner, add their tenant under Organizational settings, scope inbound access to the partner groups and apps that need it, enable Trust multifactor authentication from Microsoft Entra tenants (and device trust if you require managed devices), and target a Conditional Access policy at that partner's users.
Who this is for and what you will have at the end
This guide is for identity administrators who collaborate with suppliers, joint ventures or sister companies that run their own Microsoft Entra tenant, and who want that access to be scoped and strongly authenticated rather than open to any external account.
At the end you will have:
- A reviewed default policy for all external Microsoft Entra organizations.
- A partner-specific configuration that allows only named partner groups into named apps.
- Inbound trust for the partner's MFA and, optionally, compliant or hybrid joined devices.
- Optional automatic redemption so partner users skip the consent prompt.
- A Conditional Access policy that requires an authentication strength for that partner's users.
If you're consolidating tenants rather than collaborating, the same settings underpin cross-tenant synchronization; see M365 tenant-to-tenant migration architecture.
How cross-tenant access settings work
There are three kinds of setting:
| Setting | Controls | Configured in |
|---|---|---|
| Inbound access | Which external users and groups can be invited or connect, and which of your applications they can use | The resource tenant |
| Outbound access | Which of your users and groups can go to external organizations, and which external apps they can use | The user's home tenant |
| Inbound trust | Whether your Conditional Access accepts MFA, compliant device and hybrid joined device claims from the other tenant | The resource tenant |
Settings exist at two levels. Default settings apply to every external Microsoft Entra organization you haven't configured; Organizational settings apply to specific tenants and take precedence. Out of the box:
- B2B collaboration is enabled for all users, inbound and outbound, and MFA and device claims from other tenants aren't trusted.
- B2B direct connect is blocked inbound and outbound.
- No organizations are listed under Organizational settings.
- No users are synchronized in through cross-tenant synchronization.
Cross-tenant access settings cover only other Microsoft Entra organizations. For social identities and email one-time passcode guests, use External collaboration settings, which also control who can invite guests and allow or block domains. Both are checked at invitation: a domain on the external collaboration blocklist can't be invited regardless of cross-tenant settings. Tenant restrictions, which control which external accounts your users can use on your devices, are configured separately and aren't affected by these settings.
Licensing and roles
- Security Administrator is the least-privileged built-in role for cross-tenant access settings. Microsoft also documents recommended custom roles.
- Microsoft Entra ID P1 in the tenant you configure, to use trust settings or to target specific users, groups or applications. B2B direct connect needs P1 in both tenants.
- Conditional Access Administrator for the policies in Step 6.
- Changes to cross-tenant access settings are protected actions, so you can require a Conditional Access policy, such as phishing-resistant MFA, for the admins who make them.
Prerequisites
- Find out what access exists today. Changing defaults to Block can break business-critical access. Use the Cross-tenant access activity workbook in Azure Monitor, the
Get-MSIDCrossTenantAccessActivityscript from the MSIdentityTools module,Get-MgAuditLogSignIn, or your SIEM. Sign-in logs may only cover 30 days, so also ask business owners. - Get identifiers from the partner. To scope inbound access you need the partner's tenant ID or primary domain, and the object IDs of the partner groups (or users) that should have access.
- Agree trust in both directions. Automatic redemption and B2B direct connect need matching settings in the partner's tenant.
Step 1: Review the default settings
- Sign in to the Microsoft Entra admin center as at least a Security Administrator.
- Go to Entra ID > External Identities > Cross-tenant access settings and open the Default settings tab.
- Review Edit inbound defaults and Edit outbound defaults.
Many organizations keep the defaults permissive for B2B collaboration and tighten access per partner. If you block inbound access by default, you must also block access to all your applications in the default, and every partner you work with then needs an organizational entry. You can't target specific users or groups in the inbound defaults.
Step 2: Add the partner organization
- Open Organizational settings and select Add organization.
- Enter the partner's full domain name or tenant ID, select it and select Add.
The organization now inherits every setting from the defaults until you customize it, shown as Inherited from default in the Inbound access and Outbound access columns.
Step 3: Scope inbound B2B collaboration
- Select the link in the partner's Inbound access column and the B2B collaboration tab, then Customize settings.
- On External users and groups, set Access status to Allow access, set Applies to to Select external users and groups, and add the partner group object IDs you collected, choosing group in the type menu.
- On Applications, set Allow access and Select applications, then add the apps the partner should use with Add Microsoft applications or Add other applications.
- Select Save.
User and application settings must be consistent: if you block all external users you must block all applications, and vice versa.
Include the Microsoft apps partner users need
If you allow only specific apps, partner users can lose access to pages they need to redeem invitations and register MFA. Microsoft recommends adding these:
| Application | Resource ID | Why |
|---|---|---|
| My Apps | 2793995e-0a7d-40d7-bd35-6968ba142197 | Landing page after redemption |
| Microsoft App Access Panel | 0000000c-0000-0000-c000-000000000000 | Security info and organization switcher pages; MFA registration |
| My Profile | 8c59ead7-d703-4a27-9e55-c96a0054c8d2 | myaccount.microsoft.com, My Groups, My Access |
| My Sign ins | 19db86c3-b2b9-44cc-b339-36da233a3be2 | Security info, needed if partner users register MFA in your tenant |
Some of these can't be selected in the admin center. Add them with a Microsoft Graph PATCH to https://graph.microsoft.com/v1.0/policies/crossTenantAccessPolicy/partners/{partner-tenant-id}, remembering that it overwrites the application list, so include every app you want to keep:
{
"b2bCollaborationInbound": {
"applications": {
"accessType": "allowed",
"targets": [
{ "target": "2793995e-0a7d-40d7-bd35-6968ba142197", "targetType": "application" },
{ "target": "0000000c-0000-0000-c000-000000000000", "targetType": "application" },
{ "target": "8c59ead7-d703-4a27-9e55-c96a0054c8d2", "targetType": "application" },
{ "target": "19db86c3-b2b9-44cc-b339-36da233a3be2", "targetType": "application" }
]
}
}
}If you use SharePoint and OneDrive integration with Microsoft Entra B2B, also add the partner's domains to External collaboration settings, or invitations from those apps can fail even when the tenant is allowed here.
Step 4: Trust the partner's MFA and device claims
- In the partner's inbound settings, open the Trust settings tab and select Customize settings.
- Select Trust multifactor authentication from Microsoft Entra tenants.
- Select Trust compliant devices and Trust Microsoft Entra hybrid joined devices only if you'll require managed devices and accept the partner's device management.
- Select Save.
What changes:
- With MFA trust, your MFA policies still apply, but if the user's session already shows MFA completed in their home tenant, they aren't challenged again. If not, the challenge happens in their home tenant. Without MFA trust, B2B collaboration users must register and complete MFA in your tenant, and B2B direct connect users are blocked.
- With device trust, your Require compliant device or Require hybrid joined device grant controls can be satisfied by the partner's claims. Without it, external users can't satisfy those controls, because their devices can only be managed by their home tenant. Microsoft doesn't recommend requiring managed devices for external users unless you trust these claims.
- Users from cloud service providers signing in with granular delegated admin privileges (GDAP) always do MFA in their home tenant, which is always trusted, regardless of this setting.
The same trust can be set with Microsoft Graph PowerShell:
Connect-MgGraph -Scopes "Policy.ReadWrite.CrossTenantAccess"
$params = @{
inboundTrust = @{
isMfaAccepted = $true
isCompliantDeviceAccepted = $true
isHybridAzureADJoinedDeviceAccepted = $false
}
}
Update-MgPolicyCrossTenantAccessPolicyPartner `
-CrossTenantAccessPolicyConfigurationPartnerTenantId "<partner tenant ID>" `
-BodyParameter $paramsIf you trust partner MFA, consider excluding external users from the ID Protection MFA registration policy; when both apply, external users can't satisfy the requirements.
Step 5: Outbound access and automatic redemption
Outbound settings decide where your own users can collaborate. For the partner, open the Outbound access link, B2B collaboration tab, Customize settings, and scope Users and groups and External applications the same way. Blocking all your users also blocks all external apps for that partner.
If you block apps by default, allow app ID 00000012-0000-0000-c000-000000000000 outbound, or your users can't read messages encrypted with Office 365 Message Encryption.
Automatic redemption removes the consent prompt the first time partner users access your tenant. Select Automatically redeem invitations with the tenant on the Trust settings tab of your inbound settings for the partner, and the partner must select the same option in their outbound settings for your tenant. If only one side sets it, the prompt still appears. It is required for cross-tenant synchronization and optional for B2B collaboration and B2B direct connect.
Step 6: Enforce Conditional Access for partner users
Trust settings only define what you accept; Conditional Access defines what you require.
- Sign in as at least a Conditional Access Administrator, go to Entra ID > Conditional Access > Policies > New policy.
- Users: Select users and groups > Guest or external users, select B2B collaboration guest users (and B2B collaboration member users if the partner's users are members in your tenant), then specify the partner's tenant instead of all tenants. Exclude your emergency access accounts.
- Target resources: the apps you opened to the partner.
- Grant: Require authentication strength, choosing Multifactor authentication or Phishing-resistant MFA. Add Require device to be marked as compliant only if you trust the partner's compliant claims.
- Start in Report-only, review the results, then switch the policy On.
Which methods count depends on where MFA happens:
| Method | Accepted when done in the home tenant (MFA trusted) | Accepted when done in your tenant |
|---|---|---|
| SMS, voice call, Authenticator push, OATH software token | Yes | Yes |
| Authenticator phone sign-in, OATH hardware token | Yes | No |
| FIDO2 security key, Windows Hello for Business, certificate-based authentication | Yes | No |
So a phishing-resistant requirement for partner users only works with MFA trust enabled. Authentication strengths apply only to external users who authenticate with Microsoft Entra ID; for email one-time passcode, SAML/WS-Fed and Google federation users, use the Require multifactor authentication grant instead. Require approved client app and Require app protection policy aren't supported for external users. For the access model behind these choices, see the zero trust remote access architecture.
Optional: B2B direct connect
B2B direct connect is a mutual trust used for Teams shared channels. Users don't get a guest account in your tenant. It is blocked by default and needs inbound and outbound settings on both sides, plus inbound MFA trust if your policies require MFA. B2B direct connect isn't supported between different Microsoft clouds.
Verify
- Audit logs: filter Category to CrossTenantAccessSettings to see every change to these settings.
- Sign-in logs: sign in as a test partner user and check the Conditional Access and Authentication Details tabs to see which policies applied and how MFA was satisfied.
- Graph:
GET https://graph.microsoft.com/v1.0/policies/crossTenantAccessPolicy/partners/{partner-tenant-id}returns the effective partner configuration, includinginboundTrust. - A partner user outside the allowed groups should be blocked; an allowed user should reach only the allowed apps.
Troubleshooting
AADSTS500213: The resource tenant's cross-tenant access policy doesn't allow this user to access this tenant. Your inbound settings block the user. Check that the user is in an allowed partner group, that the app is allowed, and that no organization-specific setting overrides what you expect.
AADSTS500212: The user's administrator has set an outbound access policy that doesn't allow access to the resource tenant. The partner's outbound settings block their user. Their administrator must allow your tenant, the user and the app.
Partner users can't register MFA or accept terms of use. With an app allowlist, allow 0000000c-0000-0000-c000-000000000000 (Microsoft App Access Panel) for MFA registration and d52792f4-ba38-424d-8140-ada5b883f293 (Microsoft Entra Terms of Use), outbound in the home tenant and inbound in the resource tenant. The inbound side must currently be set through Microsoft Graph.
Partner users are blocked by a compliant device policy. Device trust isn't enabled for that partner, or the device isn't compliant in the partner's own Intune.
High-risk partner users are blocked. User risk is evaluated in the home tenant and can't be remediated in yours; a policy forcing a password change blocks them. Exclude external users from user-risk policies.
Partner users are still asked to consent. Automatic redemption is set on only one side.
Checklist
- Current cross-tenant sign-ins reviewed before changing defaults.
- Partner added under Organizational settings with inbound access scoped to named groups and apps.
- My Apps, App Access Panel, My Profile and My Sign ins allowed if you use an app allowlist.
- MFA trust enabled for the partner; device trust only where you require managed devices.
- Automatic redemption agreed and set on both sides, if wanted.
- Conditional Access policy scoped to the partner tenant's external users, tested in report-only mode.
- Audit log alerts on the CrossTenantAccessSettings category, and protected actions for admins who change these settings.
References
- Cross-tenant access overview
- Cross-tenant access settings for B2B collaboration
- Authentication and Conditional Access for B2B users
- Conditional Access: authentication strength for external users
- Conditional Access users, groups and workload identities
- Update crossTenantAccessPolicyConfigurationPartner
- crossTenantAccessPolicyInboundTrust resource type
- Microsoft Entra authentication and authorization error codes