Multitenant Collaboration vs Cross tenant access best practices

Eddie Vincent 125 Reputation points
2025-03-07T16:41:14.2333333+00:00

Hi All,

I am looking at option(s) in relation to Multitenant Collaboration vs Cross-tenant access in 365/Entra/Azure portals, I am finding my search for documentation challenging- I have found a non Microsoft page which describes the following:

"Multitenant organizations synchronize users between tenants using Microsoft Entra ID B2B collaboration users. Cross-tenant synchronization automates creating, updating, and deleting B2B collaboration users"Diagram that shows cross-tenant synchronization between source tenant and target tenant.

So, if I want to create a trust/sync between 2 (or more) separate Entra tenants/offices/organizations who sit under the same umbrella (and have no reason to distrust) what is the best practice for setting this up and which option should be used within the settings (including dynamic group settings for user onboarding).

Thanks!

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
3,070 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Venkata Jagadeep 255 Reputation points Microsoft External Staff
    2025-03-07T21:15:44.47+00:00

    Hello Eddie Vincent,

    Thank you for posting your query on Microsoft Q&A.

    The multitenant organization scenario occurs when an organization has more than one tenant instance of Microsoft Entra ID. It offers a portfolio of multitenant capabilities you can use to securely interact with users across your organization of multiple tenants and to automatically provision and manage those users across your tenants.

    Cross-tenant access settings is one of the sets of multitenant capabilities support the needs of multitenant organizations:

    Cross-tenant access settings manage how your tenant allows or disallows access to your tenant from other tenants in your organization or vice versa. They govern B2B collaboration, B2B direct connect, cross-tenant synchronization, and they indicate whether another tenant of your organization is known to be part of your multitenant organization.

    Cross-tenant access settings are required for each tenant-to-tenant relationship, and tenant administrators explicitly configure each cross-tenant access relationship as needed.

    The following diagram shows the basic cross-tenant access inbound and outbound settings capabilities.

    001

    Reference :

    https://learn.microsoft.com/en-us/entra/identity/multi-tenant-organizations/overview

    https://learn.microsoft.com/en-us/entra/external-id/cross-tenant-access-overview

    Every tenant has its own in-bound, out-bound rules and default rules configured.

    To change inbound B2B collaboration settings, navigate to Identity > External Identities > Cross-tenant access settings, then select Organizational settings

    Customize settings: Select this option if you want to customize the settings to enforce for this organization instead of the default settings.

    Under Access status, you can allow or block access to specific users and groups.

    002

    Please refer the below document

    https://learn.microsoft.com/en-us/entra/external-id/cross-tenant-access-settings-b2b-collaboration#to-change-inbound-b2b-collaboration-settings

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.