Cross-Tenant Synchronization Configuration Question

jisoo 0 Reputation points
2024-11-19T06:16:34.9466667+00:00

Hello.

A question is regarding Cross-Tenant Synchronization functionality.

Currently, there is an interest in using Microsoft's tenant-to-tenant synchronization feature to receive user information from an external tenant (Tenant B) within Tenant A.

The one-way synchronization setup for Tenant B has been completed, and the following configuration has been made:

Tenant-to-Tenant Synchronization > Configuration > Provisioning > Mapping Settings: userType has been set to Guest.

Is it possible to control the synchronization mapping setting in Tenant A so that the userType for Tenant B cannot be changed from Guest to Member?

Additionally, if Tenant B attempts to change the userType to Member during synchronization, can Tenant A refuse or filter that user?

The goal is to ensure that Tenant A only receives users from Tenant B with the userType set as Guest, not Member.

Is it possible for an administrator in Tenant A to control or filter the synchronization mapping configuration of Tenant B?

Recommendations received include:

  1. Conditional Access Policies
  2. Custom Attribute Mapping
  3. Post-Synchronization Scripts
  4. Provisioning Logs and Alerts

However, is there a way to prevent this proactively rather than dealing with it afterward?

Thank you.

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,931 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,229 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vasil Michev 108.6K Reputation points MVP
    2024-11-19T07:50:57.0866667+00:00

    No, mapping configuration is done entirely on the "receiving" side. You can only prevent which users/groups can be synchronized from the "home" tenant.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.