Microsoft Entra - Cross-Tenant Access and B2B Collab
In this article
Summary
This article covers how to configure Microsoft Entra cross-tenant access settings for secure B2B collaboration: the difference between B2B collaboration and B2B direct connect, how inbound, outbound, and trust settings work together, and how to manage a guest account's lifecycle from invitation through access review.
Why Cross-Tenant Access Exist
The moment you collaborate with another organization, such as a partner, a client, an acquisition, you run into the same problem: their users need access to something in your tenant, but their identities live in a directory you don't control. Cross-tenant access settings are Microsoft Entra's answer to that problem. Instead of treating every external identity as either fully trusted or completely unknown, cross-tenant access lets you define, explicitly and per organization, exactly what you're willing to trust and what you're willing to share.
Cross-Tenant Access Settings Anatomy: Inbound, Outbound, Trust
Cross-tenant access settings live in the Entra admin center under External Identities, and they're built from three parts.
- Inbound access: Controls what external users from another tenant can do in yours: whether they can be invited as B2B collaboration guests or connected via B2B direct connect, and which of your users, groups, or applications they can reach.
- Outbound access: The mirror image: whether your users can collaborate in an external tenant, and which of your users, groups, or applications are allowed to do so.
- Trust settings: Whether you accept MFA, compliant-device, and hybrid-Azure-AD-joined-device claims that an external tenant has already verified, so your policies don't force external users to redo work their home tenant already did.
These settings exist at two levels. Default settings apply to every external organization you haven't explicitly configured by default, inbound and outbound B2B collaboration are enabled, and B2B direct connect is blocked. Organizational settings let you override those defaults for one specific partner tenant, which is what you'll use whenever a relationship needs different rules than everyone else gets.
B2B Collaboration vs. B2B Direct Connect vs. Multi-Tenant Organizations
Three related features solve overlapping problems, and it's worth being precise about which is which.
B2B collaboration is the classic guest model: you send an invitation, the external user redeems it, and a guest object is created in your directory that references their home identity. It's the most flexible option and works with almost any external user or organization.
B2B direct connect skips the guest object entirely. It establishes a mutual, two-way trust relationship between specific tenants, used almost exclusively today for Microsoft Teams shared channels external users participate directly, with no invitation and nothing added to your user directory.
Multi-tenant organizations are a different scenario again: multiple tenants that belong to the same company, connected via cross-tenant synchronization so employees move between tenants with a near-native experience, rather than as guests. If you're connecting tenants within one company rather than with an external partner, this not B2B collaboration is usually the right tool.
Guest User Lifecycle: Invitation, Redemption, Access Reviews
A B2B guest account has a lifecycle, and each stage is a place to apply governance. Invitation is the starting point, sent by an admin or, if you allow it, by any user. Redemption is when the guest accepts and their guest object is created; for partners with a verified domain, you can enable automatic redemption so users skip that step entirely. Once a guest is active, don't assume the relationship is permanent: access reviews let you periodically confirm a guest still needs access, with an inactive or unconfirmed guest removed automatically. Guest accounts that outlive the project or relationship that created them are one of the most common audit findings in Entra tenants building a review cadence in from the start is far cheaper than cleaning it up later.
Conclusion
Cross-tenant access turns "do we trust this partner" from a vague, ad hoc judgment call into an explicit, auditable configuration, scoped per organization rather than applied as one blanket default. Once you're comfortable configuring inbound, outbound, and trust settings for a single partner, the same pattern extends cleanly to every partner relationship your organization takes on next.