FREE STUDY NOTES · SC-300

Cross-tenant access settings: inbound, outbound and trust

How default and per-organisation settings control B2B collaboration and B2B direct connect, and when MFA and device claims are trusted.

From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)

Cross-tenant access settings govern B2B collaboration and B2B direct connect with other Microsoft Entra organisations, including organisations in other Microsoft clouds. They’re under Entra ID > External Identities > Cross-tenant access settings, and there’s no limit to the number of organisations you can add. Figure 3.1 shows which tenant holds each setting.

A user in the home tenant passes through that tenant's outbound access settings to reach the resource tenant's inbound access settings, trust settings (MFA, compliant-device and hybrid joined device claims) and resources. Below, default settings (initial values) are compared with organisational settings, which take precedence for a named partner.
Figure 3.1: Outbound settings in the home tenant, inbound and trust settings in the resource tenant

Inbound, outbound and trust

Defaults and organisational settings

The Default settings tab applies to every external Microsoft Entra organisation that has no custom entry:

Area Initial default
B2B collaboration Enabled inbound and outbound for all users; MFA and device claims not trusted
B2B direct connect Blocked inbound and outbound for all tenants
Organisational settings None added
Cross-tenant sync No users synchronised into your tenant

The Organizational settings tab holds per-partner entries, which take precedence over the defaults. To scope settings to specific external users, groups or apps, you need their object IDs or application IDs from the partner. User/group settings and application settings must not conflict: for example, blocking inbound access for all external users also requires blocking all applications.

Roles and licences

How MFA and device trust work

When an external Microsoft Entra user signs in, your Conditional Access policies are evaluated together with the partner’s outbound settings and your inbound settings:

Trusting MFA doesn’t exempt guests from your policies. The policy still applies; it simply accepts the home tenant’s MFA. If you trust MFA, consider excluding external users from the ID Protection MFA registration policy, or they can’t satisfy both.

Automatic redemption

Automatically redeem invitations with the tenant suppresses the first-time consent prompt and invitation email. It works only when it’s selected in the home tenant’s outbound settings and the resource tenant’s inbound settings. It’s optional for B2B collaboration and direct connect, and required for cross-tenant synchronization. With B2B collaboration the user still receives a notification email.

Microsoft cloud settings

Microsoft cloud settings enable B2B collaboration between the commercial cloud and Microsoft Azure Government, or between the commercial cloud and Microsoft Azure operated by 21Vianet. B2B direct connect isn’t supported across clouds.

Common trap: Enabling MFA trust and assuming guests no longer face your MFA policy - the policy still applies; trust only lets an MFA claim from the home tenant satisfy it.

Common trap: Ticking automatic redemption in the resource tenant only and expecting the consent prompt to disappear - the box must be ticked in the home tenant’s outbound settings and the resource tenant’s inbound settings.

Get the whole book

This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-300 terms in the glossary · All SC-300 study notes

More SC-300 study notes