How default and per-organisation settings control B2B collaboration and B2B direct connect, and when MFA and device claims are trusted.
From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)
Cross-tenant access settings govern B2B collaboration and B2B direct connect with other Microsoft Entra organisations, including organisations in other Microsoft clouds. They’re under Entra ID > External Identities > Cross-tenant access settings, and there’s no limit to the number of organisations you can add. Figure 3.1 shows which tenant holds each setting.
The Default settings tab applies to every external Microsoft Entra organisation that has no custom entry:
| Area | Initial default |
|---|---|
| B2B collaboration | Enabled inbound and outbound for all users; MFA and device claims not trusted |
| B2B direct connect | Blocked inbound and outbound for all tenants |
| Organisational settings | None added |
| Cross-tenant sync | No users synchronised into your tenant |
The Organizational settings tab holds per-partner entries, which take precedence over the defaults. To scope settings to specific external users, groups or apps, you need their object IDs or application IDs from the partner. User/group settings and application settings must not conflict: for example, blocking inbound access for all external users also requires blocking all applications.
When an external Microsoft Entra user signs in, your Conditional Access policies are evaluated together with the partner’s outbound settings and your inbound settings:
Trusting MFA doesn’t exempt guests from your policies. The policy still applies; it simply accepts the home tenant’s MFA. If you trust MFA, consider excluding external users from the ID Protection MFA registration policy, or they can’t satisfy both.
Automatically redeem invitations with the tenant suppresses the first-time consent prompt and invitation email. It works only when it’s selected in the home tenant’s outbound settings and the resource tenant’s inbound settings. It’s optional for B2B collaboration and direct connect, and required for cross-tenant synchronization. With B2B collaboration the user still receives a notification email.
Microsoft cloud settings enable B2B collaboration between the commercial cloud and Microsoft Azure Government, or between the commercial cloud and Microsoft Azure operated by 21Vianet. B2B direct connect isn’t supported across clouds.
Common trap: Enabling MFA trust and assuming guests no longer face your MFA policy - the policy still applies; trust only lets an MFA claim from the home tenant satisfy it.
Common trap: Ticking automatic redemption in the resource tenant only and expecting the consent prompt to disappear - the box must be ticked in the home tenant’s outbound settings and the resource tenant’s inbound settings.
This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-300 terms in the glossary · All SC-300 study notes
How the two hybrid sync engines differ in capability and limits, and where each sign-in method checks the password.
The three ways to switch on MFA across a tenant, compared by licence, flexibility and what each one enforces.
What a TAP is for, its lifetime and length settings, and which role can create one for which users.
Which events and location changes revoke a still-valid token, how long-lived CAE tokens behave, and where CAE falls back to one-hour tokens.
The difference between the two risk types, real-time versus offline detections, and which detections need P2.
How the two managed identity types differ in lifecycle and sharing, when to choose each, and the Azure roles needed to manage them.
Why every app has a global definition and a per-tenant instance, the three service principal types, and what happens when you change or delete one.