nerdexam
Microsoft

AZ-500 · Question #523

You have a Microsoft Entra tenant named contoso.com. You have a partner company that has a Microsoft Entra tenant named fabrikam.com. You need to ensure that when a user in fabrikam.com attempts to…

The correct answer is A. From the Azure portal of contoso.com, configure the inbound access default settings. Trust multi-factor authentication from Microsoft Entra tenants: Select this checkbox to allow your Conditional Access policies to trust MFA claims from external organizations. During authentication, Microsoft Entra ID checks a user's credentials for a claim that the user…

Submitted by priya_blr· Mar 6, 2026Secure identity and access

Question

You have a Microsoft Entra tenant named contoso.com. You have a partner company that has a Microsoft Entra tenant named fabrikam.com. You need to ensure that when a user in fabrikam.com attempts to access the resources in contoso.com, the user only receives a single Microsoft Entra Multi-Factor Authentication (MFA) prompt. The solution must minimize administrative effort. What should you do?

Options

  • AFrom the Azure portal of contoso.com, configure the inbound access default settings.
  • BFrom the Azure portal of contoso.com, configure the External collaboration settings.
  • CFrom the Azure portal of contoso.com, configure the outbound access default settings.
  • DFrom the Azure portal of fabrikam.com, configure the outbound access default settings.

How the community answered

(52 responses)
  • A
    69% (36)
  • B
    4% (2)
  • C
    17% (9)
  • D
    10% (5)

Explanation

Trust multi-factor authentication from Microsoft Entra tenants: Select this checkbox to allow your Conditional Access policies to trust MFA claims from external organizations. During authentication, Microsoft Entra ID checks a user's credentials for a claim that the user completed MFA. If not, an MFA challenge is initiated in the user's home tenant. https://learn.microsoft.com/en-us/entra/external-id/cross-tenant-access-settings-b2b- collaboration#to-change-inbound-trust-settings-for-mfa-and-device-claims

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice