MS-700 · Question #216
You have a Microsoft 365 subscription named contoso.com. Contoso.com uses Teams to collaborate with users from a partner company that has a Microsoft 365 subscription named fabrikam.com. You need to…
This question tests knowledge of Azure AD (Entra ID) Cross-tenant Access Settings, specifically B2B Direct Connect configuration required for Teams shared channels, and inbound trust settings for MFA federation between partner tenants.
Question
Explanation
This question tests knowledge of Azure AD (Entra ID) Cross-tenant Access Settings, specifically B2B Direct Connect configuration required for Teams shared channels, and inbound trust settings for MFA federation between partner tenants.
Approach. For Requirement 1 (invite only fabrikam.com users): In the Azure portal under Azure Active Directory > External Identities > Cross-tenant access settings, you must ADD fabrikam.com as a specific organization under 'Organizational settings' and enable B2B Direct Connect (inbound and outbound) for that org specifically. The Default settings should have B2B Direct Connect blocked, so only the explicitly added fabrikam.com organization is permitted - this scopes shared channel invitations to fabrikam.com only. For Requirement 2 (trust MFA from fabrikam.com): Within the same Cross-tenant access settings, select the fabrikam.com organizational entry, navigate to 'Inbound access' > 'Trust settings', and enable 'Trust multi-factor authentication from Azure AD tenants'. This tells contoso.com to honor MFA claims already satisfied in fabrikam.com, preventing users from being double-prompted.
Concept tested. Azure AD (Entra ID) Cross-tenant Access Settings - B2B Direct Connect for Teams Shared Channels and Inbound Trust Settings for MFA federation. Teams shared channels require B2B Direct Connect (not traditional B2B guest/collaboration), which is configured per-organization in Cross-tenant access settings. Scoping to a single partner requires blocking in Default settings and allowing only in Organizational settings.
Reference. Microsoft Learn: Configure cross-tenant access settings for B2B direct connect - https://learn.microsoft.com/en-us/azure/active-directory/external-identities/cross-tenant-access-settings-b2b-direct-connect
Topics
Community Discussion
No community discussion yet for this question.