Skip to content

Commit 4ccb725

Browse files
authored
Merge pull request #203176 from msmimart/mm-xtas-ga
[EXID] GA: External Identities cross-tenant access settings and B2B direct connect
2 parents b822827 + 3839458 commit 4ccb725

19 files changed

+66
-67
lines changed

articles/active-directory/external-identities/b2b-direct-connect-overview.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,15 +6,15 @@ services: active-directory
66
ms.service: active-directory
77
ms.subservice: B2B
88
ms.topic: conceptual
9-
ms.date: 04/08/2022
9+
ms.date: 06/30/2022
1010

1111
ms.author: mimart
1212
author: msmimart
1313
manager: celestedg
1414
ms.collection: M365-identity-device-management
1515
---
1616

17-
# B2B direct connect overview (Preview)
17+
# B2B direct connect overview
1818

1919
Azure Active Directory (Azure AD) B2B direct connect is a feature of External Identities that lets you set up a mutual trust relationship with another Azure AD organization for seamless collaboration. This feature currently works with Microsoft Teams shared channels. With B2B direct connect, users from both organizations can work together using their home credentials and a shared channel in Teams, without having to be added to each other’s organizations as guests. Use B2B direct connect to share resources with external Azure AD organizations. Or use it to share resources across multiple Azure AD tenants within your own organization.
2020

articles/active-directory/external-identities/cross-cloud-settings.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ services: active-directory
55
ms.service: active-directory
66
ms.subservice: B2B
77
ms.topic: how-to
8-
ms.date: 05/17/2022
8+
ms.date: 06/30/2022
99

1010
ms.author: mimart
1111
author: msmimart
@@ -55,7 +55,7 @@ In your Microsoft cloud settings, enable the Microsoft Azure cloud you want to c
5555
>Microsoft Azure China - https://aka.ms/cloudsettingschina
5656
5757
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
58-
1. Select **External Identities**, and then select **Cross-tenant access settings (Preview)**.
58+
1. Select **External Identities**, and then select **Cross-tenant access settings**.
5959
1. Select **Microsoft cloud settings (Preview)**.
6060
1. Select the checkboxes next to the external Microsoft Azure clouds you want to enable.
6161

@@ -69,7 +69,7 @@ In your Microsoft cloud settings, enable the Microsoft Azure cloud you want to c
6969
Follow these steps to add the tenant you want to collaborate with to your Organizational settings.
7070

7171
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
72-
1. Select **External Identities**, and then select **Cross-tenant access settings (Preview)**.
72+
1. Select **External Identities**, and then select **Cross-tenant access settings**.
7373
1. Select **Organizational settings**.
7474
1. Select **Add organization**.
7575
1. On the **Add organization** pane, type the tenant ID for the organization (cross-cloud lookup by domain name isn't currently available).

articles/active-directory/external-identities/cross-tenant-access-overview.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ services: active-directory
55
ms.service: active-directory
66
ms.subservice: B2B
77
ms.topic: how-to
8-
ms.date: 05/17/2022
8+
ms.date: 06/30/2022
99

1010
ms.author: mimart
1111
author: msmimart
@@ -14,10 +14,7 @@ ms.custom: "it-pro"
1414
ms.collection: M365-identity-device-management
1515
---
1616

17-
# Overview: Cross-tenant access with Azure AD External Identities (Preview)
18-
19-
> [!NOTE]
20-
> Cross-tenant access settings are preview features of Azure Active Directory. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
17+
# Overview: Cross-tenant access with Azure AD External Identities
2118

2219
Azure AD organizations can use External Identities cross-tenant access settings to manage how they collaborate with other Azure AD organizations and other Microsoft Azure clouds through B2B collaboration and [B2B direct connect](cross-tenant-access-settings-b2b-direct-connect.md). [Cross-tenant access settings](cross-tenant-access-settings-b2b-collaboration.md) give you granular control over how external Azure AD organizations collaborate with you (inbound access) and how your users collaborate with external Azure AD organizations (outbound access). These settings also let you trust multi-factor authentication (MFA) and device claims ([compliant claims and hybrid Azure AD joined claims](../conditional-access/howto-conditional-access-policy-compliant-device.md)) from other Azure AD organizations.
2320

@@ -59,6 +56,9 @@ You can configure organization-specific settings by adding an organization and m
5956

6057
## Microsoft cloud settings
6158

59+
> [!NOTE]
60+
> Microsoft cloud settings are preview features of Azure Active Directory. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
61+
6262
Microsoft cloud settings let you collaborate with organizations from different Microsoft Azure clouds. With Microsoft cloud settings, you can establish mutual B2B collaboration between the following clouds:
6363

6464
- Microsoft Azure global cloud and Microsoft Azure Government

articles/active-directory/external-identities/cross-tenant-access-settings-b2b-collaboration.md

Lines changed: 7 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ services: active-directory
55
ms.service: active-directory
66
ms.subservice: B2B
77
ms.topic: how-to
8-
ms.date: 05/17/2022
8+
ms.date: 06/30/2022
99

1010
ms.author: mimart
1111
author: msmimart
@@ -14,10 +14,7 @@ ms.custom: "it-pro"
1414
ms.collection: M365-identity-device-management
1515
---
1616

17-
# Configure cross-tenant access settings for B2B collaboration (Preview)
18-
19-
> [!NOTE]
20-
> Cross-tenant access settings are preview features of Azure Active Directory. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
17+
# Configure cross-tenant access settings for B2B collaboration
2118

2219
Use External Identities cross-tenant access settings to manage how you collaborate with other Azure AD organizations through B2B collaboration. These settings determine both the level of *inbound* access users in external Azure AD organizations have to your resources, as well as the level of *outbound* access your users have to external organizations. They also let you trust multi-factor authentication (MFA) and device claims ([compliant claims and hybrid Azure AD joined claims](../conditional-access/howto-conditional-access-policy-compliant-device.md)) from other Azure AD organizations. For details and planning considerations, see [Cross-tenant access in Azure AD External Identities](cross-tenant-access-overview.md).
2320

@@ -38,7 +35,7 @@ Use External Identities cross-tenant access settings to manage how you collabora
3835
Default cross-tenant access settings apply to all external tenants for which you haven't created organization-specific customized settings. If you want to modify the Azure AD-provided default settings, follow these steps.
3936

4037
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
41-
1. Select **External Identities**, and then select **Cross-tenant access settings (Preview)**.
38+
1. Select **External Identities**, and then select **Cross-tenant access settings**.
4239
1. Select the **Default settings** tab and review the summary page.
4340

4441
![Screenshot showing the Cross-tenant access settings Default settings tab.](media/cross-tenant-access-settings-b2b-collaboration/cross-tenant-defaults.png)
@@ -58,7 +55,7 @@ Use External Identities cross-tenant access settings to manage how you collabora
5855
Follow these steps to configure customized settings for specific organizations.
5956

6057
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
61-
1. Select **External Identities**, and then select **Cross-tenant access settings (Preview)**.
58+
1. Select **External Identities**, and then select **Cross-tenant access settings**.
6259
1. Select **Organizational settings**.
6360
1. Select **Add organization**.
6461
1. On the **Add organization** pane, type the full domain name (or tenant ID) for the organization.
@@ -82,7 +79,7 @@ With inbound settings, you select which external users and groups will be able t
8279

8380
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
8481

85-
1. Select **External Identities** > **Cross-tenant access settings (Preview)**.
82+
1. Select **External Identities** > **Cross-tenant access settings**.
8683

8784
1. Navigate to the settings you want to modify:
8885
- **Default settings**: To modify default inbound settings, select the **Default settings** tab, and then under **Inbound access settings**, select **Edit inbound defaults**.
@@ -192,7 +189,7 @@ With outbound settings, you select which of your users and groups will be able t
192189

193190
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
194191

195-
1. Select **External Identities**, and then select **Cross-tenant access settings (Preview)**.
192+
1. Select **External Identities**, and then select **Cross-tenant access settings**.
196193

197194
1. Navigate to the settings you want to modify:
198195

@@ -272,7 +269,7 @@ When you remove an organization from your Organizational settings, the default c
272269
273270
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
274271

275-
1. Select **External Identities**, and then select **Cross-tenant access settings (Preview)**.
272+
1. Select **External Identities**, and then select **Cross-tenant access settings**.
276273

277274
1. Select the **Organizational settings** tab.
278275

articles/active-directory/external-identities/cross-tenant-access-settings-b2b-direct-connect.md

Lines changed: 8 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ services: active-directory
55
ms.service: active-directory
66
ms.subservice: B2B
77
ms.topic: how-to
8-
ms.date: 03/21/2022
8+
ms.date: 06/30/2022
99

1010
ms.author: mimart
1111
author: msmimart
@@ -14,10 +14,7 @@ ms.custom: "it-pro"
1414
ms.collection: M365-identity-device-management
1515
---
1616

17-
# Configure cross-tenant access settings for B2B direct connect (Preview)
18-
19-
> [!NOTE]
20-
> Cross-tenant access settings are preview features of Azure Active Directory. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
17+
# Configure cross-tenant access settings for B2B direct connect
2118

2219
Use cross-tenant access settings to manage how you collaborate with other Azure AD organizations through [B2B direct connect](b2b-direct-connect-overview.md). These settings let you determine the level of outbound access your users have to external organizations. They also let you control the level of inbound access that users in external Azure AD organizations will have to your internal resources.
2320

@@ -44,7 +41,7 @@ Learn more about using cross-tenant access settings to [manage B2B direct connec
4441
Default cross-tenant access settings apply to all external tenants for which you haven't created organization-specific customized settings. If you want to modify the Azure AD-provided default settings, follow these steps.
4542

4643
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
47-
1. Select **External Identities**, and then select **Cross-tenant access settings (Preview)**.
44+
1. Select **External Identities**, and then select **Cross-tenant access settings**.
4845
1. Select the **Default settings** tab and review the summary page.
4946

5047
![Screenshot showing the Cross-tenant access settings Default settings tab](media/cross-tenant-access-settings-b2b-direct-connect/cross-tenant-defaults.png)
@@ -64,7 +61,7 @@ Learn more about using cross-tenant access settings to [manage B2B direct connec
6461
Follow these steps to configure customized settings for specific organizations.
6562

6663
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
67-
2. Select **External Identities**, and then select **Cross-tenant access settings (preview)**.
64+
2. Select **External Identities**, and then select **Cross-tenant access settings**.
6865
3. Select **Organizational settings**.
6966
4. Select **Add organization**.
7067
5. On the **Add organization** pane, type the full domain name (or tenant ID) for the organization.
@@ -88,7 +85,7 @@ With inbound settings, you select which external users and groups will be able t
8885

8986
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
9087

91-
1. Select **External Identities**, and then select **Cross-tenant access settings (Preview)**.
88+
1. Select **External Identities**, and then select **Cross-tenant access settings**.
9289

9390
1. Navigate to the settings you want to modify:
9491
- To modify default inbound settings, select the **Default settings** tab, and then under **Inbound access settings**, select **Edit inbound defaults**.
@@ -190,7 +187,7 @@ With outbound settings, you select which of your users and groups will be able t
190187

191188
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
192189

193-
1. Select **External Identities** > **Cross-tenant access settings (preview)**.
190+
1. Select **External Identities** > **Cross-tenant access settings**.
194191

195192
1. Navigate to the settings you want to modify:
196193

@@ -266,12 +263,12 @@ When you remove an organization from your Organizational settings, the default c
266263
267264
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator or Security administrator account. Then open the **Azure Active Directory** service.
268265

269-
1. Select **External Identities**, and then select **Cross-tenant access settings (Preview)**.
266+
1. Select **External Identities**, and then select **Cross-tenant access settings**.
270267

271268
1. Select the **Organizational settings** tab.
272269

273270
1. Find the organization in the list, and then select the trash can icon on that row.
274271

275272
## Next steps
276273

277-
[Configure cross-tenant access settings for B2B collaboration (Preview)](cross-tenant-access-settings-b2b-collaboration.md)
274+
[Configure cross-tenant access settings for B2B collaboration](cross-tenant-access-settings-b2b-collaboration.md)

articles/active-directory/external-identities/external-identities-overview.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ services: active-directory
77
ms.service: active-directory
88
ms.subservice: B2B
99
ms.topic: overview
10-
ms.date: 05/17/2022
10+
ms.date: 06/30/2022
1111
ms.author: mimart
1212
author: msmimart
1313
manager: celestedg
@@ -91,7 +91,7 @@ The following table gives a detailed comparison of the scenarios you can enable
9191

9292
Azure AD B2B collaboration and B2B direct connect are features Azure AD, and they're managed in the Azure portal through the Azure Active Directory service. To control inbound and outbound collaboration, you can use a combination of *cross-tenant access settings* and *external collaboration settings*.
9393

94-
### Cross-tenant access settings (Preview)
94+
### Cross-tenant access settings
9595

9696
Cross-tenant access settings let you manage B2B collaboration and B2B direct connect with other Azure AD organizations. You can determine how other Azure AD organizations collaborate with you (inbound access), and how your users collaborate with other Azure AD organizations (outbound access). Granular controls let you determine the people, groups, and apps, both in your organization and in external Azure AD organizations, that can participate in B2B collaboration and B2B direct connect. You can also trust multi-factor authentication (MFA) and device claims (compliant claims and hybrid Azure AD joined claims) from other Azure AD organizations.
9797

articles/active-directory/external-identities/faq.yml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
ms.service: active-directory
88
ms.subservice: B2B
99
ms.topic: faq
10-
ms.date: 05/06/2022
10+
ms.date: 06/30/2022
1111
ms.author: mimart
1212
author: msmimart
1313
manager: celestedg
@@ -58,7 +58,13 @@ sections:
5858
- question: |
5959
What if a partner organization already has multifactor authentication set up? Can we trust their multifactor authentication?
6060
answer: |
61-
[Cross-tenant access settings](cross-tenant-access-overview.md) (preview) let you trust multifactor authentication and device claims ([compliant claims and hybrid Azure AD joined claims](../conditional-access/howto-conditional-access-policy-compliant-device.md)) from other Azure AD organizations.
61+
[Cross-tenant access settings](cross-tenant-access-overview.md) let you trust multifactor authentication and device claims ([compliant claims and hybrid Azure AD joined claims](../conditional-access/howto-conditional-access-policy-compliant-device.md)) from other Azure AD organizations.
62+
63+
- question: |
64+
How many organizations can I add in cross-tenant access settings?
65+
answer: |
66+
Cross-tenant access settings are a policy in the directory that stores your settings for how you collaborate with other organizations. This policy file has a 25kb size limit and once it is maxed out, no additional organizations or changes can be made that would further increase the file size. Due to how we store the content in this policy, there is no defined limit of organizations you can add in cross-tenant access settings. If you need to apply settings to a large number of organizations, we recommend implementing those settings as your default settings. Follow the steps to [calculate the current size of your policy](troubleshoot.md#an-error-similar-to-failure-to-update-policy-due-to-object-limit-appears-while-configuring-cross-tenant-access-settings) and determine whether you are close to hitting the 25kb file size limit.
67+
6268
- question: |
6369
How can I use delayed invitations?
6470
answer: |

articles/active-directory/external-identities/index.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,15 +24,15 @@ landingContent:
2424
url: external-identities-overview.md
2525
- text: What is Azure AD B2B collaboration?
2626
url: what-is-b2b.md
27-
- text: What is Azure AD B2B direct connect? (preview)
27+
- text: What is Azure AD B2B direct connect?
2828
url: b2b-direct-connect-overview.md
2929
- text: What is Azure AD B2C (business-to-consumer) identity?
3030
url: ../../active-directory-b2c/overview.md
3131
- title: Collaborate with users outside your org (B2B collaboration)
3232
linkLists:
3333
- linkListType: concept
3434
links:
35-
- text: Cross-tenant access settings (preview)
35+
- text: Cross-tenant access settings
3636
url: cross-tenant-access-overview.md
3737
- text: B2B collaboration user properties
3838
url: user-properties.md

0 commit comments

Comments
 (0)