You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/fundamentals/5-secure-access-b2b.md
+8-10Lines changed: 8 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,13 +33,11 @@ Use the information in this article to move external collaboration into Azure Ac
33
33
34
34
You can limit the organizations your users collaborate with (inbound and outbound), and who in your organization can invite guests. Most organizations permit business units to decide collaboration, and delegate approval and oversight. For example, organizations in government, education, and financial often don't permit open collaboration. You can use Azure AD features to control collaboration.
35
35
36
-
You can control access your tenant:
36
+
You can control access your tenant, by deploying one or more of the following solutions:
37
37
38
38
-**External Collaboration Settings** – Restrict the email domains that invitations got to
39
-
-**Cross Tenant Access Settings** – Control application access by guests by user, group, or tenant (inbound). Control external Azure AD tenant and application access for users (outbound).
40
-
-**Connected Organizations** – Determine what organizations can request Access Packages in Entitlement Management.
41
-
42
-
You can deploy one or more of these solutions.
39
+
-**Cross Tenant Access Settings** – Control application access by guests by user, group, or tenant (inbound). Control external Azure AD tenant and application access for users (outbound)
40
+
-**Connected Organizations** – Determine what organizations can request Access Packages in Entitlement Management
43
41
44
42
### Determine collaboration partners
45
43
@@ -48,7 +46,7 @@ Document the organizations you collaborate with, and organization users' domains
48
46
If your users use Azure AD B2B, you can discover the external Azure AD tenants they're collaborating, with via the sign-in logs, PowerShell, or a workbook. Learn more:
@@ -92,7 +90,7 @@ You can block access to tenants (blocklist). Set the default policy to Allow and
92
90
93
91
To control external organizations users access, configure outbound access policies similarly to inbound access: allowlist and blocklist. Configure default and organization-specific policies.
94
92
95
-
Learn more: [Configure cross-tenant access settings for B2B collaboration](../external-identities/cross-tenant-access-settings-b2b-collaboration.md).
93
+
Learn more: [Configure cross-tenant access settings for B2B collaboration](../external-identities/cross-tenant-access-settings-b2b-collaboration.md)
96
94
97
95
> [!NOTE]
98
96
> Cross Tenant Access Settings apply to Azure AD tenants. To control access for partners not using Azure AD, use External Collaboration Settings.
@@ -152,7 +150,7 @@ Invited guest users from a collaboration partner can have trouble redeeming an i
152
150
153
151
## External users access
154
152
155
-
Generally, there are resources you can share with external users, and some you can't. You can control what external users access. [Manage external access with Entitlement Management](6-secure-access-entitlement-managment.md).
153
+
Generally, there are resources you can share with external users, and some you can't. You can control what external users access. See, [Manage external access with Entitlement Management](6-secure-access-entitlement-managment.md).
156
154
157
155
By default, guest users see information and attributes about tenant members and other partners, including group memberships. Consider limiting external user access to this information.
158
156
@@ -216,9 +214,9 @@ Sharing through SharePoint and OneDrive adds users not in the Entitlement Manage
216
214
*[Secure external access to Microsoft Teams, SharePoint, and OneDrive for Business](9-secure-access-teams-sharepoint.md)
217
215
*[Block OneDrive use from Office](/office365/troubleshoot/group-policy/block-onedrive-use-from-office.md)
218
216
219
-
### Send documents through email
217
+
### Documents in email
220
218
221
-
Users send documents to external users by email. You can use sensitivity labels to restrict and encrypt access to documents. [Learn about Sensitivity labels.](/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide&preserve-view=true).
219
+
Users send documents to external users by email. You can use sensitivity labels to restrict and encrypt access to documents. See, [Learn about sensitivity labels](/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide&preserve-view=true).
0 commit comments