What's changed: Created SC-300 Chapter 2 (Domain 1 second-half: External ID/B2B collaboration/External collaboration settings/Cross-tenant access settings/cross-tenant sync; external IdP/direct federation/SAML/WS-Fed/social IdP; hybrid identity: Entra Connect Sync/Cloud Sync/PHS/PTA/seamless SSO/Connect Health/AD FS migration).
2.1External ID, B2B collaboration, and cross-tenant access
Understand inviting/managing external users with Microsoft Entra External ID (B2B collaboration), External collaboration settings, Cross-tenant access settings, and cross-tenant synchronization.
Organizations must collaborate securely with external partners/vendors. Microsoft Entra External ID B2B collaboration invites external people "with their existing identity," granting access without your managing their passwords.
2.1.1B2B invitations and external collaboration settings
Invite external users as guests (individually or in bulk). External collaboration settings control "who can invite guests," "guest permissions," and "which domains are allowed/blocked (allow/deny lists)." Govern guests with Conditional Access and access reviews, and expire them via external-user lifecycle when no longer needed. The principle: invite external people securely and do not leave them unmanaged.
2.1.2Cross-tenant access and synchronization
For organizations with multiple Entra tenants (mergers, affiliates), Cross-tenant access settings finely control "inbound/outbound access" and "trusting the other tenant’s MFA/device-compliance claims" per partner tenant. Cross-tenant synchronization then auto-provisions users from one tenant into another as B2B guests, removing manual invitations. For "automatically share users between two tenants," use cross-tenant sync.
Cues: "invite external partners with their identity" = B2B collaboration (guests). "who can invite / allowed domains" = External collaboration settings. "trust the other tenant’s MFA / control inbound-outbound" = Cross-tenant access settings. "auto-share users between two tenants" = cross-tenant synchronization.
Watch the mix-ups: (1) Distinguish B2B (invite external people) from B2C/External ID for customers (identities for consumer apps). (2) Cross-tenant access settings (trust/access control) differ from cross-tenant sync (auto-provisioning users). (3) Apply CA/access reviews to guests—do not invite and forget.
2.1.3Section summary
- B2B collaboration = invite external people as guests with their identity; control inviters/allowed domains via External collaboration settings
- Cross-tenant access settings = per-tenant trust/inbound-outbound control; cross-tenant sync = auto B2B-provision users
- Apply CA/access reviews/lifecycle to guests—do not leave them unmanaged
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to invite a partner company’s employees with their existing identity (no password management on your side) to access certain apps. Which is best?
Q2. After a merger you have two Entra tenants and want users from one auto-provisioned into the other as B2B guests without manual invites. Which is best?
Q3. You want to trust MFA performed by a partner tenant so your tenant does not require MFA again. Which is best?
Q4. You want to allow guest invitations only from certain trusted domains and block others. Which is best?
Q5. What is the best practice when an invited guest’s access is no longer needed?

