Cross-Tenant Inbound Domain Addition
This guide will show an administrator how to allow designated domains to have shared access to internal resources.
Role Requirements
Procedure Scope: Administrators
Required Group Membership: Admin.Collaboration
Handbook Reference
Package: Collaboration Security
Domain: B2B Collaboration Management
Modifies: Allowed Inbound B2B Organizations
![]()
Tenant Collaboration Inbound B2B Domain Addition
- Navigate to the Cross-Tenant Access Settings – Azure Active Directory portal, from the Organizational Settings tab locate and select the external organization entry from the list below, select the Configured item under the Inbound Access column for the entry.

- Select the B2B Collaboration tab, followed by Customize Settings. Select Allow Access for the External Users and Groups tab, make sure to also select Allow Access for the External Applications tab. Select Save at the bottom of the page to finalize the addition.

- After the B2B collaboration settings have been saved, we will select the Trust settings tab. From here we will select the Customize settings option. We will want to toggle the Trust multifactor authentication from Microsoft Entra tenants option on, as well as the Automatically redeem invitations with the tenant [External Tenant Name]. Select Save at the bottom of the page to finalize the addition.

- This organization-specific entry intentionally overrides your tenant's default B2B block to grant sanctioned inbound access for the partner tenant, trusts their MFA claim so external users aren't forced through a redundant registration campaign for your tenant, and auto-redeems consent given that the SharePoint guest workflow only surfaces shared site and file/folder resources.
Need Assistance?
Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? Inquire about arranging a consultation to explore optimizing your Azure environment for painless management.
