| # | Action | Notes |
|---|---|---|
| 1 | Navigate to the Entra Admin Centre | entra.microsoft.com |
| 2 | Sign in with your PRV (privileged) account | Never use a standard user account |
| 3 | Activate Global Administrator via PIM | Navigate to PIM → My Roles → Activate |
| # | Action | Notes |
|---|---|---|
| 1 | Navigate to Entra ID → External Identities → External collaboration settings | |
| 2 | Scroll down to the Collaboration restrictions section | This shows the current allow list of approved domains |
| # | Action | Notes |
|---|---|---|
| 1 | In the Collaboration restrictions text box, enter the partner's domain | e.g. supplier.com |
| 2 | Click Save at the top of the page | The domain is now added to the collaboration allow list |
| 3 | Verify the domain appears in the allow list |
Invitations sent to users whose domains are not in the allow list will be blocked. The inviting user will see an error indicating the recipient is not eligible for invitation. This is by design — it ensures R&R maintains tight control over which external organisations have any form of access to the tenant.
| # | Action | Notes |
|---|---|---|
| 1 | Confirm the partner has been designated as trusted by R&R security | This is a governance decision, not a technical one |
| 2 | Verify evidence of their tenant configuration has been provided and reviewed | e.g. Conditional Access policies, MFA methods, compliance posture |
| 3 | Obtain approval to proceed with inbound trust configuration | Document the approval in the change record |
| # | Action | Notes |
|---|---|---|
| 1 | Sign in with a PRV account and activate Security Administrator via PIM | If already elevated as Global Admin from Section A, this role is included |
| 2 | Navigate to Entra ID → External Identities → External collaboration settings | |
| 3 | Locate the Organizational settings section | This lists organisations with specific cross-tenant policies |
| # | Action | Notes |
|---|---|---|
| 1 | Under Organizational settings, click Add organization | |
| 2 | Enter the partner's domain name in the search box | e.g. supplier.com |
| 3 | Wait for the tenant details to populate | Entra will resolve the domain to the partner's tenant ID and name |
| 4 | Click Add | The organisation now appears in the Organizational settings list |
| # | Action | Notes |
|---|---|---|
| 1 | Click the hyperlink under Inbound access for the partner | It will typically read "Inherited from default" |
| 2 | Navigate to the Trust settings tab | |
| 3 | Select Customize settings | This overrides the default and allows per-organisation configuration |
| # | Action | Notes |
|---|---|---|
| 1 | Tick "Trust multifactor authentication from Microsoft Entra tenants" | This is the primary setting — enables MFA claims passthrough |
| 2 | Review whether additional trust checkboxes are required | See the available claims below |
| 3 | Click Save | Changes take effect immediately for the partner organisation |
Available Inbound Trust Claims: