Houses of Parliament
Restoration & Renewal
External IdAM — B2B Configuration
Houses of Parliament Restoration & Renewal
External IdAM

B2B Collaboration Entra ID Partners

A step-by-step guide for onboarding new supplier organisations as B2B collaboration partners in R&R's Entra ID tenant — covering domain whitelisting, cross-tenant trust configuration, and inbound MFA claims so guest users can authenticate seamlessly with their home credentials.

Cross-Tenant Access · Collaboration Allow List · Inbound MFA Trust Entra-to-Entra Trust B2B Collaboration Inbound MFA Claims Cross-Tenant Access Version 1.0 Author: Koz Georgiou
Completion
0 / 8
Background & Purpose
What is Entra ID B2B Collaboration?

When R&R works with external suppliers who use Microsoft Entra ID (formerly Azure AD) as their identity provider, those suppliers' users can be invited as B2B collaboration guests into R&R's tenant. This allows them to access shared resources — SharePoint sites, Teams channels, applications — while authenticating with their own organisation's credentials.

However, R&R operates a collaboration allow list, meaning only pre-approved domains can receive B2B invitations. This guide covers two processes: adding a domain to the allow list so invitations can be sent, and configuring inbound cross-tenant trust so the partner's MFA claims are accepted — eliminating the need for guest users to register a separate R&R MFA token.

B2B Collaboration Onboarding Flow
Whitelist
Supplier DomainAllow list
Add Organisation
to Cross-TenantOrg settings
Configure Inbound
MFA TrustClaims passthrough
Invite Guest
UsersB2B invitations
🔐
Prerequisites & Required Permissions
Allow List ChangesGlobal Administrator, activated via PIM using a PRV account
Cross-Tenant TrustSecurity Administrator (minimum), activated via PIM using a PRV account
PortalEntra Admin Centre — entra.microsoft.com
Partner DomainThe exact domain name of the partner organisation (e.g. supplier.com)
Security EvidenceFor inbound MFA trust: evidence that the partner's Entra tenant meets R&R security requirements
Section A — Add Domain to Collaboration Allow List
1
Sign In with PRV Account & Elevate to Global Administrator
entra.microsoft.com
💡 Why is this step needed?
The collaboration allow list is a tenant-wide security boundary that controls which external organisations can receive B2B invitations. Modifying it requires Global Administrator privileges — the highest role in Entra ID — because changes directly affect who can be invited into the R&R tenant. Using a PRV account with PIM activation ensures this powerful access is time-limited and fully audited.
#ActionNotes
1Navigate to the Entra Admin Centreentra.microsoft.com
2Sign in with your PRV (privileged) accountNever use a standard user account
3Activate Global Administrator via PIMNavigate to PIM → My Roles → Activate
2
Navigate to External Collaboration Settings
External Identities
💡 Why is this step needed?
External Collaboration Settings is the central policy blade in Entra ID that governs all B2B collaboration behaviour for the R&R tenant — including who can be invited, what roles guests receive, and which domains are allowed or blocked. The allow list is managed within the Collaboration restrictions section of this blade.
#ActionNotes
1Navigate to Entra ID → External Identities → External collaboration settings
2Scroll down to the Collaboration restrictions sectionThis shows the current allow list of approved domains
3
Add the Partner Domain to the Allow List
Collaboration restrictions
💡 Why is this step needed?
R&R uses a domain allow list model for B2B collaboration — only users from explicitly approved domains can be invited as guests. This is a security decision: rather than allowing invitations to any organisation and blocking specific threats (a deny list), R&R takes a zero-trust approach where every partner must be pre-approved. Adding a domain to the allow list is the gate that permits B2B invitations to be sent to users at that domain.
#ActionNotes
1In the Collaboration restrictions text box, enter the partner's domaine.g. supplier.com
2Click Save at the top of the pageThe domain is now added to the collaboration allow list
3Verify the domain appears in the allow list
🚫
What happens if a domain is NOT on the allow list?
Invitations sent to users whose domains are not in the allow list will be blocked. The inviting user will see an error indicating the recipient is not eligible for invitation. This is by design — it ensures R&R maintains tight control over which external organisations have any form of access to the tenant.
✔ What happens next?
Users from the approved domain can now be invited as B2B collaboration guests into R&R's tenant. They will receive an invitation email and can redeem it to access the resources they are aligned with. However, without inbound MFA trust (Section B), they may be required to register a separate MFA token for R&R.
Section B — Configure Inbound Cross-Tenant Trust
4
Verify the Partner Meets R&R Security Requirements
Pre-check
💡 Why is this step needed?
Configuring inbound MFA trust means R&R will accept the partner's MFA claims as valid — effectively trusting that the partner's Entra tenant enforces MFA to a standard equivalent to R&R's own policies. If the partner's MFA configuration is weak (e.g. SMS-only, no Conditional Access, no number matching), trusting their claims would weaken R&R's security posture. Evidence of sufficient security configuration must be provided and reviewed before trust is established.
#ActionNotes
1Confirm the partner has been designated as trusted by R&R securityThis is a governance decision, not a technical one
2Verify evidence of their tenant configuration has been provided and reviewede.g. Conditional Access policies, MFA methods, compliance posture
3Obtain approval to proceed with inbound trust configurationDocument the approval in the change record
⚠ Security Gate — Do Not Skip
Inbound trust is not automatic and should not be configured for every partner. Only partners that have demonstrated their tenant meets R&R's security bar should have inbound claims enabled. Configuring trust for an insecure partner creates a bypass of R&R's MFA Conditional Access policies.
5
Elevate to Security Administrator & Navigate to Cross-Tenant Settings
entra.microsoft.com
💡 Why is this step needed?
Cross-tenant access settings — including inbound trust — are managed under External Collaboration Settings in Entra ID. This section requires at least Security Administrator role. This is a different (lower) privilege level than the Global Administrator required for the allow list in Section A, following the principle of least privilege.
#ActionNotes
1Sign in with a PRV account and activate Security Administrator via PIMIf already elevated as Global Admin from Section A, this role is included
2Navigate to Entra ID → External Identities → External collaboration settings
3Locate the Organizational settings sectionThis lists organisations with specific cross-tenant policies
6
Add the Partner Organisation
Organizational settings
💡 Why is this step needed?
Before configuring inbound trust, the partner's Entra ID tenant must be registered as a named organisation in R&R's cross-tenant access settings. This creates a per-organisation policy override — without it, the partner would inherit the default inbound settings which do not include MFA trust. Adding the organisation enables you to configure custom inbound policies specifically for that partner.
#ActionNotes
1Under Organizational settings, click Add organization
2Enter the partner's domain name in the search boxe.g. supplier.com
3Wait for the tenant details to populateEntra will resolve the domain to the partner's tenant ID and name
4Click AddThe organisation now appears in the Organizational settings list
ℹ Tenant Resolution
When you enter the domain, Entra automatically looks up the associated tenant ID and display name. If the domain does not resolve, it may not be verified in the partner's Entra tenant — confirm the correct domain with the partner before proceeding.
7
Open Inbound Access & Navigate to Trust Settings
Organizational settings
💡 Why is this step needed?
Each organisation in the cross-tenant settings has its own Inbound access policy — this controls what R&R will accept from incoming users from that tenant. By default, new organisations inherit the default settings (which do not include MFA trust). You must switch to Customize settings to configure trust policies that are specific to this partner.
#ActionNotes
1Click the hyperlink under Inbound access for the partnerIt will typically read "Inherited from default"
2Navigate to the Trust settings tab
3Select Customize settingsThis overrides the default and allows per-organisation configuration
8
Enable Inbound MFA Trust & Save
Trust settings
💡 Why is this step needed?
This is the critical configuration step. Enabling "Trust multifactor authentication from Microsoft Entra tenants" tells R&R's Conditional Access engine to accept MFA claims that the partner's tenant passes through the cross-tenant connection. Without this, guest users from the partner organisation would be prompted to complete MFA again using an R&R-registered method — which typically means registering a separate authenticator app, creating friction and support overhead. With trust enabled, the partner's MFA satisfies R&R's policies seamlessly.
#ActionNotes
1Tick "Trust multifactor authentication from Microsoft Entra tenants"This is the primary setting — enables MFA claims passthrough
2Review whether additional trust checkboxes are requiredSee the available claims below
3Click SaveChanges take effect immediately for the partner organisation

Available Inbound Trust Claims:

MFA Trust
Accept the partner's MFA claims — guest users don't need to re-register MFA for R&R
✦ Primary — Enable for approved partners
Compliant Device
Accept the partner's device compliance claims from their Intune policies
◇ Optional — if R&R CA requires device compliance
Hybrid Joined Device
Accept claims that a device is Hybrid Azure AD Joined in the partner's tenant
◇ Optional — if R&R CA requires hybrid join
✔ Configuration Complete
The partner organisation is now fully configured for B2B collaboration. Their domain is on the allow list (Section A) and inbound MFA trust is enabled (Section B). When guest users from this organisation are invited and access R&R resources, they will be able to sign in with their home credentials and their home MFA will satisfy R&R's Conditional Access policies — no separate R&R MFA registration required.
ℹ How it works at sign-in
When a guest user from the trusted partner accesses an R&R resource, they are redirected to their home tenant to authenticate. Their home tenant handles username/password and MFA. The resulting token includes an MFA claim which is passed back to R&R's Entra via the cross-tenant trust. R&R's Conditional Access policy evaluates this claim and — because trust is configured — accepts it as valid, granting access without a second MFA prompt.