Share via

Trust device from TenantA for conditional Access on TenantB with a user from TenantB

Adrien Maugard 121 Reputation points
2023-06-06T15:25:54.34+00:00

Hello all,

I have two existing tenants:

  1. TenantA - Work tenant, containing all my data and services.
  2. TenantB - Admin tenant, containing our tools for our IT activity toward our customers.

Both tenants have their own AD, name, AD Connect, nothing is linked.

All our devices are registered in TenantA and managed for access our company data and such. Conditional Access is in place in this TenantA with MFA requirement and other stuffs.

I need to secure TenantB to require both MFA/Passwordless AND a compliant device (for example my TenantA laptop...)

I searched for the B2B Collaboration inbound Trusted device setting, but it seems limited to TenantA users themselves that are NOT allowed on TenantB (strictly no guest on TenantB) so this setting seem to have no effect on my conditional acces.

Is there a solution? Or should I start building VMs on my laptops to solve the issue?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Intune | Other
0 comments No comments

Answer accepted by question author

Vasil Michev 127K Reputation points MVP Volunteer Moderator
2023-06-06T16:00:47.1+00:00

There's no way to establish such trust without having the users represented in some form in both tenants. Using the recently released cross-tenant sync you can provision them either as Guests or Members, but a matching user account must exist before you can configure the Trust settings.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.