Azure VM & AAD of another tenancy

Rob Brown 26 Reputation points
2022-11-16T15:15:53.867+00:00

One of my C-Suite has asked/instructed for something to be done which I'm not sure is possible and I'm looking for some confirmation.

VM-1 is in Tenancy Alpha, with AAD alpha.com

C-Suite wants VM-1 to remain in Tenancy Alpha but be connected to Tenancy Beta's AAD Beta.co.uk

To the best of my knowledge, you can't have a VM use an AAD from a totally different tenancy?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,130 questions
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
666 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,473 questions
0 comments No comments
{count} votes

Accepted answer
  1. Vasileios Dionysopoulos 456 Reputation points
    2022-11-16T15:29:44.89+00:00

    Hi,

    You can do it with Azure b2b collaboration, but it is a bit of mess, before you continue with any configuration you have to design it, in order to avoid security leaks.

    If is the same as you do a forest trust between forest domains.

    Below you will find a link with the appropriate documentation:
    https://learn.microsoft.com/en-us/azure/active-directory/external-identities/what-is-b2b

    After you make the configuration you can use the resources from the other tenant to the VM or any other resources.

    Last but not least check also the limitations.

    BR,


2 additional answers

Sort by: Most helpful
  1. Rob Brown 26 Reputation points
    2022-11-16T15:33:53.393+00:00

    nods no native option though - and I really have no desire to go down any route that makes life harder than it needs to be. No benefit to be had there really.

    Moving the VM(s) and associated components would be less grief.

    0 comments No comments

  2. Vasileios Dionysopoulos 456 Reputation points
    2022-11-16T15:36:43.9+00:00

    Yes I agree totally with you...
    It is a mess :)

    0 comments No comments