how would access to federated applications for external identities work (if possible)?

Rakesh Singh 250 Reputation points
2024-08-01T16:59:49.2166667+00:00

So, we have a Tenant A (source tenant) and a tenant B (target tenant) and we are synching users via Cross Tenant synch from A to B. We are synching them as userType: member, with home realm MFA and claims accepted by tenant B.
Now, question is: how would access to federated applications (on tenant B) for external identities work (if possible)? Can this be setup at all?

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,924 questions
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 36,886 Reputation points Microsoft Employee
    2024-08-07T20:56:22.1666667+00:00

    Hi @Rakesh Singh ,

    I have not yet heard back from my colleague on the External Identities team about this, but my understanding is that you are correct and this is not a supported scenario.

    Adding a federated OIDC identity provider is currently only supported in an Azure AD B2C tenant, which supports allowing sign in via external federated OIDC IDP identities.

    That said, there is a potential workaround available, which I will share with you in a private message on this thread.

    Under External Identities, you can invite B2B guest users via SAML\WS-Fed Federation feature (where OIDC is not supported).

     

    If you are planning to invite external users to the other Entra tenant, the recommended approach is to use B2B Guest Invitations: Add a guest user and send an invitation

    I am sending you a private message about an available option and you can confirm whether it meets your requirements! If you refresh the page and click on the private messaging feature under the original post, you would be able to see my message.

    If the information helped you, please Accept the answer. This will help us and improve searchability for others in the community who may be researching similar questions.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.