Topologies for cross-tenant synchronization

Cross-tenant synchronization provides a flexible solution to enable collaboration, but every organization is different. Each cross-tenant synchronization configuration provides one-way synchronization between two Microsoft Entra tenants, which enables configuration of the following topologies.

Single source with a single target

The following example shows the simplest topology where users in a single tenant need access to applications in the parent tenant.

Diagram that shows a single source tenant synchronizing with a single target tenant.

Single source with multiple targets

The following example shows a central user hub tenant where users need access to applications in smaller resource tenants across your organization.

Diagram that shows a source tenant synchronizing with multiple target tenants.

Multiple sources with a single target

The following example shows recently acquired tenants where users in multiple tenants need access to applications in the parent tenant.

Diagram that shows multiple source tenants synchronizing with a single target tenant.

Mesh peer-to-peer

Your organization might be more complex that is similar to a mesh. The following example shows a topology where users flow across tenants in their organization. This topology is often used to enable people search scenarios where every user needs to be in every tenant to have a unified gallery.

Diagram that shows a hybrid topology synchronizing with multiple tenants.

Cross-tenant synchronization is one way. An internal member user can be synchronized into multiple tenants as an external user. When the topology shows a synchronization going in both directions, it's a distinct set of users in each direction and each arrow is a separate configuration.

Next steps