Forum Discussion
User classed as internal or external for Azure AD P2.
Yes there are still questions. Please understand I am referring specifically about users in tenant (A) accessing resources in tenant (B) as external (guest) users. Note also that the customer owns both tenants. External users would be activating PIM roles to manage Azure resources.
Rahul mentions this "they might not require an assigned Azure AD P2 license in the separate tenant (B) if they are only accessing resources there as guests." and also comments that I should engage with a Microsoft or a licensing specialist who can provide guidance. Hence my follow up question.
In this case, are the users from tenant (A) classed as external in tenant (B) and can these external users benefit from the full AAD P2 features, according to this document?
Pricing - Active Directory External Identities | Microsoft Azure
Thanks,
Nick
Where Azure AD P2, specifically PIM is concerned, are the (A) users classed as external and therefore do not require an assigned AAD P2 license?
As stated in my initial reply to your post, to use Privileged Identity Management (PIM) in Azure Active Directory (Azure AD), part of Microsoft Entra, each tenant must have a valid license. Licenses must also be assigned to the administrators and relevant users. Here is the link that I originally provided for your convenience - License requirements to use Privileged Identity Management - Microsoft Entra | Microsoft Learn
This is because for Azure resource roles in Privileged Identity Management (PIM), only a subscription administrator, a resource Owner, or a resource User Access administrator can manage assignments for other administrators. Users who are Privileged Role Administrators, Security Administrators, or Security Readers don't by default have access to view assignments to Azure resource roles in Privileged Identity Management. What is Privileged Identity Management? - Microsoft Entra | Microsoft Learn
"Please understand I am referring specifically about users in tenant (A) accessing resources in tenant (B) as external (guest) users. Note also that the customer owns both tenants."
Yes, I understand that you have multiple tenants under the same organization.
"In this case, are the users from tenant (A) classed as external in tenant (B) and can these external users benefit from the full AAD P2 features, according to this document?
Pricing - Active Directory External Identities | Microsoft Azure"
External Identities is a set of capabilities that enables organizations to secure and manage any external user, including customers and partners.
The link that you provided in your post contains documentation about B2B Collaboration capability of Azure AD External Identities, where you can invite guest users to collaborate with your organization, but you should carefully review the details to understand what B2B Collaboration provides as the information does not mention PIM.
Here is how I found the documentation using your link:
Resource: please find addt'l links on the tree to the left of the webpage:
If this (or someone else's) reply answers your question, please Accept as the solution to help the other members find it more quickly. Otherwise, please let me know if you need further assistance on this topic.
Regards,
Microsoft CSP Licensing Concierge
- Nick_BeacroftJun 18, 2023Steel Contributor
Thanks for the additional documentation links.
Having read these, B2B collaboration includes entitlement management for invited guest members.
https://learn.microsoft.com/en-us/azure/active-directory/external-identities/external-identities-overview#comparing-external-identities-feature-setsWhat is entitlement management? - Microsoft Entra | Microsoft Learn
Entitlement management provides guest users to request and approve access to access packages.
This document also describes the tenant as the licensing boundary.
What is a multi-tenant organization in Azure Active Directory? - Microsoft Entra | Microsoft Learn
Therefore, I have concluded that at least one Azure AD P2 license is required in the non-primary tenant (B) to activate the P2 features.
Users in tenant (A) invited as guest members to tenant (B) may use AAD P2 features as external users, and benefit from the MAU pricing model for external users.