Forum Discussion
Teams Client, Guest User access, Separate Tenant
Hey Team,
I am trying to figure out what i am missing here. This is what we have.
- 2x Tenants with Enterprise E3 licenses
- Some user accounts are sync'd between the 2 tenants, not all users
We have added a guest user, and we need his account to be able to access our Tenants teams. When he goes to the Teams Web Client, he sees his org and ours.
However in the teams fat client, he is not able to switch from his home tenant (tenant.com) to our tenant (tenant-business.com).
My question is how do i get our tenant to show up in his teams client? I tried having him login using his #EXT# guest account, but it requires a password.
Thanks,
Robert
2 Replies
- Ahmed_Masoud97Steel Contributor
Check Entra ID, Users, search his email. Guest type, UPN ending #EXT#@tenant-business.onmicrosoft.com, means he's properly invited. Not there means he never was, and that's your answer right there.
Works on web, fails on desktop switcher, is almost always one of these:
Cross tenant access settings aren't allowing B2B inbound on your side, or outbound on his. Both need to agree.
His home tenant blocks external Teams orgs on desktop. Common default.
He's logging in with the #EXT# UPN and a password. Won't work, those accounts don't have one. He needs to log in through his home identity.
Verify the guest object exists. Check External Identities, Cross tenant access settings, set inbound to Allow for his domain. He needs to check outbound on his end.
His login flow: Teams desktop, profile picture, Add another account, sign in with his normal home credentials. No separate password. Your org should then appear in the switcher.
Two E3 tenants syncing is a good opening for a cross tenant access review and a B2B governance framework. Also worth raising guest lifecycle management via Entra ID Governance or PIM.
Don't let him try #EXT# credentials directly. Don't assume web access means B2B trust is configured. Don't skip his home tenant's outbound settings, that's the half you can't see.
What does his entry show in your guest list?
Take this:
- Ensure Guest Access is Enabled: Verify that guest access is enabled in both tenants. You can do this in the Teams Admin Center under Guest Access settings.
- Use the Correct Account: When logging into the Teams desktop client, ensure the guest user is using their guest account (e.g., #EXT#email address removed for privacy reasons). If it requires a password, make sure the guest user knows it or reset it if necessary.
- Switching Tenants: In the Teams desktop client, the guest user should be able to switch between tenants. They can do this by clicking on their profile picture in the top right corner and selecting the tenant they want to switch to.
- Shared Channels: If you want the guest user to access resources without switching tenants, consider using Shared Channels. This feature allows users to access cross-tenant resources without needing to switch tenants.
- Check Permissions: Ensure the guest user has the necessary permissions to access the teams and resources in your tenant.