Using Azure B2B for our Customer portal

%3CLINGO-SUB%20id%3D%22lingo-sub-2554312%22%20slang%3D%22en-US%22%3EUsing%20Azure%20B2B%20for%20our%20Customer%20portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2554312%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20community%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20our%20mechanical%20engineering%20company%20we%20are%20building%20a%20customer%20portal%2C%20where%20our%20customers%20should%20find%20their%20documentation%20for%20their%20equipment.%3C%2FP%3E%3CP%3EThis%20documentation%20is%20natively%20hosted%20in%20our%20SharePoint%20Online.%20Here%20we%20create%20a%20site%20collection%20for%20each%20machine%20where%20all%20documentation%20is%20hosted.%3C%2FP%3E%3CP%3ETo%20provide%20the%20customer%20access%20to%20those%20documents%2C%20we%20would%20create%20a%20web%20application%20where%20the%20customer%20has%20to%20sign%20in%20with%20Azure%20B2B%20(not%20B2C).%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20the%20sign%20in%20process%20the%20user%20will%20automatically%20be%20added%20as%20a%20guest%20with%20visit-permission%20to%20the%20site%20collections%20of%20all%20the%20machines%20they%20have.%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20user%20would%20not%20directly%20visit%20the%20site%20collection%2C%20but%20a%20REST-call%20to%20fetch%20the%20documents%20with%20their%20metadata%20should%20work%20to%20display%20the%20files%20in%20our%20own%20web%20application.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EImportant%3A%20Customers%20can%20also%20invite%20other%20users%20of%20their%20own%20organisation%20to%20give%20other%20employees%20access%20to%20the%20portal.%20We%20could%20use%20the%20B2B%20API%20for%20this.%3C%2FP%3E%3CP%3EEverytime%20the%20customer%20%22adds%22%20a%20new%20user%2C%20this%20user%20will%20be%20added%20as%20a%20guest%20and%20will%20be%20added%20automatically%20also%20to%20the%20same%20site%20collections.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20the%20skills%20to%20develop%20something%20like%20that.%20Only%20question%3A%20Is%20Azure%20B2B%20made%20for%20this%3F%20Can%20we%20do%20it%20like%20this%3F%3C%2FP%3E%3CP%3EIn%20Azure%20B2C%20no%20access%20to%20SharePoint%20Online%20(or%20generally%20365)%20is%20possible.%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20this%20reason%20I%20hope%20that%20our%20approach%20can%20work.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20using%20Azure%20B2C%20we%20would%20have%20to%20write%20our%20own%20service%20that%20accesses%20SharePoint%20in%20the%20background%20via%20client%20credential%20flow%20(with%20a%20certificate)%20and%20return%20the%20docs%20through%20this%20%22reroute%22.%20This%20approach%20is%20harder%20and%20would%20also%20not%20allow%20the%20customer%20to%20visit%20SharePoint.%20But%20in%20this%20case%20users%20would%20not%20have%20to%20be%20guest%20users...%20We%20could%20clearly%20seperate%20%22internal%22%20and%20%22guest%20users%22%20with%20two%20different%20tenants.%20Nevertheless%3A%20I%20prefer%20the%20first%20approach.%26nbsp%3BWhat%20do%20you%20think%3F%20Any%20security%20concerns%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor
Dear community,
 
In our mechanical engineering company we are building a customer portal, where our customers should find their documentation for their equipment.
This documentation is natively hosted in our SharePoint Online. Here we create a site collection for each machine where all documentation is hosted.
To provide the customer access to those documents, we would create a web application where the customer has to sign in with Azure B2B (not B2C). 
After the sign in process the user will automatically be added as a guest with visit-permission to the site collections of all the machines they have. 
The user would not directly visit the site collection, but a REST-call to fetch the documents with their metadata should work to display the files in our own web application. 
 
Important: Customers can also invite other users of their own organisation to give other employees access to the portal. We could use the B2B API for this.
Everytime the customer "adds" a new user, this user will be added as a guest and will be added automatically also to the same site collections.
 
We have the skills to develop something like that. Only question: Is Azure B2B made for this? Can we do it like this?
In Azure B2C no access to SharePoint Online (or generally 365) is possible. 
For this reason I hope that our approach can work. 
 
When using Azure B2C we would have to write our own service that accesses SharePoint in the background via client credential flow (with a certificate) and return the docs through this "reroute". This approach is harder and would also not allow the customer to visit SharePoint. But in this case users would not have to be guest users... We could clearly seperate "internal" and "guest users" with two different tenants. Nevertheless: I prefer the first approach. What do you think? Any security concerns?
0 Replies