B2B with clients

%3CLINGO-SUB%20id%3D%22lingo-sub-108230%22%20slang%3D%22en-US%22%3EB2B%20with%20clients%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-108230%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20investigating%20how%20to%20take%20B2B%20into%20use%20with%20our%20clients.%20Many%20of%20our%20clients%20are%20smaller%20companies%20who%20don't%20have%20AAD%20in%20use%20or%20even%20IT-know-how%20what%20it%20is.%20Now%20if%20we%20invite%20some%20client%20users%20as%20Guests%20to%20the%20MS%20Teams%20for%20example%2C%20then%20viral%20un-managed%20AAD%20would%20be%20spinned%20off%20(if%20they%20don't%20have%20AAD).%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20like%20to%20know%20has%20anyoney%20communicated%20this%20with%20your%20client%20org's%20and%20their%20IT%20departments%20and%20what%20is%20the%20general%20response%20if%20you%20go%20to%20them%20saying%20%22we%20will%20invite%20your%20users%20to%20our%20system%20and%20it%20will%20generate%20un-managed%20user%20directory%20to%20MS%20cloud%20with%20your%20domain%20name.%20You%20can%20then%20take%20over%20it%20if%20you%20want%20but%20it%20will%20on%20you%22%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20any%20way%20to%20check%20if%20the%20user%20still%20works%20(user%20ID%20enabled)%20with%20our%20client%20if%20the%20AAD%20stays%20un-managed%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-108230%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%20B2B%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-123448%22%20slang%3D%22en-US%22%3ERe%3A%20B2B%20with%20clients%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-123448%22%20slang%3D%22en-US%22%3E%3CP%3EYou're%20correct.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20tested%20this%20again%2C%20and%20when%20user%20has%20no%20Microsoft%20account%20or%20Azure%20AD%20account%2C%20clicking%20%22getting%20started%22%20on%20invite%20e-mail%20redirects%20you%20to%20%22sign%20up%20with%20Microsoft%22%20page%2C%20and%20let's%20you%20create%20a%20new%20account.%20I%20assumed%20it%20meant%20%22Microsoft%20account%22%2C%20but%20no%20it%20doesnt.%20Microsoft%20should%20be%20more%20clear%20about%20this.%20Also%20on%20documentation%20side%2C%20as%20they%20was%20when%20they%20initially%20released%20Azure%20AD%20B2B%20preview%20maybe%20two%20years%20ago.%20Now%20when%20you%20look%20under%20%22integrate%20parners%20using%20Azure%20AD%20B2B%22%20topic%20on%20MS%20documentation%2C%20you%20don't%20find%20much%20information%20about%20this%20scenario%20if%20none.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESorry%20I%20can't%20answer%20your%20original%20question.%20I'm%20also%20interested%20to%20hear%20how%20this%20is%20communicated%20to%20clients.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-123097%22%20slang%3D%22en-US%22%3ERe%3A%20B2B%20with%20clients%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-123097%22%20slang%3D%22en-US%22%3EInstead%20of%20%22unmanaged%20tenant%22%20they%20use%20wording%20%22viral%22%20and%20%22Just-in-time%22%20-%20but%20the%20concept%20has%20not%20changed.%20If%20the%20user's%20org%20does%20not%20have%20AAD%2C%20Microsoft%20will%20spin-up%20AAD%20for%20them%20and%20will%20leave%20it%20unmanaged%20until%20the%20org%20takes%20it%20over.%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Factive-directory-self-service-signup%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Factive-directory-self-service-signup%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-122498%22%20slang%3D%22en-US%22%3ERe%3A%20B2B%20with%20clients%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-122498%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20current%20release%20of%20Azure%20AD%20B2B%2C%20concept%20of%20%22unmanaged%20tenant%22%20you%20saw%20previously%2C%20doesn't%20exist%20anymore.%3C%2FP%3E%3CP%3ESee%20e.g.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Factive-directory-b2b-user-properties%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Factive-directory-b2b-user-properties%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-120044%22%20slang%3D%22en-US%22%3ERe%3A%20B2B%20with%20clients%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-120044%22%20slang%3D%22en-US%22%3EDoes%20anyone%20have%20experience%20of%20real%20life%20scenarios%20of%20using%20Azure%20B2B%20with%20real%20clients%2Fpartners%3F%20And%20especially%20with%20smaller%2Fmedium%20size%20companies%20who%20don't%20have%20MS%20infrastructure%20in%20use%20(Office%20365%2C%20AAD)%20and%20how%20these%20clients%20have%20welcomed%20the%20unmanaged%20Azure%20AD%20which%20is%20created%20for%20them.%20What%20if%20the%20customer%20does%20not%20have%20any%20capable%20IT%20personnel%20to%20take-over%20the%20unmanaged%20Azure%20directory%20(this%20is%20the%20case%20with%20many%20smaller%20comapnies)%3F%3C%2FLINGO-BODY%3E
Contributor

We are investigating how to take B2B into use with our clients. Many of our clients are smaller companies who don't have AAD in use or even IT-know-how what it is. Now if we invite some client users as Guests to the MS Teams for example, then viral un-managed AAD would be spinned off (if they don't have AAD). 

 

I would like to know has anyoney communicated this with your client org's and their IT departments and what is the general response if you go to them saying "we will invite your users to our system and it will generate un-managed user directory to MS cloud with your domain name. You can then take over it if you want but it will on you"?

 

Is there any way to check if the user still works (user ID enabled) with our client if the AAD stays un-managed?

4 Replies
Does anyone have experience of real life scenarios of using Azure B2B with real clients/partners? And especially with smaller/medium size companies who don't have MS infrastructure in use (Office 365, AAD) and how these clients have welcomed the unmanaged Azure AD which is created for them. What if the customer does not have any capable IT personnel to take-over the unmanaged Azure directory (this is the case with many smaller comapnies)?

Hi,

 

In current release of Azure AD B2B, concept of "unmanaged tenant" you saw previously, doesn't exist anymore.

See e.g. https://docs.microsoft.com/en-us/azure/active-directory/active-directory-b2b-user-properties

 

 

Instead of "unmanaged tenant" they use wording "viral" and "Just-in-time" - but the concept has not changed. If the user's org does not have AAD, Microsoft will spin-up AAD for them and will leave it unmanaged until the org takes it over.
https://docs.microsoft.com/en-us/azure/active-directory/active-directory-self-service-signup

You're correct.

 

I tested this again, and when user has no Microsoft account or Azure AD account, clicking "getting started" on invite e-mail redirects you to "sign up with Microsoft" page, and let's you create a new account. I assumed it meant "Microsoft account", but no it doesnt. Microsoft should be more clear about this. Also on documentation side, as they was when they initially released Azure AD B2B preview maybe two years ago. Now when you look under "integrate parners using Azure AD B2B" topic on MS documentation, you don't find much information about this scenario if none.

 

Sorry I can't answer your original question. I'm also interested to hear how this is communicated to clients.