Home

Azure B2B Collaboration Restrictions vs SharePoint Online Limiting Sharing

%3CLINGO-SUB%20id%3D%22lingo-sub-216478%22%20slang%3D%22en-US%22%3EAzure%20B2B%20Collaboration%20Restrictions%20vs%20SharePoint%20Online%20Limiting%20Sharing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-216478%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20little%20background.%20Our%20IT%20department%20wants%20a%20little%20more%20control%20over%20the%20inviting%20external%20users%20processes%20for%20our%20Tenant%20(Our%20clients).%20More%20than%2090%25%20of%20these%20users%20will%20be%20SharePoint%20Only%2C%20no%20B2B%20apps%20in%20our%20company%20as%20of%20yet.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20for%20automation%2C%20I%20have%20made%20use%20of%20the%20%22New-AzureADMSInvitation%22%20PowerShell%20command.%20It%20is%20simpler%20than%20trying%20to%20invite%20directly%20to%20SharePoint%2C%20and%20it%20gives%20me%20the%20AD%20user%20object%20to%20manipulate%20or%20put%20into%20groups%20before%20they%20accept%20the%20invite.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20also%20trying%20to%20automate%20control%20over%20whitelisting%20our%20client's%20domains.%20I%20have%20found%20a%20way%20to%20control%20and%20add%20to%20the%20B2BManagement%20Policy%20(%22Set-AzureAdPolicy%22).%20But%20I%20am%20now%20reading%20that%2C%20at%20most%2C%20this%20policy%20can%20hold%20only%2060%20domains.%20We%20work%20with%20well%20over%20100%20different%20companies%2C%20and%20this%20cap%20of%2060%20domains%20will%20not%20suffice.%20Is%20this%20limit%20higher%20for%20Enterprise%2C%20or%20is%20this%20standard%20across%20the%20board%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESecond%20question%2C%20which%20whitelist%2Fblacklist%20has%20precedent%3F%20I%20can%20whitelist%20within%20Azure%20AD%2C%20or%20do%20a%20whitelist%20in%20the%20SharePoint%20Sharing%20section%20under%20the%20SPO%20Admin%20interface.%20If%20a%20domain%20is%20not%20whitelisted%20in%20Azure%20AD%2C%20but%20we%20invite%20an%20external%20user%20through%20the%20SPO%20sharing%20interface%2C%20what%20happens%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20of%20this%20is%20coming%20from%20the%20assumption%20that%20at%20the%20end%20of%20the%20day%2C%20Azure%20AD%20gets%20precedent%2C%20and%20doing%20things%20in%20one%20area%2C%20affects%20the%20other.%20But%20I%20am%20seeing%20that%20may%20not%20be%20the%20case.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAm%20I%20going%20about%20this%20wrong%20by%20applying%20whitelist%2Fblacklist%20in%20Azure%20B2BManagementPolicy%2C%20and%20need%20to%20instead%20work%20in%20the%20SharePoint%20External%20Sharing%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-216478%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Justin Cessna
New Contributor

Hi all,

 

A little background. Our IT department wants a little more control over the inviting external users processes for our Tenant (Our clients). More than 90% of these users will be SharePoint Only, no B2B apps in our company as of yet.

 

So for automation, I have made use of the "New-AzureADMSInvitation" PowerShell command. It is simpler than trying to invite directly to SharePoint, and it gives me the AD user object to manipulate or put into groups before they accept the invite.

 

I am also trying to automate control over whitelisting our client's domains. I have found a way to control and add to the B2BManagement Policy ("Set-AzureAdPolicy"). But I am now reading that, at most, this policy can hold only 60 domains. We work with well over 100 different companies, and this cap of 60 domains will not suffice. Is this limit higher for Enterprise, or is this standard across the board?

 

Second question, which whitelist/blacklist has precedent? I can whitelist within Azure AD, or do a whitelist in the SharePoint Sharing section under the SPO Admin interface. If a domain is not whitelisted in Azure AD, but we invite an external user through the SPO sharing interface, what happens?

 

All of this is coming from the assumption that at the end of the day, Azure AD gets precedent, and doing things in one area, affects the other. But I am seeing that may not be the case.

 

Am I going about this wrong by applying whitelist/blacklist in Azure B2BManagementPolicy, and need to instead work in the SharePoint External Sharing?

 

Thanks in advance

Related Conversations