Azure AD B2B
220 TopicsHow do guest users change passwords?
Hi The title says it all - I have been searching for a detailed description of how guest users change their passwords. Are the guest user account somehow tied to their on-prem AD account so it is SSO? If not, do we, at the host tenant, need to activate self service password reset and how do we specify password rules? Thanks, JakobSolved77KViews0likes4CommentsHow to set up external user account expiration for Azure AD?
Right now, we are collaborating with external users using B2B functionalities. These external users are automatically added to our Azure AD Directory when they accept and register thru MFA. Now we want to set up expiration on these external users (guest user lifecycle) that automatically removes these guest users from our Azure AD directory after X days. Otherwise the list of external users will continue to grow with time. Any help appreciated!Solved69KViews0likes6CommentsAzure B2B guest users licensing question
Hello, I am working on Azure B2B in order to add guest users in my Azure AD tenant. I am wondering how to know the following information? https://docs.microsoft.com/en-us/azure/active-directory/b2b/licensing-guidance The document explains: "B2B guest user licensing is automatically calculated and reported based on the 1:5 ratio. Additionally, guest users can use free Azure AD features with no additional licensing requirements. Guest users have access to free Azure AD features even if you don’t have any paid Azure AD licenses." As reported here: https://azure.microsoft.com/en-us/pricing/details/active-directory/my guest users use only free Azure AD features, such as: User provisioning User and group management (add/update/delete) So my question is, the 1:5 ratio is also applied for free Azure AD features? Am I subject to this ratio even if guest users use free AAD features? Can I see somewhere on the portal if I exceed this limit? Thank you. Nicolas40KViews0likes5CommentsBlock users from becoming Guest in another Office 365 Tenant
Hi! Is it possible to restrict our Azure/Office 365 users from using their account/email-addresses as Guests in another Azure/Office 365 Tenant. I know that we can block which domains that we can send Guest invitations to, but in this case it is the other way around.Solved31KViews0likes15CommentsMS Teams Invitation redemption & Self service account sign up is disabled
Hi there, I am invited to join a MS Teams group from another organization. when I try to redeem the invitation , it asks me create a password and display name rather than allowing me to Sign in using my Microsoft Account (Since my organisation does not have a Azure AD yet). But when I try to go through by creating a password, then I get an error that: "We cannot create a self-service Azure AD account for you because has <orga name> disabled self-service account sign-up by email validation. Ask admin to enable EmailVerified users or create an account for you." My organisation does not have any Azure AD and I have a Microsoft Account created using my official email id. What is going on here? Any help is much appreciated 🙂31KViews0likes9CommentsAzure B2B Guest User and Licensing - what does it actually do?
Getting into Azure B2B with 300+ users invited and now Guests in our Azure AD primarily for using Teams. I notice in portal.azure.com > Azure AD > Users > selecting any Guest user, I can actually Assign a license to the Guest user and it says in "Public Preview". What does this actually do in technical terms? Is it simply to be in control over licensing according to the 5:1 rule in Microsoft's licensing guidande for Azure B2B? Or does it actually enable the Guest user to use the products that you assign to the user?27KViews0likes5CommentsMS Teams in Cross-Tenant synchronization
Hello! I am using Cross-Tenant synchronization (preview) to synchronize two tenants (A and B). I have created a configuration to send the users from Tenant A to Tenant B. In the "Provision Azure Active Directory Users" mapping, the "Usertype" attribute is set to Member and in the "showInAddressList" attribute is set to True. After these settings, in outlook the migrated users appear in the GAL/search bar and work perfectly, showing data, status and sending e-mails normally. In Microsoft Teams, the migrated users appear in the GAL with all their data, but no status and the messages do not arrive at their destination. Is this normal for the tool? If yes, is there any way to hide these migrated users only in Ms Teams? I am worried about the end user sending messages to these migrated users and not being able to contact them. Regards,26KViews0likes26CommentsGuest users are not showing in document library
If I grant guest users rights directly to a SPO document library (after having disabled inheritance), the users will have the expected rights, but they will not show up in the list of users/groups with access to the library. This is of course a security problem, because you can't see (easily) who have access, but it also means that you can't remove or edit the user (in the GUI). If I put the same users in a group, it works as expected. Are you seing the same thing?Solved21KViews1like10CommentsExternal User with conditional access for SharePoint Online not working
I'm excited about the new introduced features and I immediately tried it out. What my customer are looking for is to enhance the external collaboration on their SharePoint Online. I want to enforce MFA for all or selected external users. The users are already added to the AAD the SPO belongs to (owner tenant). I've enabled a conditional policy in the new Azure Portal for the enterprise application named "Office 365 SharePoint Online" but even after an our for potential sync between AAD and SharePoint the policy is not working. I tested the MFA enforcement with a basic ASP.NET app hosted and registered as an enterprise app in the same tenant. The policy is working if enabled for this app. The external user had to enroll using MFA and the access is granted as expected. I then changed the policy to not select specific apps but the apply to all apps in the tenant. But also without any noticeable results even after some time passed. Is it a bug? A feature? Or a topic on the roadmap? Any ETA? It is a really important app in the AAD ecosystem and respecting the AAD policies would be beneficial if not mandatory!Solved19KViews2likes12Comments