Microsoft Entra ID’s External collaboration settings control how users in a workforce tenant invite business-to-business (B2B) guests, which external domains may be invited, and how much directory information guests can see. They do not replace resource permissions, Conditional Access, SharePoint sharing controls, or cross-tenant access policies.
Find them at Microsoft Entra admin center → Entra ID → External Identities → External collaboration settings. Microsoft periodically changes navigation and labels, so verify the live portal while configuring.
What External collaboration settings control
These are tenant-level controls for B2B collaboration in a workforce tenant. A typical B2B guest is represented as a directory user with UserType = Guest and limited permissions by default. Guests may authenticate through another Microsoft Entra organization, a Microsoft account, email one-time passcode, or another supported external identity provider. See Microsoft Entra External ID documentation and B2B guest user properties.
These settings primarily determine:
- Which internal users can invite external users.
- Whether invitations are allowed or blocked by domain.
- Whether guests receive limited directory visibility or can see only their own profile.
They do not automatically grant access to an application, file, Team, SharePoint site, or other resource. Those permissions are evaluated separately.
#1 Best Overall
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
External collaboration versus cross-tenant access
| Control plane | What it governs | Scope |
|---|---|---|
| External collaboration settings | Invitation permissions, invited domains, and guest directory visibility | B2B guests, including people using non-Microsoft Entra identities |
| Cross-tenant access settings | Inbound and outbound collaboration, organization-specific policies, user/group/application scope, and trust of external MFA or device claims | Other Microsoft Entra organizations |
Both controls can apply. The most restrictive applicable control wins. For example, a partner tenant permitted in cross-tenant access settings can still fail an invitation if its domain is blocked in External collaboration settings. Conversely, stopping new invitations does not remove existing guest accounts. Read Microsoft’s cross-tenant access guidance.
Prerequisites, scope, and licensing
- Use a workforce tenant for employee-to-partner B2B collaboration. Customer-facing applications generally belong in an external tenant model; see Microsoft Entra External ID overview.
- Sign in with an account that has an appropriate Entra administrative role. Exact role requirements can vary by operation.
- Basic invitation and domain controls should be considered separately from premium features. Granular cross-tenant targeting and governance capabilities such as Conditional Access, access reviews, or entitlement management may require Microsoft Entra ID P1/P2 or other licensing, depending on your agreement and user population. Check External ID pricing and billing and Microsoft Entra pricing.
Plan before changing the tenant
- Inventory current guest users, groups, application assignments, Teams, SharePoint sites, and OneDrive sharing.
- List approved partner organizations and every domain they legitimately use, including subsidiaries or contractor domains.
- Identify who currently sends invitations and which workflows depend on self-service onboarding.
- Decide whether you need broad collaboration, approved domains, administrator-mediated invitations, or highly restricted guest directory visibility.
- Determine whether each scenario involves another Entra tenant, a non-Microsoft identity provider, a different Microsoft cloud, SharePoint/OneDrive native sharing, B2B direct connect, or cross-tenant synchronization.
- Plan External collaboration and cross-tenant access together. Microsoft’s recommendations are in B2B best practices.
Open External collaboration settings
- Sign in to the Microsoft Entra admin center.
- Open Entra ID.
- Select External Identities.
- Select External collaboration settings.
The related, separate page is Entra ID → External Identities → Cross-tenant access settings.
Choose who may invite guests
Microsoft’s documented default allows all users, including B2B guests, to invite external users; your tenant may differ because of previous configuration, cloud, or policy changes. The available choices are generally:
Allow all users, including guests
This minimizes friction for vendors, clients, and contractors but increases guest sprawl, typo-squatted or personal-domain invitations, unclear ownership, and offboarding work.
Free tools Windows power users keep installed
One-click scans. No signup required.
Allow only selected administrator roles
This provides stronger governance while requiring a request and provisioning process for ordinary business owners. Confirm the exact role names shown in your current portal.
Disable user invitations
This gives the strongest creation control, but only works operationally if your organization provides a documented approval path with reasonable service levels.
Rank #2
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
- 4GB DDR4 System Memory; 128GB Solid State Drive
- 11.6" HD (1366 x 768) Multi-Touch Display
- Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
- Windows 11 Pro
Restrict invitation domains
Domain restrictions can be configured as an approved-domain (allow-list) strategy or a blocked-domain (block-list) strategy.
Allow-list
Only specified domains can receive new B2B invitations. This creates a clearer trust boundary, but requires maintenance when partners add subsidiaries, contractors, or new domains.
Block-list
Most domains remain available except those explicitly blocked. This is easier for broad ecosystems but offers less preventive control.
No domain restriction
Users can invite broadly, subject to invitation permissions, cross-tenant policies, resource authorization, and Conditional Access.
A domain rule primarily affects the invitation process. It is not a complete access boundary and is not automatic deprovisioning. Review existing guests, memberships, application assignments, Microsoft 365 sharing, and sign-in policies separately. A blocked domain can stop a new invitation even when cross-tenant access otherwise permits the partner; existing guests may continue until their accounts, sessions, assignments, or resource permissions are changed.
Limit guest directory visibility
Guests have limited directory permissions by default. Administrators can choose a more restrictive mode in which a guest sees only their own profile information.
Recommended Free Tools
Rank #3
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
- Default limited access: Better directory discovery for collaboration workflows, with greater information exposure.
- More restrictive access: Reduces disclosure and suits sensitive environments, but can make it harder for guests to find people or groups.
This setting does not grant or revoke access to applications, files, Teams, SharePoint sites, or groups. Those resources still require independent authorization.
Configure cross-tenant access for Entra organizations
Use Cross-tenant access settings for inbound access from, and outbound access to, another Microsoft Entra organization. You can define defaults and organization-specific rules, scope selected external users, groups, or applications, and decide whether to trust a partner’s MFA or device claims.
Cross-tenant settings remain only one layer. An invitation can still fail because the domain is blocked, the inviter lacks permission, the partner is denied by a default or organization-specific policy, the user/group is outside a scoped policy, the target application rejects guests, or Conditional Access blocks the session.
SharePoint, OneDrive, Teams, and application interactions
Native SharePoint and OneDrive sharing can use Microsoft Entra B2B integration. Microsoft notes that the relevant external domains may need to be permitted in External collaboration settings even when the partner tenant is configured in cross-tenant access settings. This explains why a partner may work in one application but fail during a SharePoint or OneDrive invitation. Also check each workload’s external-sharing policy, Teams guest settings, application assignment, and resource permissions.
A safer baseline for most organizations
- Permit invitations only to designated business users or approved administrator roles.
- Use approved domains when the partner list is known and maintain that list.
- Restrict guest directory visibility as far as collaboration workflows allow.
- Create organization-specific cross-tenant policies for strategic partners and keep unknown organizations appropriately restricted.
- Apply Conditional Access requirements suitable for guest risk.
- Use access reviews or entitlement management where approvals, expiration, and recurring certification are needed.
- Review and remove dormant guests; guest invitations do not expire automatically.
What changes do—and do not do—to existing guests
Blocking a domain does not delete existing guest accounts. Disabling invitations does not revoke existing access. Restricting directory visibility does not remove application or resource permissions.
- Search for guest users from the affected domain.
- Review group memberships and application assignments.
- Check Teams, SharePoint, OneDrive, and other resource permissions.
- Remove or disable users where justified by policy.
- Revoke sessions or refresh tokens when incident response requires it.
- Check external-sharing policies so an alternate sharing path does not recreate access.
Use current Microsoft Graph or portal procedures for remediation; exact command syntax and required permissions change over time.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Troubleshooting guide
“The partner tenant is allowed, but the invitation fails”
- Check the partner’s domain in External collaboration settings.
- Confirm the inviter is permitted.
- Review both inbound and outbound cross-tenant policies.
- Check application and resource guest support.
- Review SharePoint/OneDrive sharing settings and Conditional Access.
“We blocked a domain, but existing guests still work”
This can be expected. Blocking normally addresses new invitations; audit and remove existing identities and assignments separately.
“The guest signs in but cannot open the application”
Authentication is not authorization. Confirm invitation redemption, direct or group assignment, application guest support, Conditional Access, and the resource’s own permissions. See Add and manage B2B collaboration users.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →“Cross-tenant settings work for Teams or an app, but not SharePoint”
Review SharePoint and OneDrive B2B integration requirements and ensure the external domain is permitted in External collaboration settings.
“Guests see too much directory information”
Select the more restrictive guest-directory option, test with a representative guest, and separately review Microsoft 365 workload sharing.
Validate with a test matrix
After saving changes, test behavior rather than assuming the portal accepted the intended policy:
- Invitation from an approved domain by an authorized inviter.
- Invitation from a blocked or unapproved domain.
- Invitation attempt by an unauthorized internal user.
- Sign-in by an existing guest from an affected domain.
- Guests using different identity providers, including email one-time passcode where applicable.
- Access to the actual application, Team, SharePoint site, or OneDrive resource.
- Directory visibility using a representative guest account.
- Outbound access from your users to a partner organization.
Advanced scenarios
Cross-cloud collaboration
Organizations in different Microsoft clouds must enable the relevant cloud relationship and configure inbound and outbound cross-tenant access. Enabling a cloud does not authorize every tenant in it; the partner generally must be added under organizational settings. Domain lookup may not be available, so a tenant ID can be required. B2B direct connect is not supported across different Microsoft clouds, and documented cross-cloud invitation/sign-in scenarios can have additional UPN requirements. See Cross-cloud settings.
Best Value
- WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
- 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
- 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
- CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
- LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.
Email one-time passcode
Email one-time passcode is an authentication or redemption fallback in some B2B scenarios, not an invitation-permission control. Microsoft documents it as enabled by default for new tenants and for existing tenants where it was not explicitly disabled; inspect your tenant’s actual setting.
B2B direct connect and cross-tenant synchronization
B2B direct connect has different prerequisites and is not a drop-in replacement for ordinary guest invitations; see B2B direct connect. Cross-tenant synchronization is intended for provisioning or synchronizing users across tenants, not basic invitation control.
Related governance controls
Cross-tenant access handles organization-to-organization policy. Entitlement management and access reviews add approval, expiration, and recurring certification. Conditional Access adds authentication, device, location, session, or risk requirements after sign-in begins. None of these replaces resource authorization or invitation controls.
For customer-facing applications, use the external-tenant model rather than treating workforce B2B as a customer identity system.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsFrequently Asked Questions
Are External collaboration settings the same as cross-tenant access settings?
No. External collaboration settings govern invitations, invited domains, and guest directory visibility. Cross-tenant access settings govern inbound and outbound collaboration with other Microsoft Entra organizations, including scoped users, groups, applications, and trusted claims.
Does blocking an external domain remove existing guests?
No. Domain blocking primarily prevents new invitations. Existing guest accounts, sessions, assignments, and resource permissions must be reviewed and remediated separately.
Does a guest who can sign in automatically have application access?
No. Sign-in proves authentication only. The guest still needs application or resource authorization and must satisfy Conditional Access and workload-specific policies.
Is email one-time passcode an invitation restriction?
No. It is an authentication and redemption method for some B2B scenarios; invitation permissions and domain policies are separate controls.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




