Microsoft Entra External ID
General

Set up B2B direct connect

In brief

The documentation now explains how Microsoft Entra ID accepts compliant-device claims from an external user’s home tenant and how Conditional Access evaluates those claims. It also describes the trust implications and behavior when the setting is disabled.

What Entra admins need to know

Administrators can use the added guidance to assess whether an external organization’s device compliance policies are trustworthy before enabling the setting.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • Trust multi-factor authentication from Microsoft Entra tenants: Select this checkbox if your Conditional Access policies require multifactor authentication (MFA). This setting allows your Conditional Access policies to trust MFA claims from external organizations. During authentication, Microsoft Entra ID checks a user's credentials for a claim that the user completed MFA. If not, an MFA challenge is initiated in the user's home tenant.

  • Trust compliant devices: Allows your Conditional Access policiesMicrosoft Entra ID to trust compliant device claims from an external Microsoft Entra organization when their users access your resources.

  • Trust Microsoft Entra hybrid joined devices: Allows your When you enable this setting, external users can satisfy Conditional Access policies to trustthat require a compliant device by using the compliance status evaluated by their home organization.

    When an external user signs in, Microsoft Entra hybrid joinedID can receive a device claimscompliance claim from anthe user's home tenant. If Trust compliant devices is enabled, Microsoft Entra ID accepts the claim. Conditional Access policies that require a compliant device can then evaluate successfully based on the compliance assessment performed by the external organization.

    Enable this setting only for organizations whose device compliance policies you trust. Your tenant relies on the compliance evaluation performed by the external organization when their users access your resources.'s device management and compliance solution.

  • Trust Microsoft Entra hybrid joined devices: Allows your Conditional Access policies to trust Microsoft Entra hybrid joined device claims from an external organization when their users access your resources.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…