To give partner users a single MFA prompt when accessing your tenant, enable 'Trust MFA from other Microsoft Entra tenants' in your inbound access default settings

Answer Correct answer: A — In contoso.com inbound access default settings, enable 'Trust MFA from other Microsoft Entra tenants' so fabrikam.com users get a single MFA prompt.

You have a Microsoft Entra tenant named contoso.com. You have a partner company that has a Microsoft Entra tenant named fabrikam.com. You need to ensure that when a user in fabrikam.com attempts to access the resources in contoso.com, the user only receives a single Microsoft Entra Multi-Factor Authentication (MFA) prompt. The solution must minimize administrative effort. What should you do?

  1. From the Azure portal of contoso.com, configure the inbound access default settings. Correct Answer
  2. From the Azure portal of contoso.com, configure the External collaboration settings.
  3. From the Azure portal of contoso.com, configure the outbound access default settings.
  4. From the Azure portal of fabrikam.com, configure the outbound access default settings.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Single MFA prompt for inbound guests is governed by the resource tenant's (contoso.com) inbound access settings, specifically the MFA trust toggle — not External collaboration settings and not the partner's outbound settings.

When a fabrikam.com user accesses contoso.com resources, you avoid a second MFA prompt by configuring contoso.com's inbound access default settings (Cross-tenant access settings) and enabling 'Trust multi-factor authentication from Microsoft Entra tenants'. The home tenant's MFA claim is then accepted, giving a single prompt with minimal effort.

Candidates pick External collaboration settings or the partner's outbound settings, but MFA trust for inbound users is configured on the resource tenant's inbound access default settings in Cross-tenant access settings.

Community Discussion (6 comments)

pentium75 👍 1 Selected: A
Not B, "External collaboration settings" are about what guests can access but have nothing to do with MFA prompts. That is in the Cross-tenant access settings.
ruscomike 👍 1 Selected: A
agree with A, even if ot could be better modify the setting just for fabrikam and not all the inbound default as suggested in the answer :-P
ceejay12 👍 1 Selected: A
Agreed, A
NK203 👍 3
Agree A. Not select B,Reason :https://learn.microsoft.com/en-us/entra/external-id/external-collaboration-settings-configure
Pamban 👍 3 Selected: A
I would go with A Trust multi-factor authentication from Microsoft Entra tenants: Select this checkbox to allow your Conditional Access policies to trust MFA claims from external organizations. During authentication, Microsoft Entra ID checks a user's credentials for a claim that the user completed MFA. If not, an MFA challenge is initiated in the user's home tenant. Link: https://learn.microsoft.com/en-us/entra/external-id/cross-tenant-access-settings-b2b-collaboration#to-change-inbound-trust-settings-for-mfa-and-device-claims
danielklein09 👍 2
Agree, B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The resource tenant (contoso.com) controls how external users are treated. By setting contoso.com's inbound access default settings and enabling 'Trust multi-factor authentication from Microsoft Entra tenants', Microsoft Entra accepts the MFA claim already satisfied in the user's home tenant (fabrikam.com), so the user gets only one MFA prompt. (Option A)

Why the Other Options Are Wrong

  • Option B (External collaboration settings) governs guest invitation/restriction scope, not MFA trust for cross-tenant access.
  • Option C (contoso.com outbound access) controls contoso users going to external tenants, the opposite direction.
  • Option D (fabrikam.com outbound access) configures the partner's egress, not how contoso trusts MFA from fabrikam users.

Community Comment Notes

Comments confirmed A and noted: 'External collaboration settings... have nothing to do with MFA prompts. That is in the Cross-tenant access settings,' and referenced the inbound 'Trust multi-factor authentication from Microsoft Entra tenants' checkbox.

Official Reference

Related Analysis

← Back to AZ-500 Study Guide