To give partner users a single MFA prompt when accessing your tenant, enable 'Trust MFA from other Microsoft Entra tenants' in your inbound access default settings
You have a Microsoft Entra tenant named contoso.com. You have a partner company that has a Microsoft Entra tenant named fabrikam.com. You need to ensure that when a user in fabrikam.com attempts to access the resources in contoso.com, the user only receives a single Microsoft Entra Multi-Factor Authentication (MFA) prompt. The solution must minimize administrative effort. What should you do?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Single MFA prompt for inbound guests is governed by the resource tenant's (contoso.com) inbound access settings, specifically the MFA trust toggle — not External collaboration settings and not the partner's outbound settings.
When a fabrikam.com user accesses contoso.com resources, you avoid a second MFA prompt by configuring contoso.com's inbound access default settings (Cross-tenant access settings) and enabling 'Trust multi-factor authentication from Microsoft Entra tenants'. The home tenant's MFA claim is then accepted, giving a single prompt with minimal effort.
Candidates pick External collaboration settings or the partner's outbound settings, but MFA trust for inbound users is configured on the resource tenant's inbound access default settings in Cross-tenant access settings.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The resource tenant (contoso.com) controls how external users are treated. By setting contoso.com's inbound access default settings and enabling 'Trust multi-factor authentication from Microsoft Entra tenants', Microsoft Entra accepts the MFA claim already satisfied in the user's home tenant (fabrikam.com), so the user gets only one MFA prompt. (Option A)Why the Other Options Are Wrong
- Option B (External collaboration settings) governs guest invitation/restriction scope, not MFA trust for cross-tenant access.
- Option C (contoso.com outbound access) controls contoso users going to external tenants, the opposite direction.
- Option D (fabrikam.com outbound access) configures the partner's egress, not how contoso trusts MFA from fabrikam users.