Creating an allow list of a partner's cloud apps for your users is configured via Outbound access settings in Cross-tenant access settings

Answer Correct answer: D — Configure Outbound access settings in Cross-tenant access settings to allow-list fabrikam.com cloud apps for contoso.com users.

You have a Microsoft Entra tenant named contoso.com. You collaborate with a partner organization that has a Microsoft Entra tenant named fabrikam.com. You need to create an allow list of cloud apps from fabrikam.com that can be used by the users in contoso.com. What should you do for contoso.com in the Microsoft Entra admin center?

  1. From Inbound access settings in Cross-tenant access settings, configure the B2B direct connect settings.
  2. From External collaboration settings, configure the Collaboration restrictions settings.
  3. From External collaboration settings, configure the Guest invite settings.
  4. From Outbound access settings in Cross-tenant access settings, configure the B2B collaboration settings. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Inbound = external users to your apps; Outbound = your users to external apps; Tenant restrictions = external users to external apps. An allow list of partner cloud apps used by your users is an outbound scenario.

When contoso.com users need to access specific cloud apps in a partner's Entra tenant (fabrikam.com), you configure Outbound access settings under Cross-tenant access settings. Outbound settings control your internal users' access to external apps and let you scope an allow list of external applications.

People confuse Inbound (B2B direct connect) or External collaboration settings with the correct Outbound access settings; the key phrase is your users consuming the partner's apps, which is outbound.

Community Discussion (7 comments)

randy0077 👍 1 Selected: D
https://learn.microsoft.com/en-us/entra/external-id/tenant-restrictions-v2#tenant-restrictions-vs-inbound-and-outbound-settings:~:text=tenant%20access%20policy.-,Tenant%20restrictions%20vs.%20inbound%20and%20outbound%20settings,Outbound%20settings%20control%20internal%20account%20access%20to%20external%20apps,-.
Hot_156 👍 1 Selected: A
I was wrong... It is A To create an allow list of cloud apps from fabrikam.comthat can be used by the users in contoso.com, you should configure the Inbound access settings in Cross-tenant access settings and set up the B2B direct connect settings. So, the correct answer is A. From Inbound access settings in Cross-tenant access settings, configure the B2B direct connect settings. https://learn.microsoft.com/en-us/entra/external-id/tenant-restrictions-v2
Hot_156 👍 1 Selected: B
It is from external collaboration settings! -Sign in to the Admin Center -Navigate to External Identities: Go to Identity > External Identities > External collaboration settings. -Configure Outbound Access Settings: These settings control whether your users can access resources in an external organization. You can apply these settings to everyone or specify individual users, groups, and applications3. -Configure Inbound Access Settings: These settings control whether users from external organizations can access resources in your organization. You can apply these settings to everyone or specify individual users, groups, and applications3. -Trust Settings: Determine whether your Conditional Access policies trust the multifactor authentication (MFA), compliant device, and Microsoft Entra hybrid joined device claims from an external organization
Nhadipour 👍 2 Selected: D
To allow users in contoso.com to access cloud apps in fabrikam.com, we should configure an outbound policy
Viggy1212 👍 3 Selected: D
Outbound settings control internal account access to external apps.
obaemf 👍 3
Think of the different cross-tenant access settings this way: Inbound settings control external account access to your internal apps. Outbound settings control internal account access to external apps. Tenant restrictions control external account access to external apps. https://learn.microsoft.com/en-us/entra/external-id/tenant-restrictions-v2#tenant-restrictions-vs-inbound-and-outbound-settings By default, B2B collaboration with other Microsoft Entra organizations is enabled, and B2B direct connect is blocked. But the following comprehensive admin settings let you manage both of these features. Outbound access settings control whether your users can access resources in an external organization. You can apply these settings to everyone, or specify individual users, groups, and applications. Inbound access settings control whether users from external Microsoft Entra organizations can access resources in your organization. You can apply these settings to everyone, or specify individual users, groups, and applications. https://learn.microsoft.com/en-us/entra/external-id/cross-tenant-access-overview
Koekjesdoos_111 👍 1
Its D. https://learn.microsoft.com/en-us/entra/external-id/tenant-restrictions-v2#tenant-restrictions-vs-inbound-and-outbound-settings

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Outbound access settings in Cross-tenant access settings govern how your internal users access resources in external organizations. To let contoso.com users use a specific allow list of fabrikam.com cloud apps, you set an outbound B2B collaboration policy that scopes the external applications. (Option D)

Why the Other Options Are Wrong

  • Option A (Inbound access settings / B2B direct connect) controls external users accessing your apps, the opposite direction.
  • Option B (External collaboration settings / Collaboration restrictions) limits which external domains your users can invite, not an allow list of external apps.
  • Option C (Guest invite settings) controls how guests are invited, not app-level access from your tenant to a partner.

Community Comment Notes

A comment distilled the model: 'Outbound settings control internal account access to external apps,' with the official tenant-restrictions-v2 article confirming inbound vs outbound vs tenant-restrictions scope.

Official Reference

Related Analysis

← Back to AZ-500 Study Guide