Skip to main content

B2B Collaboration Setup

Applies to:
Multi-TenantGuest UsersExternal IdentitiesCross-Tenant Access

Overview​

The Azure Enterprise Application for DKE is configured as a multi-tenant app.

This allows Microsoft tenants outside your own organization to be added using the DKE App Wizard under "Azure Domain Names."

The main configuration for B2B collaboration takes place in Microsoft Entra and Microsoft Purview.

Note

The DKE application supports B2B collaboration out of the box, allowing encrypted documents to be shared across different Microsoft 365 tenants while maintaining security controls.

Key Requirements​

Prerequisites

  • Guest users (identified by #EXT# in their username) require an E5 license
  • Guest users need access to shared Sensitivity Labels
  • Both organizations must set up External Identities
  • Both organizations must enable Cross-Tenant Access
Warning

Ensure that guest users have the appropriate E5 licensing to access DKE-protected content across tenant boundaries.

Configuration Overview​

B2B Setup Requirements

1

DKE App Wizard

Add external Azure Domain Names

2

External Identities

Configure in Microsoft Entra

3

Cross-Tenant Access

Enable in both organizations

4

Label Sharing

Grant access to Sensitivity Labels

Guest User Configuration​

RequirementDescription
E5 LicenseGuest users must have an E5 license to access DKE-protected content
External IdentityUsers identified by #EXT# suffix in their UPN
Label AccessMust be granted access to the relevant Sensitivity Labels
Azure AD B2BMust be configured as B2B guest in the host tenant

Resources​

For detailed setup instructions on configuring External Identities and Cross-Tenant Access, please refer to Microsoft's official documentation on B2B collaboration and cross-tenant access policies.