B2B Collaboration Setup
B2B Collaboration Setup
Configure cross-tenant sharing for DKE-protected content
Overview
The Azure Enterprise Application for DKE is configured as a multi-tenant app.
This allows Microsoft tenants outside your own organization to be added using the DKE App Wizard under "Azure Domain Names."
The main configuration for B2B collaboration takes place in Microsoft Entra and Microsoft Purview.
The DKE application supports B2B collaboration out of the box, allowing encrypted documents to be shared across different Microsoft 365 tenants while maintaining security controls.
Key Requirements
Prerequisites
- Guest users (identified by #EXT# in their username) require an E5 license
- Guest users need access to shared Sensitivity Labels
- Both organizations must set up External Identities
- Both organizations must enable Cross-Tenant Access
Ensure that guest users have the appropriate E5 licensing to access DKE-protected content across tenant boundaries.
Configuration Overview
B2B Setup Requirements
DKE App Wizard
Add external Azure Domain Names
External Identities
Configure in Microsoft Entra
Cross-Tenant Access
Enable in both organizations
Label Sharing
Grant access to Sensitivity Labels
Guest User Configuration
| Requirement | Description |
|---|---|
| E5 License | Guest users must have an E5 license to access DKE-protected content |
| External Identity | Users identified by #EXT# suffix in their UPN |
| Label Access | Must be granted access to the relevant Sensitivity Labels |
| Azure AD B2B | Must be configured as B2B guest in the host tenant |
Resources
For detailed setup instructions on configuring External Identities and Cross-Tenant Access, please refer to Microsoft's official documentation on B2B collaboration and cross-tenant access policies.