Microsoft Unified SecOps Platform
General

Mto Cross Cloud

In brief

The article now explicitly names the MFA trust setting, distinguishes home and target tenant configuration, adds section anchors, and clarifies terminology for added cross-cloud tenants.

What Defender admins need to know

The clearer labels help administrators identify the correct settings and follow cross-cloud tenant setup guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Cross-cloud visibility is available to government customers who have the applicable licensing requirements.

In addition, ensure that the trustTrust multi-factor authentication (MFA) from Microsoft Entra tenants setting is properly configured to successfully access tenants in Microsoft Commercial cloud environments. To configure MFA, see Change inbound trust settings for MFA and device claims.

Configure B2B collaboration settings

Follow these steps to configure B2B collaboration settings.

HomeConfigure home tenant settings

  1. Sign in to the Microsoft Entra admin center.
  2. Navigate to Identity > External identities > Cross-tenant access settings, then select Cross-tenant access settings.

Configure the home tenant settings to the following:

  1. For the organization you added, select Inbound access.
  2. Set B2B collaboration to Block for Access and Users.
  3. Select B2B direct connect, set access status to Block and Applies to all users.
  4. On the Application tab, set access to Block and Applies to All applications, then select Save.

No other MFA trust settings are required for the home tenant (the tenant from which you manage cross-cloud access).

Configure outbound access settings for the home tenant by following these steps:

  1. Select External applications and set access status to Allow.
  2. Set the Applies to to All external applications. Select Save.
  3. Select B2B direct connect and set access status to Block.
  4. In the Applies to, select All users.
  5. Select External applications and set access status to Block.
  6. Set the Applies to to All external applications. Select Save.

Configure target tenant settings

Perform the following steps to add the target tenant organization:

  1. On the Application tab, set access to Block and Applies to All applications, then select Save.
  2. Select Trust settings, then select Trust multi-factor authentication from Microsoft Entra tenants.

Configure outbound access settings for the target tenant by following these steps:

  1. In the Cross-tenant access settings pane, select Outbound access.
  2. Configure B2B collaboration by setting access status to Block.

Manage tenants across cloud environments

Add tenants from another cloud

To manage tenants from other Microsoft cloud environments:

  1. Go to the Multitenant management settings page in Microsoft Defender. :::image type="content" source="/unified-secops-platform/media/mto-cross-cloud/mto-add-from-cloud-small.png" alt-text="Screenshot of the Settings page with the Add tenant option highlighted." lightbox="/unified-secops-platform/media/mto-cross-cloud/mto-add-from-cloud.png":::

  2. In the Add from another cloud pane, type the tenant ID or domain of the tenant you want to add, then select Verify tenant. The verification process looks at the added tenant’s information and permissions.

    :::image type="content" source="/unified-secops-platform/media/mto-cross-cloud/mto-verify-tenant-small.png" alt-text="Screenshot of the add tenants pane with the verification highlighted." lightbox="/unified-secops-platform/media/mto-cross-cloud/mto-verify-tenant.png":::

  3. Once verified, select Add tenant to complete the process.

The tenants list now includes the tenants from the otherexternal cloud environment.environment you added. You can now manage these tenants as you would any other tenant in Microsoft Defender.

If you get an error during the verification process, you can:

To remove tenants from the list, select the tenant, then select Remove tenants.

After successfully adding tenants from other clouds, you can view thesethe added cross-cloud tenants in other multitenant pages like the incidents and device inventory pages.

Next stepsRelated content