Entra external tenant - federation with other Entra ID tenants

Martin Kallukalam 540 Reputation points
2025-08-02T19:01:34.04+00:00

I am exploring entra-id external tenant and comparing with workforce tenant.
WF tenant have builtin federation with other Azure Entra ID tenants. No extra configuration needed.
This is not supported in Entra ID. So I was hoping I can do a manual OIDC federation with other Entra ID tenants . This is when I read the statement that it is not supported.
https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-custom-oidc-federation-customers
User's image

Is it really not supported?
So how does a customer using Entra ID external tenant expect to federate with other Entra ID workforce or external tenant customers ?

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
{count} votes

Answer accepted by question author
  1. Sreetheja Adusumilli 880 Reputation points Microsoft External Staff Moderator
    2025-08-18T10:12:41.9866667+00:00

    Hello Martin Kallukalam,

    Thanks for reaching out to Microsoft Q&A Portal,

    Right now, you cannot set up direct OpenID Connect (OIDC) federation between one Microsoft Entra External ID tenant (your customer account) and another Entra ID tenant. Instead, there are other ways to enable collaboration or federation:

    1. Custom OIDC Federation Microsoft’s custom OIDC federation feature only supports identity providers that are not Entra tenants — like social logins (Google, Facebook), Azure AD B2C, Microsoft personal accounts, or any OIDC-compliant service. Using another Entra ID tenant as an OIDC provider is not supported at this time.
    2. B2B Guest User Invitations
      • You can invite users from another Entra ID tenant to your External ID tenant as guests.
      • To do this, go to your External ID tenant’s “External Identities” section, choose “Invite users,” and enter the users’ email addresses from the partner Entra tenant.
      • The invited users get an email invitation, which they accept, and then appear as Guest users in your tenant.
    3. Cross-Tenant Access Settings (B2B Direct Connect)
      • This method lets you set up direct trust between Entra tenants without needing individual user invitations.
      • In your External ID tenant, under “Cross-tenant access settings,” you can configure policies for how users from the partner tenant authenticate, handle multi-factor authentication (MFA), device compliance, and what claims are shared.
    4. SAML/WS-Fed Direct Federation
      • If the partner tenant wants to federate using SAML or WS-Fed (older federation protocols), you can set this up for verified partner domains (like ******@partner.com).
      • To do this, verify the partner’s domain in your tenant and add their SAML/WS-Fed identity provider metadata and certificate.
      • When users sign in, they get redirected to their own tenant to authenticate and then return to your tenant after successful login.

    Microsoft Document for reference

    Kindly let us know if the above helps or you need further assistance on this issue.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.