AZ-500 Manage identity and access Practice Question
A company has a partner organization in another Microsoft Entra ID tenant. They want to allow users from the partner tenant to access their Azure resources through Microsoft Entra B2B collaboration. They also want the partner's Multi-Factor Authentication (MFA) claims to be trusted when partner users access their resources, so that they do not need to perform MFA again. Which configuration in cross-tenant access settings should they enable?
⚠ Common exam trap
Many exam-takers confuse Conditional Access policies with cross-tenant trust settings, thinking they can use a Conditional Access policy to 'trust' external MFA, when in fact the trust must be explicitly configured in the cross-tenant access settings for inbound MFA claims.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trust multi-factor authentication from the partner tenant (inbound trust).
Cross-tenant access settings in Microsoft Entra ID allow you to configure inbound trust for MFA from an external Microsoft Entra ID tenant. When enabled, Microsoft Entra B2B collaboration will accept the partner tenant's MFA claims, so partner users who have already satisfied MFA in their home tenant will not be prompted again when accessing your resources. This is configured under 'Cross-tenant access settings' > 'Inbound trust settings' for the specific partner tenant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Trust multi-factor authentication from the partner tenant (inbound trust).
Why this is correct
This setting, located in the partner tenant's cross-tenant access settings under 'Inbound access' > 'Trust settings', instructs your Microsoft Entra ID to accept the multi-factor authentication (MFA) claims already performed in the partner tenant. When enabled, B2B collaboration users from that tenant are not prompted for MFA again in your tenant, provided their home tenant has satisfied MFA. This is the correct mechanism to avoid redundant authentication prompts.
- ✗
Trust device compliance from the partner tenant.
Why it's wrong here
Trusting device compliance is a distinct inbound trust option that consumes the partner tenant's device compliance status (e.g., from Intune) to evaluate your Conditional Access policies that require compliant devices. It does not accept MFA claims or alter user authentication flow. Even if this is enabled, a user who has not satisfied MFA in the home tenant would still be challenged, so it cannot solve the problem of duplicate MFA prompts.
- ✗
Enable a Conditional Access policy that grants access to the partner tenant.
Why it's wrong here
A Conditional Access policy you create grants access based on conditions like user, location, or application, but it applies to access to your resources, not to how your tenant interprets the partner tenant's authentication claims. Enabling a policy that 'grants access to the partner tenant' (if it were possible) would not cause Microsoft Entra ID to trust the partner's MFA; it would merely allow users, and any MFA requirement from the partner tenant remains untrusted. The trust relationship must be configured separately in cross-tenant access settings.
- ✗
Configure identity synchronization with the partner tenant.
Why it's wrong here
Identity synchronization, such as via Microsoft Entra Connect or cross-tenant synchronization, propagates user objects between directories, but it does not convey security authentication results. Synchronized users are treated as separate identities in your tenant and would still have to go through your own authentication and MFA policies. Synchronization does not create a federation of authentication claims that could suppress MFA prompts for B2B collaboration.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.