MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
You are troubleshooting an issue where users from a partner organization cannot access a shared app in your Microsoft Entra ID tenant. The partner uses Microsoft Entra ID with a custom domain. You have configured cross-tenant access settings. Which setting is most likely misconfigured?
⚠ Common exam trap
The trap here is that candidates often focus on app-level configuration (user assignment or provisioning) or confuse inbound/outbound directions, overlooking that cross-tenant access settings act as a mandatory first gate that must explicitly allow the partner's tenant ID before any app access can occur.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Default inbound cross-tenant access settings for the partner's tenant ID
The default inbound cross-tenant access settings control how external users from other tenants access your tenant's resources. Since the partner cannot access the shared app, the most likely misconfiguration is that the default inbound settings for the partner's tenant ID are set to block access, or the partner's tenant ID is not explicitly allowed in the inbound settings. This overrides any app-level permissions, as cross-tenant access settings act as a gate before user assignment is evaluated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Outbound cross-tenant access settings for the partner's tenant ID
Why it's wrong here
Outbound cross-tenant access settings for the partner's tenant ID govern what your organization's users can access in the partner tenant (e.g., MFA or device-compliance requirements imposed on your users when they authenticate to partner apps). They do not control whether partner users can sign in to your applications, so examining them cannot reveal why inbound partner access is failing.
- ✗
The app's user assignment and provisioning configuration
Why it's wrong here
While the app's user assignment and provisioning configuration can affect which users appear in the app or whether accounts are synced, cross-tenant access settings are evaluated first at the Microsoft Entra ID tenant boundary for an external identity. Even if the partner user is assigned to the app, a blocked default inbound cross-tenant access policy will reject the authentication before app-level assignment is considered.
- ✓
Default inbound cross-tenant access settings for the partner's tenant ID
Why this is correct
Default inbound cross-tenant access settings for the partner's tenant ID are the correct place to check because these settings determine whether external partner users are allowed to authenticate into your tenant and access your applications. Microsoft Entra ID evaluates cross-tenant access policies individually for each external tenant, and the default inbound policy applies unless a tenant-specific override exists, so a block here would prevent partner users from signing in.
- ✗
The partner's inbound cross-tenant access settings for your tenant
Why it's wrong here
The partner's inbound cross-tenant access settings for your tenant define the policies your users must satisfy when they access resources in the partner tenant—for example, whether the partner trusts your MFA claims. The issue involves partner users attempting to access your apps, so the relevant configuration is your inbound settings for the partner tenant, not the partner's inbound settings for your tenant.
Go deeper
Related to this question
Learn chapter
Azure Active Directory Domain Services (AADDS)
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Custom domain
A custom domain is a personalized internet address (like contoso.com) that you can use with cloud services instead of the default domain provided by the service provider.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.