You have a Microsoft Entra tenant named contoso.com and a partner tenant named fabrikam.com. Ensure that when a user from fabrikam.com accesses resources in contoso.com they see only one Microsoft Entra Multi-Factor Authentication (MFA) prompt while minimizing administrative effort. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: From the Azure portal of contoso.com, configure the inbound access default settings..
Why this is the answer
To ensure users from fabrikam.com experience a single MFA prompt when accessing contoso.com resources, you must configure inbound access settings within the contoso.com tenant. Specifically, you need to adjust the cross-tenant access settings, which allow you to trust MFA performed by the partner tenant (fabrikam.com). By configuring the inbound access default settings in contoso.com to trust MFA from fabrikam.com, users will not be prompted again for MFA by contoso.com if they have already completed it in their home tenant. Configuring External collaboration settings primarily controls who can invite guest users and guest user permissions, not MFA trust. Outbound access settings in contoso.com control what contoso.com users can access in other tenants, which is not relevant here. Configuring settings in fabrikam.com for outbound access would affect fabrikam.com users accessing other tenants, but it wouldn't dictate contoso.com's MFA policy for inbound users.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed