Close Menu
Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Facebook X (Twitter) Instagram
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    • Home
    • Intune
    • Windows
      • Modern Workplace
    • macOS
    • Android
    • iOS
    • Automation
      • Logic Apps
      • Intune Monitoring
      • GitHub
    • Security
      • Passwordless
      • Security
    • Speaking
    • About me
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Home»Microsoft365»Azure Active Directory B2B Collaboration
    Microsoft365

    Azure Active Directory B2B Collaboration

    Peter KlapwijkBy Peter KlapwijkSeptember 1, 2017Updated:December 3, 20193 Mins Read

    Earlier this year Microsoft released Azure AD business-to-business Collaboration world wide in general availability. With Azure AD B2B collaboration companies are able to work together with users of partner companies, without providing those users an user account in there own Azure AD. The user accounts of the partner company may exist in Azure AD, but actually any type of email address is supported. Let`s have a look at how this works for both the admin and the user from the partner company. In my example I use the with Azure AD integrated application Salesforce.

    How does it work for the Azure AD Admin

    I have already setup the integration between Azure AD and Salesforce, which provides my users an SSO experience when the access Salesforce from the Office Myapps portal. I have also enabled automatic user provisioning, so for users I provide access to Salesforce automatically an user account in Salesforce is created with the right user role.

    Logged on to the Azure Portal, go to Azure Active Directory, Users and groups and All users. At the top you can choose New guest User.

    Now fill in the email address of the partners user. In my example I used a Gmail account, but it can be any kind of email address; Outlook, Office 365, on-prem Exchange etc.

    The user invited now can be found in your Azure AD. Because it is in your Azure AD, you are able to manage the user account. You can off-course delete the account when access to your Azure AD isn`t wanted anymore. You can add it to groups, to provide access to an Enterprise Application or force a Conditional Access policy to require Multi-factor Authentication when accessing an Enterprise Application.
    You can also have a look at the sign-ins, like you can for your own users accounts.

    When we have a look at the users in the Salesforce admin center, we can see also a (guest) user account is created at that site.

    This is all from the Admin perspective.

    How does it look like for the user

    When you are invited as a partner user, you receive an email invitation like below. When you click on Get started you are redirected to the logon page from Azure AD.

    Depending on the type of account you received the invitation on, you are able to sign-n with your Office 365 or Microsoft account or to create a Microsoft account using your existing email address.
    In my example I used Gmail, so I`m asked to create an account. The email address is already filled in and you need provide an password of choice.

    To verify you own the email address you provided, a code is send to your email address. Fill in the received code

    You get a Welcome screen with some info on what information you share with this organization

    And you are now logged on to the Azure portal, with your Gmail guest account. This account is only assigned Salesforce, but there are lots of resources you can provide access to when using Azure B2B.

    When you click on the Salesforce icon, you are logged on directly to Salesforce without providing a username or password.

    If the administrator of the Azure tenant setup your guest account to use MFA, you first need to setup MFA before you are logged on to Salesforce.

    Azure B2B licensing

    What kind of licenses you need to purchase for using Azure AD B2B depends on what kind of access you provide to your partner users.
    Have a look at this Azure AD B2B licensing guide for all the information.

    Azure AD Identity Management Salesforce SSO
    Share. Facebook Twitter LinkedIn Email WhatsApp
    Peter Klapwijk
    • Website
    • X (Twitter)
    • LinkedIn

    Peter is a Security (Intune) MVP since 2020 and is working as Modern Workplace Engineer at Wortell in The Netherlands. He has more than 15 years of experience in IT, with a strong focus on Microsoft technologies like Microsoft Intune, Windows, and (low-code) automation.

    Related Posts

    Manage Microsoft Edge Chromium extensions with Microsoft Intune

    February 18, 2020

    How to protect against ransomware?

    September 15, 2016

    Intune Mobile Application Management

    September 13, 2016
    Add A Comment
    Leave A Reply Cancel Reply

    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Awards
    Sponsor
    Latest Posts

    Change a Microsoft 365 Apps installation from 32-bit to 64-bit

    January 30, 2026

    Intune PowerShell script installer feature

    January 17, 2026

    Configuring the time zone with Intune, what are our options?

    January 9, 2026

    Configure Azure file shares for Entra joined Windows devices and cloud identities

    December 19, 2025
    follow me
    • Twitter 4.8K
    • LinkedIn 6.1K
    • YouTube
    • Bluesky 1.5K
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Defender Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Windows Windows 10 Windows10 Windows 11 Windows 365 Windows Autopilot Windows Update
    Awards
    Sponsor
    Follow me on Twitter
    Tweets by inthecloud_247
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Defender Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Windows Windows 10 Windows10 Windows 11 Windows 365 Windows Autopilot Windows Update
    Archives
    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

     

    Copyright © 2025 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved, No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand; Don’t pass off my work as yours, it’s not nice.

    Recent Comments
    • Ludovic on Intune PowerShell script installer feature
    • djoek on Application installation issues; Download pending
    • Artin on Onboarding a passwordless Azure AD user
    • George on Configure Azure file shares for Entra joined Windows devices and cloud identities
    • Ganesh sekarbabu on Configure Azure file shares for Entra joined Windows devices and cloud identities
    most popular

    Application installation issues; Download pending

    October 1, 2024

    How to change the Windows 11 language with Intune

    November 11, 2022

    Restrict which users can logon into a Windows 10 device with Microsoft Intune

    April 11, 2020

    How I solved a strange Kerberos issue

    December 12, 2024
    Recent Comments
    • Ludovic on Intune PowerShell script installer feature
    • djoek on Application installation issues; Download pending
    • Artin on Onboarding a passwordless Azure AD user
    • George on Configure Azure file shares for Entra joined Windows devices and cloud identities
    • Ganesh sekarbabu on Configure Azure file shares for Entra joined Windows devices and cloud identities
    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

    Copyright © 2023 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved. No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand: Don’t pass off my work as yours, it’s not nice.

    Peter Klapwijk – In The Cloud 24-7
    X (Twitter) LinkedIn YouTube RSS Bluesky
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}