Cloud Β· Microsoft Azure Β· Certifications
AZ-500: Cross-tenant access and guest controls
Select one answer. Your result and the explanation will appear immediately.
Question 18
You manage cross-tenant access between contoso.com and a partner tenant, fabrikam.com, which enforces MFA. Contoso has cross-tenant access and external collaboration settings, plus a Conditional Access policy requiring compliant devices and MFA for guest users. Evaluate these statements: 1. Fabrikam users with compliant devices get full app access without other restrictions. 2. The policy accepts MFA claims from fabrikam.com users. 3. Fabrikam guest users can view and modify all contoso.com user properties. Which option correctly evaluates these statements?
Correct answer: False, True, False
A compliant device does not by itself bypass all other Conditional Access requirements; the guest policy also requires MFA, and cross-tenant settings can impose additional controls. With the relevant cross-tenant trust configured, Contoso can accept an MFA claim from Fabrikam. Guest users have restricted directory permissions and cannot view and modify all Contoso user properties.
Exam clue: Separate the three controls: device compliance, trust of an external MFA claim, and guest directory permissions. They are independent settings.
Remember: Cross-tenant access can trust partner MFA and device claims, but it does not grant unrestricted app or directory access. Guest users remain limited by external collaboration and directory permissions.