Azure AD cross-tenant access settings Preview
Hi All,
Microsoft recently announced the Azure AD cross-tenant access settings Preview
Collaborate more securely with new cross-tenant access settings
Overview: Cross-tenant access with Azure AD External Identities (Preview)
data:image/s3,"s3://crabby-images/8c02f/8c02ff2ad69625ec9a06d4a16760365b07406c60" alt=""
The settings can be found in Azure Active Directory > External Identities
data:image/s3,"s3://crabby-images/79593/795930315f468b002c66a1951b404cf6e6a58d5e" alt=""
If you click on "Default settings" and then edit the defaults you will see the details
data:image/s3,"s3://crabby-images/0bdad/0bdaddc523b8f4babd8f550783afb7e79fcc022d" alt=""
data:image/s3,"s3://crabby-images/082e4/082e42cdfd78aefa6bd60aeeee8dca41a46c70fd" alt=""
data:image/s3,"s3://crabby-images/5a0b1/5a0b1311f3be7a5acc6c5e1a5e5e9680af5a46c0" alt=""
I find this one of the most interesting Settings. If you have already done MFA in your home Tenant - i can trust that Setting. Something i would recommend for example.
data:image/s3,"s3://crabby-images/12479/12479e216ba53b04b80bbbb8d5a09ec8892c175e" alt=""
There is also a Workbook that shows the cross-tenant Activity
data:image/s3,"s3://crabby-images/88ff8/88ff8865879528efa7b6bb1592eee73980c51165" alt=""
This gives you already a good overview - but if you want to see more details, open up the LogAnalytics Query
data:image/s3,"s3://crabby-images/f9f92/f9f92843c608332d406a3423f79738fa86da89f2" alt=""
That's the Query behind the cross-tenant activity Workbook
data:image/s3,"s3://crabby-images/1326e/1326edd404e50d44919229a9467c9906366b571c" alt=""
Microsoft has released a PowerShell Module based on the MGGraph Module
Find-Module MSIdentityTools
Install-Module MSIdentityTools
data:image/s3,"s3://crabby-images/21bd0/21bd0b448ff78938e1ab2e18fdcedd4e514b2884" alt=""
These are the available Commands of the Module
Get-Command -Module MSIdentityTools
data:image/s3,"s3://crabby-images/5e3d2/5e3d2c9ca9dfc7c3bf32b3c48b5ed23c27bfc6b7" alt=""
With the following Commands you should be able to see the Names of the Tenant (ResolveTenantId) - but does not work here. Any hints?
Connect-MGGraph -Scope AuditLog.Read.All
Select-MgProfile -Name beta
Get-MSIDCrossTenantAccessActivity -SummaryStats -ResolveTenantId
Select-MgProfile -Name beta
Get-MSIDCrossTenantAccessActivity -SummaryStats -ResolveTenantId
data:image/s3,"s3://crabby-images/03681/036810fc8a825c4eb10750c731a8754a0acc2e7d" alt=""
Update 07.04.2022
Branko Sabadi found out that you require the following Scope: CrossTenantInformation.ReadBasic.All
But it only works in PowerShell 7 as you can see
data:image/s3,"s3://crabby-images/54d22/54d22623d831aecdfa22d3807cfd411b83523a1f" alt=""
data:image/s3,"s3://crabby-images/603b1/603b19fbd2199de022f803673a874ab5beeb8f88" alt=""
Connect-MgGraph -Scopes AuditLog.Read.All,CrossTenantInformation.ReadBasic.All
Select-MgProfile -Name "beta"
Select-MgProfile -Name "beta"
Resolve-MsIdTenant -TenantId 2e467102-8204-4e70-a8b6-11272c26e761
data:image/s3,"s3://crabby-images/44bb7/44bb7a021870f24b302b65d71b682755550791a5" alt=""
Connect-MgGraph -Scopes AuditLog.Read.All,CrossTenantInformation.ReadBasic.All
Get-MSIDCrossTenantAccessActivity -SummaryStats -ResolveTenantId
Get-MSIDCrossTenantAccessActivity -SummaryStats -ResolveTenantId
data:image/s3,"s3://crabby-images/cfb71/cfb71c099603a2c93384f972cf6102ec9090600f" alt=""
Connect-MgGraph -Scopes AuditLog.Read.All,CrossTenantInformation.ReadBasic.All
Resolve-MsIdTenant -TenantId 815d4e96-e3a0-41eb-9183-2fea315f3277
data:image/s3,"s3://crabby-images/fd2d2/fd2d23d1d1dfc64cadba5d3dc05e05092db11a73" alt=""
Regards
Andres
data:image/s3,"s3://crabby-images/ce79f/ce79f9c98cd007f13e0ccefdf2d821bb659c891e" alt=""