Azure B2B, B2C or Entra External ID for OneDrive/SharePoint external collaboration
Dear Community,
We have a business requirement that internal staff needs to collaborate files with external customers.
Staff share individual files from OneDrive for Business or SharePoint Online library.External customers will be required to register as guests.External customers will be required to use MFA for authentication.
I am able to get it somewhat working by enabling OneDrive/SharePoint and Azure B2B integration.
The benefit is that external customers will be added as guests even when you share single files, which is not possible by default.
Then the default guest CAP will require guests to have MFA turned on during first registration.
The reason I said somewhat working is that the user experience is not that great.
For example, the page for guest registration cannot be customised so the process seems clunky and confusing for non-technical user, so as the guest registration email.
The SharePoint file sharing email that customers receive are also not customisable. It looks like a spam.
It seems like without using Azure B2C or now the next generation of External ID, I cannot use separate company branding just for my guests.
When comparing different features, it also comes to my understanding that even with an external tenant, the customised signup/signin user flow needs to associated with an enterprise app. And this document specifically called out OneDrive/SharePoint cannot be used to trigger the signup/signin user flow.
https://learn.microsoft.com/en-us/entra/external-id/self-service-sign-up-user-flow
The above link is for B2B but I think for B2C, it is the same deal, even though it didn’t say explicitly.
Any advice is welcome.
Thank you so much!
nhtkid
Dear Community, We have a business requirement that internal staff needs to collaborate files with external customers.Staff share individual files from OneDrive for Business or SharePoint Online library.External customers will be required to register as guests.External customers will be required to use MFA for authentication.I am able to get it somewhat working by enabling OneDrive/SharePoint and Azure B2B integration.The benefit is that external customers will be added as guests even when you share single files, which is not possible by default.Then the default guest CAP will require guests to have MFA turned on during first registration. The reason I said somewhat working is that the user experience is not that great.For example, the page for guest registration cannot be customised so the process seems clunky and confusing for non-technical user, so as the guest registration email.The SharePoint file sharing email that customers receive are also not customisable. It looks like a spam. It seems like without using Azure B2C or now the next generation of External ID, I cannot use separate company branding just for my guests. When comparing different features, it also comes to my understanding that even with an external tenant, the customised signup/signin user flow needs to associated with an enterprise app. And this document specifically called out OneDrive/SharePoint cannot be used to trigger the signup/signin user flow. https://learn.microsoft.com/en-us/entra/external-id/self-service-sign-up-user-flowThe above link is for B2B but I think for B2C, it is the same deal, even though it didn’t say explicitly.https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-user-flow-sign-up-sign-in-customers Any advice is welcome.Thank you so much!nhtkid Read More