Cross-Tenant Access – Security hole? or am I missing a setting?
Hi,
I am just having a play with cross-tenant access as we’d like to use Shared Channels in Teams. I’ve setup a test connection between two tenants. Tenant A is configured for inbound access from Tenant B and then Tenant B is configured to outbound access to Tenant A. This appears be working. The part that makes me very nervous is if I sign into Azure using Tenant A’s URL i.e. https://portal.azure.com/TenantA and then login with my Tenant B credentials I can see all the Azure Entra settings including user names, email, enterprise apps, devices etc. Is this by design? Can I do anything to prevent this kind of access?
Cheers
Rob
Hi, I am just having a play with cross-tenant access as we’d like to use Shared Channels in Teams. I’ve setup a test connection between two tenants. Tenant A is configured for inbound access from Tenant B and then Tenant B is configured to outbound access to Tenant A. This appears be working. The part that makes me very nervous is if I sign into Azure using Tenant A’s URL i.e. https://portal.azure.com/TenantA and then login with my Tenant B credentials I can see all the Azure Entra settings including user names, email, enterprise apps, devices etc. Is this by design? Can I do anything to prevent this kind of access? CheersRob Read More