Skip to content

Commit f1cd389

Browse files
authored
Merge pull request #74665 from MicrosoftDocs/master
Merge master to live 3:00 AM
2 parents e68122f + 58c7024 commit f1cd389

File tree

366 files changed

+2651
-2268
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

366 files changed

+2651
-2268
lines changed

articles/active-directory/b2b/add-users-administrator.md

+8-4
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ services: active-directory
77
ms.service: active-directory
88
ms.subservice: B2B
99
ms.topic: conceptual
10-
ms.date: 04/10/2019
10+
ms.date: 04/11/2019
1111

1212
ms.author: mimart
1313
author: msmimart
@@ -26,11 +26,15 @@ After you add a guest user to the directory, you can either send the guest user
2626
> [!IMPORTANT]
2727
> You should follow the steps in [How-to: Add your organization's privacy info in Azure Active Directory](https://aka.ms/adprivacystatement) to add the URL of your organization's privacy statement. As part of the first time invitation redemption process, an invited user must consent to your privacy terms to continue.
2828
29+
## Before you begin
30+
31+
Make sure your organization's external collaboration settings are configured such that you're allowed to invite guests. By default, all users and admins can invite guests. But your organization's external collaboration policies might be configured to prevent certain types of users or admins from inviting guests. To find out how to view and set these policies, see [Enable B2B external collaboration and manage who can invite guests](delegate-invitations.md).
32+
2933
## Add guest users to the directory
3034

3135
To add B2B collaboration users to the directory, follow these steps:
3236

33-
1. Sign in to the [Azure portal](https://portal.azure.com) as a user who is assigned any of the limited administrator directory roles.
37+
1. Sign in to the [Azure portal](https://portal.azure.com) as a user who is assigned a limited administrator directory role or the Guest Inviter role.
3438
2. In the navigation pane, select **Azure Active Directory**.
3539
3. Under **Manage**, select **Users**.
3640
4. Select **New guest user**.
@@ -55,7 +59,7 @@ After you send the invitation, the user account is automatically added to the di
5559
![Shows B2B user with Guest user type](./media/add-users-administrator/GuestUserType.png)
5660

5761
## Add guest users to a group
58-
If you need to manually add B2B collaboration users to a group as an Azure AD administrator, follow these steps:
62+
If you need to manually add B2B collaboration users to a group, follow these steps:
5963

6064
1. Sign in to the [Azure portal](https://portal.azure.com) as an Azure AD administrator.
6165
2. In the navigation pane, select **Azure Active Directory**.
@@ -72,7 +76,7 @@ You can also use dynamic groups with Azure AD B2B collaboration. For more inform
7276

7377
## Add guest users to an application
7478

75-
To add B2B collaboration users to an application as an Azure AD administrator, follow these steps:
79+
To add B2B collaboration users to an application, follow these steps:
7680

7781
1. Sign in to the [Azure portal](https://portal.azure.com) as an Azure AD administrator.
7882
2. In the navigation pane, select **Azure Active Directory**.

articles/active-directory/b2b/delegate-invitations.md

+36-24
Original file line numberDiff line numberDiff line change
@@ -1,51 +1,63 @@
11
---
2-
title: Delegate invitations for B2B collaboration - Azure Active Directory | Microsoft Docs
3-
description: Azure Active Directory B2B collaboration user properties are configurable
2+
title: Enable B2B external collaboration settings - Azure Active Directory | Microsoft Docs
3+
description: Learn how to enable Active Directory B2B external collaboration and manage who can invite guest users. Use the Guest Inviter role to delegate invitations.
44

55
services: active-directory
66
ms.service: active-directory
77
ms.subservice: B2B
88
ms.topic: conceptual
9-
ms.date: 12/14/2018
9+
ms.date: 04/11/2019
1010

1111
ms.author: mimart
1212
author: msmimart
13-
manager: daveba
14-
ms.reviewer: sasubram
13+
manager: celested
14+
ms.reviewer: mal
1515

1616
ms.collection: M365-identity-device-management
1717
---
1818

19-
# Delegate invitations for Azure Active Directory B2B collaboration
19+
# Enable B2B external collaboration and manage who can invite guests
2020

21-
With Azure Active Directory (Azure AD) business-to-business (B2B) collaboration, you do not have to be a global admin to send invitations. Instead, you can use policies and delegate invitations to users whose roles allow them to send invitations. An important new way to delegate guest user invitations is through the Guest Inviter role.
21+
This article describes how to enable Azure Active Directory (Azure AD) B2B collaboration and determine who can invite guests. By default, all users and guests in your directory can invite guests even if they're not assigned to an admin role. External collaboration settings let you turn guest invitations on or off for different types of users in your organization. You can also delegate invitations to individual users by assigning roles that allow them to invite guests.
2222

23-
## Guest Inviter role
24-
We can assign the user to Guest Inviter role to send invitations. You don't have to be member of the global admin role to send invitations. By default, regular users can also invoke the invite API unless a global admin disabled invitations for regular users. A user can also invoke the API using the Azure portal or PowerShell.
23+
## Configure B2B external collaboration settings
2524

26-
Here's an example that shows how to use PowerShell to add a user to the Guest Inviter role:
25+
With Azure AD B2B collaboration, a tenant admin can set the following invitation policies:
2726

28-
```
29-
Add-MsolRoleMember -RoleObjectId 95e79109-95c0-4d8e-aee3-d01accf2d47b -RoleMemberEmailAddress <RoleMemberEmailAddress>
30-
```
27+
- Turn off invitations
28+
- Only admins and users in the Guest Inviter role can invite
29+
- Admins, the Guest Inviter role, and members can invite
30+
- All users, including guests, can invite
3131

32-
## Control who can invite
32+
By default, all users, including guests, can invite guest users.
3333

34-
In Azure Active Directory, select **User Settings**. Under **External users**, select **Manage External Collaboration Settings**.
34+
### To configure external collaboration settings:
3535

36-
> [!NOTE]
37-
> The **External collaboration settings** are also available from the **Organizational relationships** page. In Azure Active Directory, under **Manage**, go to **Organizational relationships** > **Settings**.
36+
1. Sign in to the [Azure portal](https://portal.azure.com) as a tenant administrator.
37+
2. Select **Azure Active Directory** > **Users** > **User settings**.
38+
3. Under **External users**, select **Manage external collaboration settings**.
39+
> [!NOTE]
40+
> The **External collaboration settings** are also available from the **Organizational relationships** page. In Azure Active Directory, under **Manage**, go to **Organizational relationships** > **Settings**.
41+
4. On the **External collaboration settings** page, choose the policies you want to enable.
3842

39-
![External collaboration settings](./media/delegate-invitations/control-who-to-invite.png)
43+
![External collaboration settings](./media/delegate-invitations/control-who-to-invite.png)
4044

41-
With Azure AD B2B collaboration, a tenant admin can set the following invitation policies:
45+
- **Guest users permissions are limited**: This policy determines permissions for guests in your directory. Select **Yes** to block guests from certain directory tasks, like enumerating users, groups, or other directory resources. Select **No** to give guests the same access to directory data as regular users in your directory.
46+
- **Admins and users in the guest inviter role can invite**: To allow admins and users in the "Guest Inviter" role to invite guests, set this policy to **Yes**.
47+
- **Members can invite**: To allow non-admin members of your directory to invite guests, set this policy to **Yes**.
48+
- **Guests can invite**: To allow guests to invite other guests, set this policy to **Yes**.
49+
- **Enable Email One-Time Passcode for guests (Preview)**: For more information about the one-time passcode feature, see [Email one-time passcode authentication (preview)](one-time-passcode.md).
50+
- **Collaboration restrictions**: For more information about allowing or blocking invitations to specific domains, see [Allow or block invitations to B2B users from specific organizations](allow-deny-list.md).
4251

43-
- Turn off invitations
44-
- Only admins and users in the Guest Inviter role can invite
45-
- Admins, the Guest Inviter role, and members can invite
46-
- All users, including guests, can invite
52+
## Assign the Guest Inviter role to a user
53+
54+
With the Guest Inviter role, you can give individual users the ability to invite guests without assigning them a global administrator or other admin role. Assign the Guest inviter role to individuals. Then make sure you set **Admins and users in the guest inviter role can invite** to **Yes**.
4755

48-
By default, tenants are set to #4. (All users, including guests, can invite B2B users.)
56+
Here's an example that shows how to use PowerShell to add a user to the Guest Inviter role:
57+
58+
```
59+
Add-MsolRoleMember -RoleObjectId 95e79109-95c0-4d8e-aee3-d01accf2d47b -RoleMemberEmailAddress <RoleMemberEmailAddress>
60+
```
4961

5062
## Next steps
5163

articles/active-directory/b2b/toc.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -51,6 +51,8 @@
5151
- name: How-to guides
5252
expanded: true
5353
items:
54+
- name: Manage B2B sharing
55+
href: delegate-invitations.md
5456
- name: Manage invitations
5557
items:
5658
- name: Admins adding B2B users
@@ -61,8 +63,6 @@
6163
href: google-federation.md
6264
- name: One-time passcode authentication
6365
href: one-time-passcode.md
64-
- name: B2B sharing policies
65-
href: delegate-invitations.md
6666
- name: Allow or block invitations
6767
href: allow-deny-list.md
6868
- name: Add B2B users without an invitation

0 commit comments

Comments
 (0)