Azure Active Directory
Welcome to the Azure Active Directory suggestions and feedback site! We love hearing from you. If you have suggestions, please submit an idea or vote up an idea. We are monitoring the site actively.
Thank you for joining our community and helping improve Azure AD!
Wehave a new log in experience integrated with Azure AD, and we stronglyrecommend you log in with your Azure AD (Office 365) account. If yourUserVoice account is the same email address as your Azure AD account, yourprevious activities will be automatically mapped to your Azure AD account. You can read more here for details: https://techcommunity.microsoft.com/t5/Azure-Active-Directory-Identity/Putting-customers-first-for-f...
-
Update UserType from portal
Be able to see and change the userType from the portal.
(This is only available in Powershell : example: change from Guest -> member, in order to see the directory as an external user.)Set-MsolUser -UserPrincipalName xxxhotmail.com#EXT#@xxxhotmail.onmicrosoft.com -UserType Member
252 votesUpdating the status to indicate that this is a valid suggestion and in our backlog for the future. Please keep the comments/votes coming, knowing more about how you intend to use this helps us prioritize and design better features.
/Elisabeth
-
B2B Guest User Expiration
Looking for the functionality where you can schedule Azure B2B users to exist in your tenant for a predetermined period of time. This would operate similarly to the O365 Groups expiration functionality that exist today. Additionally, managers would be allowed to extend these periods of time and automated reminders would be sent to the manager of these users.
138 votesWe do have some capabilities in this space by using either Access Reviews (https://docs.microsoft.com/en-us/azure/active-directory/governance/manage-guest-access-with-access-reviews) or the newly-released-to-preview Entitlement Management feature (https://docs.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-overview).
If neither of those fulfill your requirements, please add a comment with your scenario for the feature to help us prioritize and design it better.
/Elisabeth
-
remove b2b user when host account is removed
We use Azure B2B extensively. However where B2B users have been into our directory and the user has left the third party organisation and thus had their account removed does not clean up the guest account records in our directory.
Over time this leaves thousands of 'orphaned' guest accounts in our directory, with no ability for our administrators to identify which accounts are orphaned. and thus numbers of guest users in our our directory expands over time infinity
Azure AD should automatically in the in the event of a user object being removed from the third party directory remove the…
53 votesThis is in our backlog, but votes and comments about how you would expect this to work are very helpful to our planning/designing the feature so please keep them coming.
Also, for some scenarios in this space Access Reviews (https://docs.microsoft.com/en-us/azure/active-directory/governance/manage-guest-access-with-access-reviews) can be a good way of removing users who no longer need access, including those who don’t have accounts anymore. (Thanks Shawn for pointing that out for everyone!)
/Elisabeth
-
Bring through external user profile fields when using B2B
Currently, when you invite someone from another AzureAD, using the B2B process, only their DisplayName and EmailAddress comes through (both of which are actually provided in the B2B CSV file).
It would be very useful if more profile information could be retrieved, possibly with the user's authorisation.
In particular, details like Firstname, Lastname and Country, would be a useful start, but potentially more profile fields (address, phone numbers, title, etc) would be ideal.
38 votesMarking this as part of our backlog. The votes and comments about how you would use this are really helpful, please keep voting/commenting if this is an interesting scenario for you.
/Elisabeth
-
Allow Azure AD to Azure AD Trust
Add the ability to trust another 365 tenant like exists with on prem active directory. The scenario is a company that has an establish 365 acquires another company that has a 365 environment. In a on prem scenario a domain trust would be put in place, however federation and external user access is the only options. This capability needs to be in place for Azure AD to trust another Azure AD.
37 votes -
customize B2B signup process
When working with partners it is critical to have customized and company specific branding and experience.
complete customization verification emails and domain name in signup URL
26 votesPlease add more comments to let us know what scenarios you’d complete using this feature, and upvote to help us understand its priority for you.
/Elisabeth
-
Who created guest user
Hi,
Currently i have no possibility to see who created a guest-user, except going through the audit-logs.
Maybe the User inviting the guest could be automatically set to the "Manager" attribute(which is currently not available for guest users).Then the monthly review of created guest-accounts would be much easier to handle, as you could ask the inviter/manager if still needed.
23 votesThis is good feedback and is in our backlog but not currently under development. While we work on prioritizing/designing the feature, it’s helpful to hear from you how you would use this information in your scenarios. Please let us know by adding comments here.
Thanks,
Elisabeth -
Can i use Azure AD B2B collaboration together with Azure AD B2C within one tenant?
For external customers we will use Azure AD B2B to login in and for external users (from custom domains i.e. Hotmail.com, Outlook.com) we would like to use Azure AD B2C to log on.
So, one tenant with Azure AD B2B extension and Azure B2C extension coexisting.
21 votesWe’re still considering this, and would love to hear your scenarios for this combination. Please add comments to give us more details.
/Elisabeth
-
Azure AD B2B better support for users who don't know their organisation has O365
We invite quite a lot of external guests into our SPOnline tenant. Originally via the (old Azure portal) bulk add (CSV) B2B process, but more recently via the (new Azure portal) invite guest user B2B/B2C process.
We're getting more and more B2B users that fit into one or more of the following:
- Don't know their organisation has O365
- Don't know their O365 login (it's not always their email address)
- Their organisation/domain is registered for O365, but they don't have a license.
- Have O365, but aren't syncing their AD with AzureAD.
- Aren't able to get their IT to give them O365…
19 votesWe’ve made several improvements in this area to support users who don’t have O365 or who are using email addresses that differ from their O365 login information (such as supporting proxy addresses, direct federation support, and email one-time passcodes), but we know there’s more work to do in this space. Please let us know what other scenarios are causing you and your guests the most pain so we can use that information to triage and prioritize future investments.
/Elisabeth
-
Invitation (or import) Security Groups from other tenant
It would be great if we can import Security Groups from other tenant using Azure B2B.
16 votes -
Restrict Azure B2B Guest Users from viewing Group members in https://myapps.microsoft.com
We would like to restrict B2B Guest users from viewing Groups that they are part of, or from viewing the Members inside those Groups.
Currently, the feature to turn this off (Under Groups - General - Self Service Group Management - Restrict Access to Groups in the Access Panel) exists for ALL the users in the directory and not for the Guest users only. Hence, If we turn this off, then the internal users won't be able to leverage the Self service group membership feature. And if we keep this on then we will end up letting the Guest users…
15 votes -
Allow all and future users from guest tenant to automatically be added as guest users.
Allow all and future users from guest tenant to automatically be added as guest users without invitation email. This would mimic the classic AD trust.
15 votes -
Azure Active Directory, Guest User invite. Allow Group/Distribution lists
Azure Active Directory, Guest User invite. Allow Group/Distribution lists.
You can not add a guest user email address if its a distribution list. You have to use a "user" email address, ticket REG:117081816209241. This is would be useful to invite clients to manage certain objects (our example is keyvaults). People come and go and change positions. So using a distro list makes sense here. Using a "shared" mailbox is possible but why extra overhead of an additional mailbox and license.
14 votes -
Allow B2B Guest users to authenticate on Windows 10 Azure AD joined Devices
Allow B2B collaboration users (Guest users who signs in with an account that's managed by another Azure AD directory) login into Azure AD Windows 10 joined devices.
Use case: Collaboration between an educational institution and a public library. Adding student Azure AD (AAD) accounts from the educational institution as AAD Guest accounts in the public library AAD tenant would allow students to use their educational institution AAD credentials to login into the public library Windows 10 AAD joined devices.
12 votes -
Additional information for Azure B2B shadow user during invite creation
Allow us to add more information about the Azure B2B shadow user before sending Azure B2B invite
12 votes -
Intune Ap Protection for Azure B2B users
I have app and I am using Intune app protection and every thing is working fine. I have few azure B2B users.
I also read some app configuration policies.
My question is how I will read the app configuration policies for my Guest users.11 votes -
Mail Enabled External Users - Allow UserType=Member to be Mail Enabled - Allow Inviter to Control Mail Enable/ShowInAddressList on invite
Consider the following scenario. You have a sister company or other company with their own AzureAD tenant, for which you want your users to be able to collaborate. You invite those users to your AzureAD tenant. Depending on how you do so, those external users may be Users or may be Mail Enabled Users.
These External Users may now collaborate with your users using SharePoint or other AzureAD connected business apps, but if you're users are regularly collaborating with these external users, wouldn't it be great if you could make it easy for your users to find them in the…
11 votes -
Enable full Language customization for Azure B2B
Azure AD B2B sends verification code emails to external guests only in english. There is no possibility to change language & design? Besides, if the external user has to set the new passwort for his MSA/AAD, the page is in english and cannot be customized as well. Any plans on this? Or any other idea to get this working in local language? Any plans when there will be a possibility to customize the design? Thanks a lot!
9 votes -
Prevent guest users from seing security groups/content through Access Panel.
In B2B setup guest users can see the members of a security group used for e.g an app through the Access Panel. This is unfortunate as they may be competitiors or membership exposes information that is not supposed to be public.
I am aware that you can turn of group view for all users in the access panel, but the access panel is also a nice feature.
B2C will also solve it, but not a good option for many cases.
Could it be solved with a property hidden or secret only open for internal og owners/admins?
8 votes -
Enrol B2B users into intune
I was hoping to use a large majority of B2B (External Azure Active Directory) accounts for my deployment, including allowing these users to enrol their devices into Intune on my tenant (their current provider does not offer intune). Is this likely to be supported in the future?
8 votes
- Don't see your idea?