MC931380 - Microsoft 365 admin center will support Tenant restriction v2

Service

Microsoft 365 suite

Last Updated

Nov 13, 2024

Published Nov 11, 2024

Tag

Updated message
New feature
User impact
Admin impact

Summary

The Microsoft 365 admin center will soon support Tenant Restriction v2, enhancing security by limiting user access via external accounts. This feature, part of cross-tenant access settings, will be rolled out from mid-November to late December 2024 and will be off by default. No admin action is required before the rollout.

More information

Updated November 13, 2024: We have updated the content. Thank you for your patience.

Coming soon to the Microsoft 365 admin center: Tenant restrictions v2 enables tenants to enhance security by limiting what users can access when they use an external account to sign in from your networks or devices. The Tenant restrictions v2 settings, included with cross-tenant access settings, are designed to address the security of cross-company exchange.

Authentication plane protection is supported by Microsoft Entra ID. This rollout enables data plane protection for the Microsoft 365 admin center. Learn more: Configure tenant restrictions - Microsoft Entra ID - Microsoft Entra External ID | Microsoft Learn

When this will happen:

General Availability (Worldwide): We will begin rolling out mid-November and expect to complete by late December 2024.

How this will affect your organization:

Before this rollout: Admins are not able to limit what users can access when they use the Microsoft 365 admin center with an external account to sign in from their networks or devices.

After this rollout

  • Tenant restriction v2 (TRv2) can be used to prevent data exfiltration using a foreign identity.
  • TRv2 works by sending special signals to Microsoft Entra ID, Microsoft Account, and other Microsoft resources.
  • Tenant restrictions v2 settings will be off by default and available for admins to enable them.

What you need to do to prepare:

This rollout will happen automatically by the specified date with no admin action required before the rollout. You may want to notify your admins about this change and update any relevant documentation.

Review your current configuration to determine the impact for your organization.

To take advantage of TRv2 in the Microsoft 365 admin center, create a cross-tenant access setting. Learn more: Configure tenant restrictions - Microsoft Entra ID - Microsoft Entra External ID | Microsoft Learn