CrossTenantTrust

B2B/guest/multi-tenant app trust across Entra tenants.

cross_boundary AUTHORIZATION nature: explicit walkable weight 1
Tenant, ApplicationIdentity  ── CrossTenantTrust ──▸  Tenant, ExternalIdentity

Target types

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Rules that emit CrossTenantTrust 8

An API connection referencing a resource in a different Entra tenant represents cross-tenant credential trust.
azurederived
A multi-tenant application registration that has been granted admin consent by a foreign Entra tenant creates a cross-tenant trust allowing the app's SP in the foreign tenant to act under the consented permissions. If the app or its home-tenant SP is compromised, the attacker gains a foothold in the foreign tenant - a lateral-movement primitive.
azurederived
A Private Link Service configured to accept connections from other tenants (via properties.autoApproval or explicit allowedSubscriptions from cross-tenant subscriptions) records a cross-tenant network trust. A PE from a different tenant connecting to this PLS extends network reachability and access across the tenant boundary.
azurederived
A subscription associated/transferred to a different Entra tenant is a boundary-crossing trust (rare, privileged).
azurederived
A Connected VNet peering that crosses Entra tenant boundaries (emitted from explicit azure-vnet-peering-record) extends network reachability AND establishes a cross-tenant trust boundary - a critical lateral-movement fact.
azurederived
move · open · esc close