CrossTenantTrust
B2B/guest/multi-tenant app trust across Entra tenants.
Tenant, ApplicationIdentity
── CrossTenantTrust ──▸
Tenant, ExternalIdentity
Source types
Target types
States
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | explicit |
|---|
Rules that emit CrossTenantTrust 8
An API connection referencing a resource in a different Entra tenant represents cross-tenant credential trust.
azurederived
A multi-tenant application registration that has been granted admin consent by a foreign Entra tenant creates a cross-tenant trust allowing the app's SP in the foreign tenant to act under the consented permissions. If the app or its home-tenant SP is compromised, the attacker gains a foothold in the foreign tenant - a lateral-movement primitive.
azurederived
A Private Link Service configured to accept connections from other tenants (via properties.autoApproval or explicit allowedSubscriptions from cross-tenant subscriptions) records a cross-tenant network trust. A PE from a different tenant connecting to this PLS extends network reachability and access across the tenant boundary.
azurederived
A subscription associated/transferred to a different Entra tenant is a boundary-crossing trust (rare, privileged).
azurederived
A Connected VNet peering that crosses Entra tenant boundaries (emitted from explicit azure-vnet-peering-record) extends network reachability AND establishes a cross-tenant trust boundary - a critical lateral-movement fact.
azurederived
azureexplicit
azureexplicit
azureexplicit