3.3. External Identities
💡 First Principle: Collaboration should never mean cloning people. B2B keeps every identity homed where it's managed — the partner authenticates to their IdP, your tenant holds only a guest pointer plus your policies about it. Trust, don't copy: accounts you don't copy are accounts you don't have to deprovision.
Care because both failure modes are expensive: block collaboration and the business routes around you (shadow sharing, personal emails); open it wide and you accumulate hundreds of stale guests with real access. The whole 3.3 toolkit — collaboration settings, cross-tenant access, federation options — is the dial between those failure modes, and Phase 5's governance (guest lifecycle, access reviews) is its maintenance plan.
⚠️ Common Misconception: Guests can only be "Microsoft accounts." Redemption follows a fallback ladder — the guest's own Entra tenant, their federated SAML/WS-Fed IdP, Google, Microsoft account, and finally email one-time passcode — so virtually any email address can redeem an invitation with their existing credentials.