A company implements Microsoft Entra ID Cross-Tenant Synchronization to share identities between its parent company and a recently acquired subsidiary's Entra ID tenant. The security team needs to ensure that only the subsidiary's AI research team is synchronized to the parent tenant. What must be configured?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft Entra ID Cross-Tenant Synchronization supports scoping filters that can restrict which users are synchronized based on attributes. Configuring a scoping filter based on the AI research team's group membership ensures only those users are provisioned to the parent tenant.
Full explanation below image
Full Explanation
B is correct because Microsoft Entra ID Cross-Tenant Synchronization supports scoping filters that can restrict which users are synchronized based on attributes. Configuring a scoping filter based on the AI research team's group membership ensures only those users are provisioned to the parent tenant. A is incorrect because cross-tenant access inbound settings control whether identities from the subsidiary can access resources in the parent tenant, not which users are synchronized via cross-tenant sync. C is incorrect because connected organizations in Entitlement Management are for external access package management via B2B collaboration, not for provisioning synchronized identities via cross-tenant sync. D is incorrect because guest invitation policies with domain allowlists control who can be invited as B2B guests, not cross-tenant sync scoping.