armadillo Posted March 3 Posted March 3 20 minutes ago, Boredguy said: The main sync is with the primary tenancy, but for each tenancy you add, you can pick what users (groups currently in preview) are shared with which other tenancies in your setup. Thank you both for your replies. Can also clarify what you mean about "groups currently in preview", does it mean you can only select by username when you enable sync with other client tenants? until Microsoft release the option to uise groups instead of username?
mikkydoos Posted March 3 Author Posted March 3 @armadillo I think its a case of just go and set it up. Its pretty easy. 1
Boredguy Posted March 3 Posted March 3 Currently MTO is only meant so support syncing of users between tenancies, but it says that group sync is currently in preview, so for example you will be able to use a AD group from site B as membership to a SharePoint site you have in Site A
mikkydoos Posted March 3 Author Posted March 3 (edited) 14 minutes ago, Boredguy said: Currently MTO is only meant so support syncing of users between tenancies, but it says that group sync is currently in preview, so for example you will be able to use a AD group from site B as membership to a SharePoint site you have in Site A Correct. I'm syncing with security groups. The groups don't sync but the users within do. Edited March 3 by mikkydoos
armadillo Posted March 3 Posted March 3 23 minutes ago, mikkydoos said: Correct. I'm syncing with security groups. The groups don't sync but the users within do. Thank you both for your help and clarifying the many queries about Tenants MTO. 1
Boredguy Posted March 3 Posted March 3 1 hour ago, mikkydoos said: Correct. I'm syncing with security groups. The groups don't sync but the users within do. Yep, and maybe soon that group container itself might get sync'd and not user the members of it 1
mikkydoos Posted March 3 Author Posted March 3 1 minute ago, Boredguy said: Yep, and maybe soon that group container itself might get sync'd and not user the members of it Don't hold your breath
armadillo Posted March 3 Posted March 3 (edited) 2 hours ago, Boredguy said: The main sync is with the primary tenancy, but for each tenancy you add, you can pick what users (groups currently in preview) are shared with which other tenancies in your setup. Thank you both for your replies. Can also clarify what you mean about "groups currently in preview", does it mean you can only select by username when you enable sync with other client tenants? until Microsoft release the option to uise groups instead of username? Edited March 3 by armadillo
armadillo Posted March 3 Posted March 3 @Boredguy Can I call you to go through the settings quickly and to help make an informed decision re fetaures, as we will also set up a tenant for the trust. Thanks
Boredguy Posted March 4 Posted March 4 Currently only Users within a Group will be synchronised between sites. If you have a group called "MTO Users" at Site B, that has 20 users in it, you can select that group name in the "Share Users" option in the MultiTenant collaboration page. Currently that group "MTO Users" can't itself be sync'd over, just the members within it. If the public preview works and is rolled out to the rest of us, the group itself could then be synchronised over, so instead of maybe having to add users to a group in Site A to be able to access a SharePoint site, and remembering to add them each time a new person starts, we will be able to select the Group name from Site B that has been synchronised, and then users added will automatically get access. Otherwise as for the features it provides... well everyone synchronised between any of the sites will be able to see Calendar Free/Busy data, Will appear in the Global Address list for e-mails/Teams Membership/SharePoint Permissions/Calls as if they were a normal "member" in that tenancy. Which is basically exactly what the guide says. Now you can get more in depth with who is synchronised between the sites, what AD fields are updated, and a few other tweaks via the Entra Cross-Tenant Syncronization -> Configuration This is where I now do most of my user sync selection these days 1
pete Posted March 4 Posted March 4 ^ You could probably do something like: If UPN contains "otherschooldomain.whatever" and userType=member, add to $dynamic_group ....in entra ID, but you could only get as granular as "all staff from school X" in the main tenant. That would be useful for neatness / automation. For more granular control you're manually adding people to groups (or changing their attributes in local AD/home tenant so they're auto-included in dynamic groups). 1
Boredguy Posted March 4 Posted March 4 Oh I've currently got a dynamic group setup based on the company name starting with our Trust name (since in AD at each site it's the <Trust Name> - <School Name>), but having the group names itself will come in handy down the line before we get round to the single Tenancy/Network.... hopefully before we have 12 schools!
armadillo Posted March 4 Posted March 4 With regards to staff siting on the MTO main Trust tenant, I'm thinking in using Intune to enrol and them; can you please let me know if you encountered any issues with those devices when these users travel from school to school? and any other issues I need to be aware of to help avoid them. example I could think of is printing, DHCP, DNS etc. Your reply is much appreciated. Thanks
Boredguy Posted March 5 Posted March 5 Multi-Tenancy is a cloud only solution. It has nothing to do with providing access to on premise resources controlled via your Active Directory. Most of our central MAT Team have full Azure enrolled laptops, and we have the same SSID broadcast as most of the school sites so they get an "internal" IP address (compared to connecting to a guest SSID where traffic is completely isolated). But they don't get access to printers at any site other than at Head Office since we use Papercut and they aren't part of the domain so don't have an account at that school site. 1
pete Posted March 6 Posted March 6 On 04/03/2026 at 16:02, Boredguy said: Oh I've currently got a dynamic group setup based on the company name starting with our Trust name (since in AD at each site it's the <Trust Name> - <School Name>), but having the group names itself will come in handy down the line before we get round to the single Tenancy/Network.... hopefully before we have 12 schools! Yeah, we set company name for the kids too (with their form tutor as line manager) via Salamander so it's not a future-proof filter for us. Ended up doing: School01 Staff Group in trust tenant. (user.mail -endsWith "@school01domain.whatever") and (user.userType -eq "Member") and (user.jobTitle -ne "Governor") As a couple of school's AD don't have the exchange attributes, so I needed something universal.
armadillo Posted April 8 Posted April 8 Hi again, can you please check the questions below and let me know if it's something you are using across all your schools O365 tenants MTO; The areas we are thinking in using in an O365 MTO setup are: • Basic ad-hoc approval of specific documents in Sharepoint (to be submitted and approved between users at different schools) • Workflows using Power Automate with Microsoft Approvals - e.g. a staff expense claim via Microsoft Form - available to all users in the Trust to submit, to go via a chain of approvers depending on the form criteria • Accessing other school's M365 apps from within Power Automate, e.g. building flows based on triggers from all school Outlooks (for example all 7 accounts@school inboxes) and do things like file automation to Sharepoint/Onedrive locations hosted at different schools. As far as I know, at the moment this is currently only available within the Power Automate flow's home tenant. Thank you in advance for your replies/ opinions.
pete Posted April 8 Posted April 8 We don't do any of the above (expenses and approval workflows are handled in specific platforma). With regard to 7 accounts@schoolname inboxes - are your individual schools handling their own accounts? Or has the finance team not got around to requesting all of those addresses pointing to an accounts@trustname mailbox?
armadillo Posted April 8 Posted April 8 2 hours ago, pete said: We don't do any of the above (expenses and approval workflows are handled in specific platforma). With regard to 7 accounts@schoolname inboxes - are your individual schools handling their own accounts? Or has the finance team not got around to requesting all of those addresses pointing to an accounts@trustname mailbox? HI Pete, yes individual schools have their own accounts@school emails. we will have a Trust central accounts email as part of the MTO setup. With regards to approval workflows; the issue the person who tried to use it across multiple tenants, it didn't work and couldn't reach the other users and apps from the other tenants. Thanks
Boredguy Posted April 8 Posted April 8 MTO is mainly for users to access resources, so having power flow to go to a different tenancy should be possible as long as the account it's run under has access in the first place. All our finance staff either have a Trust e-mail account which is all on one tenancy, or they use their normal school one and pass the resources over Teams or straight into the finance system which is cloud based anyway for us
armadillo Posted April 9 Posted April 9 18 hours ago, Boredguy said: MTO is mainly for users to access resources, so having power flow to go to a different tenancy should be possible as long as the account it's run under has access in the first place. All our finance staff either have a Trust e-mail account which is all on one tenancy, or they use their normal school one and pass the resources over Teams or straight into the finance system which is cloud based anyway for us Thanks for your reply Pete. An example; a Teams channel is set up on trust tenant in an MTO setup, then the finance manager shares access from that Teams channel with other finance staff which exist under different school tenant in the trust, so access needs to be possible and seamless without having to invite using email address etc.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now