An identity governance team publishes access packages that partner staff should be able to request for themselves. The partners sign in with their own Microsoft Entra tenant, and the team wants those external users to discover and request the packages directly while keeping the requests scoped to that one partner. Which Microsoft Entra entitlement management object must the administrator define so that users from the partner tenant are recognised as an eligible external requestor population?
- AA B2B direct connect trust that maps the partner tenant into shared channels for requestors
- BA dynamic membership group that captures partner guest accounts once they have been invited
- CA cross-tenant access setting that enables inbound B2B collaboration for the partner tenant
- DA connected organization that references the partner tenant as an allowed external requestor source Correct
Why A is wrong: B2B direct connect enables shared channel access without guest objects but is not how entitlement management identifies an external requestor population for access packages.
Why B is wrong: A dynamic group can collect existing guests but cannot make a partner directory a recognised external requestor source before any user is onboarded.
Why C is wrong: Cross-tenant access settings govern whether collaboration is permitted at all, but they do not define the external requestor population entitlement management offers packages to.
Why D is correct: A connected organization registers the partner directory so its users are treated as a known external population that access package assignment policies can target for self-service requests.