web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Pages / How different tenant u...
Power Pages
Unanswered

How different tenant user can login using AzureAD authentication in portal

(0) ShareShare
ReportReport
Posted on by Microsoft Employee

Hi Expert,

 

I am having one requirement where we are hosting the Power App Portal in our company tenant for the client. But the client is asking to use the AzureAD authentication which will different tenant.

When the client tried to log in using there AzureAD account login they get an error saying "its a different tenant and can't log in to the portal. create an external account for the user to give access to the portal".

 

How can I achieve to give access for different tenant users to log in to the portal using AzureAD authentication?

Any help with the issue will be appreciated.

Thanks,

Amit

Categories:
I have the same question (0)
  • justinburch Profile Picture
    Microsoft Employee on at

    Hi @Anonymous,

    Though it's in preview, the simplest approach is the new configuration tooling: https://docs.microsoft.com/en-us/powerapps/maker/portals/configure/use-simplified-authentication-configuration

    Otherwise, you just need to setup the Site Settings perfectly and create a second login button in the header (if you need login to both tenants available): https://docs.microsoft.com/en-us/powerapps/maker/portals/configure/set-authentication-identity

     

  • oliver.rodrigues Profile Picture
    9,482 Most Valuable Professional on at

    @Anonymous like @justinburch mentioned, you need to create your other tenant as a new identity provider - and have two buttons for each authentication method

     

    please note that Microsoft is recommending using Azure AD B2C as your only Identity Provider: https://docs.microsoft.com/en-us/powerapps/maker/portals/configure/migrate-identity-providers

     

    ------------

    If you like this post, give a Thumbs up. Where it solved your request, Mark it as a Solution to enable other users find it.

  • justinburch Profile Picture
    Microsoft Employee on at

    Just as a general heads up, Microsoft has appeared to remove their wording regarding only using B2C - we tried to find any trace of this to show a client recently, without success (CC: @OliverRodrigues for awareness).

    Also, I think replacing with B2C would make sense if the client is adding others to their tenant as guests, but if authentication is meant for the client themselves (employee self-service, in a sense) then the standard AAD is probably right. I don't have full context of the portal's usage and initially thought you needed both tenants, but it sounds like you might need to simply replace the initial tenant (your company's) with the clients, instead of having two, since it sounds like the hosting tenant is just the development team's and the actual business that will use it is what you're trying to change it to.

  • oliver.rodrigues Profile Picture
    9,482 Most Valuable Professional on at

    tricky to find @justinburch .. but the link I sent above contains that statement 

     

    I do remember that this was clearer in another page and then MS removed the statement in that page

    azudeadb2c.PNG

  • justinburch Profile Picture
    Microsoft Employee on at

    Ooh, thank you @OliverRodrigues!

  • Community Power Platform Member Profile Picture
    Microsoft Employee on at

    Hi @OliverRodrigues @justinburch 

     

    I have followed the below link to enable B2C button in portal:

    https://readyxrm.blog/2019/07/24/configure-azure-ad-b2c-for-powerapps-portals/

    https://docs.microsoft.com/en-us/powerapps/maker/portals/configure/use-simplified-authentication-configuration#configure-the-azure-active-directory-b2c-provider

    But it is not allowing to use the client Microsoft (MSFT )account to signing to our in-premise tenant environment.

    Basically my company is hosting the client portal in our company tenant (i.e example our tenant domain is abcdef@aarete.com and client domain is xyz@abc.com). So, when user is clicking on B2C button to login then it is taking to Azure account to signing but it is not asking to log in for the MSFT account.

    Is that what B2C mean that it will take to Azure account and it will ask you to create account there and it will not ask to use existing MSFT account ( xyz@abc.com) to log in?

     

    I am missing anything which needs to be done?

     

    Thanks,

    Amit

  • justinburch Profile Picture
    Microsoft Employee on at

    Hi @Anonymous,

    As I mentioned before, I don't think you actually want B2C - B2C is meant to be Azure AD for external customers (your customer's customers), which is why it's not asking for their Microsoft credentials. You just need to setup basic Azure AD using the client's information, and this is pretty standard.

    The following blog should help here: https://debajmecrm.com/dynamics-365-adx-portals-dynamics-365-portal-authentication-with-external-identities-part-i-authentication-with-azure-active-directory/

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Congratulations to the July Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Pages

#1
Mohsin Ali Profile Picture

Mohsin Ali 33

#2
sannavajjala87 Profile Picture

sannavajjala87 28 Super User 2026 Season 2

#3
11manish Profile Picture

11manish 22 Super User 2026 Season 2

Last 30 days Overall leaderboard