AD / Entra Terminology Decoder Fast answers for working admins
Microsoft Entra B2B guest user
Answer: A B2B guest is a user object in a resource tenant that represents an external identity authenticated by its home identity provider; access is governed in the resource tenant.
Administrator playbook

Decide, verify, and document

Use the curated answer as a starting point, then prove the outcome against the target tenant or device.

1

What it means

  • The resource tenant stores a local user object
  • Authentication can occur in the user's home tenant or another configured identity provider
  • Cross-tenant access settings and Conditional Access can affect the session
2

What to check next

  1. Confirm home identity and resource tenant
  2. Review invitation/redemption state and user type
  3. Check cross-tenant access, Conditional Access, and resource assignment
3

Verify success

  1. Confirm the object type and identifier in the authoritative tenant.
  2. Compare the portal value with Microsoft Graph or the local device state.
  3. Use IDs—not display names—when proving that two references point to the same object.
4

Escalate when

  • Two portals or APIs return conflicting identifiers for the same expected object.
  • The issue crosses tenant or cloud boundaries.
  • A production authorization decision depends on the object relationship.
Copyable admin briefAnswer, next checks, source, and review date
Inspect Microsoft Graph context
Get-MgContext | Select-Object ClientId,TenantId,Account,AuthType,Scopes

Read-only. Useful when a term or identifier is being interpreted in the wrong tenant.

Evidence to preserve

Object location
Resource tenant
Authentication
Home identity provider
Access control
Resource tenant
  • Tenant ID and cloud
  • Object type and object ID
  • User, app, or device context
  • Where the value was observed