IP Library › Granted Patent US 12,732,507
Granted Patent B2
US 12,732,507 · App. 18/518,777 · Granted Sep 8, 2026

Cross-tenant access focus

Inventors: Sucharit Sengupta (Bothell, WA); Ramachandra Ravitej Vennapusa (Bothell, WA); Hardy Wijaya (Woodinville, WA); Prakash Narayanan (Round Rock, TX); Shane Anil Pereira (Bellevue, WA); Srikanth Shoroff (Bellevue, WA); Shashidhar Lanka Venkata (Sammamish, WA); Udaya Kumar Bhaskara (Redmond, WA); Abhiram Srinivasan (Coquitlam, CA); Ashutosh Parija (Seattle, WA); Ananda Narayanan Pulamanthole Pisharathu (Redmond, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/105H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,507
App. No.
18/518,777
Granted
Sep 8, 2026
Kind
B2
Abstract

In a cloud computing environment, a cross-tenant access security measure monitors conditional access policies for changes or additions that hamper or threaten an authorized access from an assistant tenant user to a focus tenant. Some cross-tenant access security tracks role assignments to detect rogue roles, or detect hampering role changes. In some cases, focus tenant events and assistant tenant events are correlated in an audit. In some cases, the authorized access is a zero standing time bound access. In some cases, the authorized access is constrained to an IP address range, or constrained to login from a managed device, or both. In some cases, assets are excluded from managed response remediation actions. In some, managed response is modulated by product-specific Role Based Access Control. In some, repeated logins are avoided, to permit faster managed responses.

Claims (52)

1 . A cybersecurity method for focused secure cross-tenant access, the method comprising computationally, by a processor:

granting a first tenant permission to perform at least one remediation action on one or more second assets of a second tenant;

identifying an attempted cross-tenant access from the first tenant to a particular second asset of the second tenant, the attempted cross-tenant access requesting to perform a particular remediation action relating to the particular second asset; and

computationally restricting the attempted cross-tenant access based on at least an exclusion group including the particular second asset,

wherein the exclusion group specifies that the particular second asset is excluded, as opposed to included, based on at least one of: a membership in the exclusion group, an exclusion flag, an exclusion property, or an exclusion tag which is stored in the particular second asset or stored in association with the particular second asset.

2 . The method of claim 1 , further comprising:

computationally creating the exclusion group.

3 . The method of claim 1 , further comprising:

computationally creating a product-specific cross-tenant role for the first tenant.

4 . The method of claim 3 , wherein computationally creating the product-specific cross-tenant role comprises at least one of:

utilizing an access-on-behalf-of service; or

utilizing a workload cross-tenant role management service.

5 . The method of claim 3 , further comprising:

granting, to the first tenant, built-in access to the particular second asset in the second tenant after authorization in the product-specific cross-tenant role.

6 . The method of claim 1 , further comprising:

receiving a granular delegated admin privileges token from an identity provider; and at least one of:

using the granular delegated admin privileges token to query a device API; or

using the granular delegated admin privileges token to query an identity API.

7 . The method of claim 1 , wherein the first tenant is provided with access to perform remediation actions on one or more second devices of the second tenant and restricted from performing remediation actions on one or more other second devices of the second tenant that are in the exclusion group.

8 . The method of claim 1 , wherein the first tenant is provided with access to perform remediation actions for one or more second users of the second tenant and restricted from performing remediation actions for one or more other second users of the second tenant that are in the exclusion group.

9 . A computing system configured for focused secure cross-tenant access, the system comprising:

a digital memory;

a processor set comprising at least one processor, the processor set in operable communication with the digital memory, the processor set configured to:

grant a first tenant permission to perform at least one remediation action on one or more second assets of a second tenant;

identify an attempted cross-tenant access from the first tenant to a particular second asset of the second tenant, the attempted cross-tenant access requesting to perform a particular remediation action relating to the particular second asset; and

restrict the attempted cross-tenant access based on at least an exclusion group that includes the particular second asset;

wherein the exclusion group specifies that the particular second asset is excluded, as opposed to included, based on at least one of: a membership in the exclusion group, an exclusion flag, an exclusion property, or an exclusion tag which is stored in the particular second asset or stored in association with the particular second asset.

10 . The system of claim 9 , wherein the processor set is further configured to:

allow the first tenant to access to another second asset of the second tenant after authorization.

11 . The system of claim 9 , wherein the processor set is further configured to:

determine, based on at least the exclusion group, that the particular second asset comprises an excluded asset.

12 . The system of claim 11 , wherein the exclusion group comprises at least one of: a device group, or a user account group.

13 . The system of claim 9 , wherein the particular remediation action is performed by at least one of:

an endpoint security tool;

an identity security tool; or

an application security tool.

14 . The system of claim 9 , wherein the processor set is configured to implement a permissions calculation software component, which, upon execution, gets a cross-tenant role assignment and calculates a user permission based on at least the cross-tenant role assignment.

15 . The system of claim 9 , wherein the processor set is configured to implement a permissions calculation software component which, upon execution, gets a partner tenant group membership and calculates a user permission based on at least the partner tenant group membership.

16 . A computer-readable storage device configured with data and instructions which, upon execution by a processor, cause a computing system to perform a focused secure cross-tenant access method, the method comprising:

granting a first tenant permission to perform at least one remediation action on one or more second assets of a second tenant:

identifying an attempted cross-tenant access from the first tenant to a particular second asset of the second tenant, the attempted cross-tenant access requesting to perform a particular remediation action relating to the particular second asset; and

computationally restricting the attempted cross-tenant access based on an exclusion group including the particular second asset,

wherein the exclusion group specifies that the particular second asset is excluded, as opposed to included, based on at least one of: a membership in the exclusion group, an exclusion flag, an exclusion property, or an exclusion tag which is stored in the particular second asset or stored in association with the particular second asset.

17 . The computer-readable storage device of claim 16 , wherein the method further comprises:

granting, to the first tenant, access to another second asset that is not in the exclusion group based on an authorization of the first tenant.

18 . The computer-readable storage device of claim 16 , wherein the method further comprises:

determining a product-specific role status of another second asset based on at least a product-specific cross-tenant role.

19 . The computer-readable storage device of claim 16 , wherein the method further comprises;

receiving a granular delegated admin privileges token from an identity provider.

20 . The computer-readable storage device of claim 19 , wherein the method further comprises at least one of:

using the granular delegated admin privileges token to query a device API regarding the particular second asset; or

using the granular delegated admin privileges token to query an identity API regarding the particular second asset.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2023
From: SENGUPTA, SUCHARIT; VENNAPUSA, RAMACHANDRA RAVITEJ; WIJAYA, HARDY; NARAYANAN, PRAKASH; PEREIRA, SHANE ANIL; SHOROFF, SRIKANTH; LANKA VENKATA, SHASHIDHAR; BHASKARA, UDAYA KUMAR; SRINIVASAN, ABHIRAM; PARIJA, ASHUTOSH; PULAMANTHOLE PISHARATHU, ANANDA NARAYANAN
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 065675/0316 →
Continuity (2)
Provisional Application 63547026 · Nov 2, 2023
Related Publication 20250150458A1 · May 8, 2025
References Cited (45)
US 7543140B2 · Dillaway et al. · 2009 [cited by applicant]
US 7900248B2 · Ellison et al. · 2011 [cited by applicant]
US 11516222B1 · Srinivasan · 2022 [cited by examiner]
US 11777992B1 · Cross · 2023 [cited by examiner]
US 11799951B1 · Maloo et al. · 2023 [cited by applicant]
US 20090285120A1 · Swan · 2009 [cited by examiner]
US 20140330936A1 · Factor · 2014 [cited by examiner]
US 20160277411A1 · Dani · 2016 [cited by examiner]
US 20170331813A1 · Lander · 2017 [cited by examiner]
US 20170331832A1 · Lander · 2017 [cited by examiner]
US 20180083967A1 · Subramanian · 2018 [cited by examiner]
US 20210392142A1 · Stephens · 2021 [cited by examiner]
US 20220345458A1 · Kumarji · 2022 [cited by examiner]
US 20230153449A1 · Li et al. · 2023 [cited by applicant]
Yang, Shin-Jer, Pei-Ci Lai, and Jyhjong Lin. “Design role-based multi-tenancy access control scheme for cloud services.” 2013 International Symposium on Biometrics and Security Technologies. IEEE, 2013. (Year: 2013). [cited by examiner]
“Application as Filed in U.S. Appl. No. 17/820,617”, filed Aug. 18, 2022, 46 Pages. [cited by applicant]
“Application as Filed in U.S. Appl. No. 17/835,050”, filed Jun. 8, 2022, 70 Pages. [cited by applicant]
“Application as Filed in U.S. Appl. No. 18/328,089”, filed Date: Jun. 2, 2023, 63 Pages. [cited by applicant]
Vasil Michev, “Cross-tenant access policy (XTAP) and the Graph API”, retrieved from << https://www.michev.info/blog/ post/3681/cross-tenant-access-policy-xtap-and-the-graph-api >>, Posted onFebruary 10, 2022, 12 pages. [cited by applicant]
“View applied Conditional Access policies in Azure AD sign-in logs”, retrieved from << https://learn.microsoft.com/en-us/azure/active-directory/reports-monitoring/how-to-view-applied-conditional-access-policies >>, Feb.… [cited by applicant]
Abhishek Kumar, “Enforcing Zero Standing Access”, retrieved from << https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2ClzC >>, Sep. 24, 2018, 8 pages. [cited by applicant]
“Microsoft Defender Experts for Hunting”, retrieved from << https://learn.microsoft.com/en-us/microsoft-365/security/defender/defender-experts-for-hunting?view=o365-worldwide >>, Mar. 6, 2023, 2 pages. [cited by applicant]
“Microsoft Security Experts”, retrieved from << https://www.microsoft.com/en-us/security/business/services/ >>, No. later than May 2, 2023, 5 pages. [cited by applicant]
Vasu Jakkal, “Building a safer world together with our partners—introducing Microsoft Security Experts”, retrieved from << https://www.microsoft.com/en-us/security/blog/2022/05/09/building-a-safer-world-together-with-ou… [cited by applicant]
“Microsoft Defender Experts for Hunting proactively hunts threats”, retrieved from << https://www.microsoft.com/en-us/security/blog/2022/08/03/microsoft-defender-experts-for-hunting-proactively-hunts-threats/ >>, Aug. 3… [cited by applicant]
“Create device security policies in Basic Mobility and Security”, retrieved from << https://learn.microsoft.com/en-us/microsoft-365/admin/basic-mobility-security/create-device-security-policies?view=o365-worldwide >>, F… [cited by applicant]
“Audit logging and monitoring overview”, retrieved from << https://learn.microsoft.com/en-us/compliance/assurance/ assurance-audit-logging >>, Apr. 3, 2023, 7 pages. [cited by applicant]
“Overview: Cross-tenant access with Azure AD External Identities”, retrieved from << https://learn.microsoft.com/en-us/azure/active-directory/external-identities/cross-tenant-access-overview >>, Mar. 15, 2023, 12 pages. [cited by applicant]
“Introduction to granular delegated admin privileges (GDAP)”, retrieved from << https://learn.microsoft.com/en-us/ partner-center/gdap-introduction >>, Mar. 21, 2023, 2 pages. [cited by applicant]
“Use the What If tool to troubleshoot Conditional Access policies”, retrieved from << https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/what-if-tool >>, Mar. 15, 2023, 4 pages. [cited by applicant]
“Microsoft Intune securely manages identities, manages apps, and manages devices”, retrieved from << https://learn.microsoft.com/en-us/mem/intune/fundamentals/what-is-intune >>, Apr. 2, 2023, 11 pages. [cited by applicant]
“Device groups in Microsoft Defender for Business”, retrieved from << https://learn.microsoft.com/en-us/microsoft-365/ security/defender-business/mdb-create-edit-device-groups?view=o365-worldwide >>, May 17, 2023, 4 pag… [cited by applicant]
“Manage Microsoft Entra groups and group membership”, retrieved from << https://learn.microsoft.com/en-us/entra/fundamentals/how-to-manage-groups >>, Oct. 23, 2023, 11 pages. [cited by applicant]
“GDAP frequently asked questions”, retrieved from << https://learn.microsoft.com/en-us/partner-center/gdap-faq >>, Nov. 9, 2023, 24 pages. [cited by applicant]
“Introduction to granular delegated admin privileges (GDAP)”, retrieved from << https://learn.microsoft.com/en-us/partner-center/gdap-introduction >>, Jul. 31, 2023, 2 pages. [cited by applicant]
“GDAP bulk migration tool”, retrieved from << https://learn.microsoft.com/en-us/partner-center/gdap-bulk-migration-tool >>, May 24, 2023, 18 pages. [cited by applicant]
“Overview: Cross-tenant access with Microsoft Entra External ID”, retrieved from << https://learn.microsoft.com/en-us/entra/external-id/cross-tenant-access-overview >>, Nov. 7, 2023, 18 pages. [cited by applicant]
“Microsoft Defender Experts for Hunting”, retrieved from << https://learn.microsoft.com/en-us/microsoft-365/security/ defender/defender-experts-for-hunting?view=o365-worldwide >>, Oct. 18, 2023, 2 pages. [cited by applicant]
“Microsoft Security Experts”, retrieved from << https://www.microsoft.com/en-us/security/business/services/ >>, No. later than Nov. 10, 2023, 5 pages. [cited by applicant]
Vasu Jakkal, “Building a safer world together with our partners—introducing Microsoft Security Experts”, retrieved from << https://www.microsoft.com/en-us/security/blog/2022/05/09/building-a-safer-world-together-with-ou… [cited by applicant]
“Microsoft Defender Experts for Hunting proactively hunts threats”, retrieved from << https://www.microsoft.com/en-us/security/blog/2022/08/03/microsoft-defender-experts-for-hunting-proactively-hunts-threats/ >>, Aug. 3… [cited by applicant]
Alam, et al., “A Cross Tenant Access Control (CTAC) Model for Cloud Computing: Formal Specification and Verification”, IEEE, vol. No. 12, Issue No. 6, Dec. 29, 2016, pp. 1259-1268. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/052170, Jan. 29, 2025, 14 Pages. [cited by applicant]
Madani, et al., “Access Control for Collaboration in Cloud Environment: A Comparative Analysis”, IEEE, Oct. 26, 2023, pp. 1-7. [cited by applicant]
International Preliminary Report on Patentability (Chapter I) Received for PCT Application No. PCT/US2024/052170, mailed on May 15, 2026, 8 pages. [cited by applicant]