Our consultants work with multiple clients and operate from NKD Agility-managed systems wherever possible. This approach maintains high security and compliance standards while enabling efficient value delivery across customers. We use Microsoft 365 with a central calendar booking system as the single source of truth for scheduling, with delegated email access for administrative staff where required.
Using customer-provided email accounts or calendars creates scheduling conflicts and unnecessary friction. Our priority is for consultants to focus on delivering value, not managing multiple accounts. Therefore, we do not use customer-provided email accounts or calendars.
We prefer Microsoft Entra ID Guest accounts for collaboration. Where on-premises Active Directory (AD) access is unavoidable, we recommend creating AD accounts for our consultants without mailboxes and granting only the minimum permissions. Guest accounts in Entra ID should be the default, with AD accounts used only in limited cases.
1. Configure Cross-Tenant Access in Microsoft Entra ID
Cross-Tenant Access enables secure collaboration between your organisation and NKD Agility for Teams communication, Shared Channels, and device/MFA compliance.
-
Sign in to the Microsoft Entra admin center with admin rights.
-
Navigate to External Identities > Cross-tenant access settings > Organizational settings.
-
Add
nkdagility.comas an organisation. -
Configure:
-
Inbound Access (NKD Agility → Your Organisation):
- Allow access for all NKD Agility users/groups or specify object IDs.
- Allow required applications such as Microsoft Teams.
- Optionally trust MFA and device compliance.
- Enable B2B direct connect for shared channels if needed.
-
Outbound Access (Your Organisation → NKD Agility):
- Allow access for relevant users/groups.
- Allow required applications.
- Enable B2B direct connect for shared channels.
-
-
Save settings.
Microsoft Learn: Cross-tenant access configuration
1.2 Microsoft Teams Domain Access
If your Teams access is restricted by domain, allow nkdagility.com:
- Sign in to the Microsoft Teams admin center.
- Go to Users > External access.
- Choose Allow only specific external domains.
- Add
nkdagility.com. - Save changes.
Microsoft Learn: Manage external access in Microsoft Teams
1.3 Security & Device Compliance
All NKD Agility systems are Microsoft Entra domain-joined and have:
- Enforced encryption
- Automatic updates
- Security policy enforcement
- Antivirus protection
If you require device compliance or MFA for guest access, ensure Cross-Tenant Access settings:
- Include
nkdagility.comin trusted organisations. - Trust NKD Agility Conditional Access policies.
1.4 Using Microsoft Teams Shared Channels (Teams Connect)
Shared Channels let you collaborate in a single channel without adding full Guest accounts or making users switch tenants.
When to choose:
- Shared Channel: Limited collaboration space (files/chat/meetings) with specific NKD Agility consultants.
- Guest Access: Broader access across multiple channels in a Team.
Prerequisites:
- Cross-tenant access configured for
nkdagility.comwith B2B direct connect allowed. - No block on
nkdagility.comin Teams external access or shared channel policies. - Teams policies allowing channel owners to create shared channels and invite external people.
If you host the Shared Channel:
-
Verify Teams policy allows shared channel creation and external invitations.
-
Ensure
nkdagility.comis allowed in external access. -
(Optional) Restrict policy to specific owners.
-
In Teams:
- Go to (or create) the Team.
- Add channel > Shared.
- Share channel with people/teams/organisations.
- Enter consultant email and assign role.
-
NKD Agility user will see the channel under “Shared with me” without tenant switching.
If NKD Agility hosts:
- Only B2B direct connect settings are required. Channel will appear automatically when shared.
Troubleshooting:
- Invite failure: Check B2B direct connect settings.
- Channel not visible: Sign out/in or use Teams web client.
- Policy blocked: Verify Teams policy permissions.
- Conditional Access loop: Enable trust of NKD Agility MFA/device claims.
2. Testing the Setup
After configuration:
- Test Teams chat/call between your users and
nkdagility.com. - Confirm shared channel access or guest access as configured.
- Verify MFA or compliance checks as required.