I have a prospect who has set up their global tenant in the UK. They now wish to deploy Business Central in Hong Kong and purchase the license through CSP. Since their email address is associated with the global tenant, I would like to understand how we can implement Single Sign-On (SSO) for the Business Central deployment in the Hong Kong data center.
Your assistance on this matter would be greatly appreciated. Thank you.
To implement Single Sign-On (SSO) for Business Central in this case, the key point is tenant association:
✅ Solution: Ensure the Hong Kong environment is created under the same Azure AD tenant (UK global tenant), even if it's deployed in a different region via CSP. This setup will allow seamless SSO using existing credentials.
If they attempt to use a different tenant for the Hong Kong deployment, SSO won't work natively and cross-tenant access/guest setup would be required, which is not supported for Business Central SaaS.
✅ Mark this answer as verified if it helps you.
Thank you for your response and for clarifying the SSO aspect. I now have a question regarding license procurement. The customer wishes to purchase the license in Hong Kong; however, due to Microsoft's policy, they can only procure the license in the UK, where their global tenant is located.
Is it possible to set up a sub-tenant in Hong Kong that can be associated with the UK tenant, allowing us to procure the license in Hong Kong while still benefiting from SSO? Thank you.
Azure AD is global and typically tied to the initial region where the tenant was created — in your case, UK. However, Business Central environments can be deployed in different geographic regions, including Hong Kong, as long as it's supported. You can create a Business Central environment in the Hong Kong region, even if the M365 tenant is UK-based.
SSO Support Across Regions
To enable Single Sign-On (SSO) for your Business Central deployment in Hong Kong while keeping the UK tenant as the global identity provider, you can configure the Hong Kong environment to authenticate users through the existing UK Azure Active Directory (Azure AD) tenant. This means users in Hong Kong will log in using the UK tenant credentials, ensuring centralized identity management. During the Business Central setup in Hong Kong, make sure it is linked to the UK Azure AD tenant for authentication. All Hong Kong users must either exist in the UK tenant or be added via Azure AD B2B collaboration. Licenses for Business Central should also be assigned to these users through the UK tenant using the CSP (Cloud Solution Provider) model. Optionally, Once everything is set up, users will simply access the Hong Kong Business Central URL. They will be redirected to the UK tenant for authentication and then brought back to the Hong Kong environment after a successful login—ensuring seamless access with a single set of credentials.
Sohail Ahmed
2,655
Mansi Soni
1,574
YUN ZHU
1,453
Super User 2025 Season 1