A well-known limitation is that D365 can only be integrated with SharePoint Online if they are in the same tenant. And even having users from one tenant in another doesn't help - in the browser, a user from one tenant can open the SharePoint site from another tenant seamlessly, but D365 still return 401 unauthorized error. But due to security requirements, we need to separate data.