⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Microsoft 3656 min read

Microsoft Entra Tenant Governance (Preview): Visibility and Control Across Your Tenant Landscape

By Jamie Hamilton · Published

Most large organisations, and plenty of mid-sized ones, end up with more Microsoft tenants than they intended. Mergers and acquisitions bring their own. Test environments get stood up and never removed. Privacy-partitioned workloads need their own. And individual users create tenants without anybody centrally knowing.

It adds up quietly, and before long nobody has a clear picture of what exists, how any of it is configured, or how much risk it carries. Microsoft Entra Tenant Governance, now in public preview, is aimed at exactly that.

The problem is the tenants you cannot see

Managing the tenants you know about is a solved problem. Finding the ones you do not is the hard part, and until now there has been no native Microsoft tool for it.

Tenants created outside central IT sit outside central governance by definition. They tend to have weak security configuration, unmonitored external access, and sometimes multitenant applications holding permissions that reach into your primary tenant. That last one is the reason this is a security question rather than an inventory question: an ungoverned tenant with a cross-tenant application permission is a path into the environment you do govern.

What Tenant Governance does

It is a set of capabilities in the Microsoft Entra admin centre covering four things:

  • •Discovering tenants related to yours
  • •Establishing formal governance relationships across them
  • •Monitoring configuration drift against a baseline you define
  • •Controlling how new tenants get created in the first place

1. Related Tenants, the discovery engine

This identifies tenants that have a relationship with yours, working from signals rather than from a list somebody maintains:

  • •B2B access, both inbound and outbound, including administrative access
  • •Multitenant applications holding cross-tenant permissions
  • •Shared billing accounts

You get a view of how many relationships exist, how active each one is, and which represent the most risk. For a lot of organisations this alone justifies looking at it, because the first run surfaces tenants nobody knew about.

2. Governance Relationships, formalising oversight

Once you know which tenants need oversight, this is how you establish it properly rather than by holding a separate administrator credential for each one:

  • •Invitation, request and approval workflows for cross-tenant administrative access
  • •Least-privilege access so administrators in the governing tenant can act in governed tenants without holding standing rights
  • •Governance policy templates to apply consistent permissions across multiple tenants
  • •Streamlined application provisioning into governed tenants

The practical gain is that access becomes something granted and revocable rather than a set of credentials in a password manager, which is how most multi-tenant administration works today.

3. Configuration Management, monitoring drift

The most immediately useful of the four for anyone already running several tenants. It lets you:

  • •Author a configuration baseline in JSON defining the desired state of tenant resources
  • •Take snapshots of a tenant’s current configuration
  • •Create monitors that compare actual configuration against the baseline every six hours
  • •View drift, showing which properties changed and how they differ from the baseline

More than 200 resource types are supported across Entra, Intune, Exchange Online, Teams, Purview and Defender. For an organisation obliged to maintain a consistent security posture across tenants, this replaces a spreadsheet and a quarterly manual check.

4. Secure Tenant Creation, closing the door

The other three find and fix; this one prevents. Controls apply at the point a tenant is created:

  • •Governance policy templates that apply automatically when users create new tenants
  • •Control over which users can create add-on tenants through billing account access
  • •A recovery path for administrative access to add-on tenants when the original administrator leaves or the tenant is compromised

This is the capability with the longest-lasting value, because discovery only ever tells you about the sprawl that has already happened.

Licensing

Two service levels, Tenant Governance Basic and Tenant Governance Premium, with feature availability at each tier set out in Microsoft's Entra licensing documentation. The configuration management APIs are generally available; the other capabilities are in preview but are supported by Microsoft Customer Support for production use.

What preview status means here

  • •Features may change before general availability
  • •Preview services do not carry standard service level agreements
  • •It should be evaluated deliberately before anything critical depends on it

Worth reading that alongside the scope of what is being delivered. Discovery, governance, configuration monitoring and creation controls together is not a small feature, and shipping all four suggests Microsoft treating multi-tenant management as a first-class problem rather than an edge case.

Who should care

If you run more than one Microsoft tenant, or you suspect your organisation has tenants nobody is tracking, the discovery capability is worth running for the answer alone.

If you run exactly one tenant and are confident that is true, this is not aimed at you yet. The thing worth taking from it anyway is the underlying point: cross-tenant application permissions and B2B access are relationships into your environment, and they deserve the same attention as the accounts inside it.

Frequently asked questions

What is Microsoft Entra Tenant Governance?

A set of capabilities in the Microsoft Entra admin centre, currently in public preview, for organisations that have more than one Microsoft tenant. It covers four things: discovering tenants related to yours, establishing formal governance relationships across them, monitoring configuration drift against a baseline you define, and controlling how new tenants are created.

How does it discover tenants we do not know about?

It works from signals rather than from a list somebody maintains: B2B access both inbound and outbound including administrative access, multitenant applications holding cross-tenant permissions, and shared billing accounts. The output shows how many relationships exist, how active each is, and which carry the most risk. Most organisations running it for the first time find tenants they were not aware of.

What is configuration drift monitoring?

You author a baseline in JSON describing the desired state of tenant resources, then create monitors that compare the actual configuration against it every six hours and report which properties have changed. More than 200 resource types are supported across Entra, Intune, Exchange Online, Teams, Purview and Defender. For organisations maintaining consistent posture across tenants it replaces a spreadsheet and a manual quarterly check.

What licensing does Tenant Governance need?

There are two service levels, Tenant Governance Basic and Tenant Governance Premium, and which features sit at which tier is set out in Microsoft’s Entra licensing documentation. The configuration management APIs are generally available. The other capabilities are in public preview, though Microsoft Customer Support does support them for production use.

Should we use a preview feature in production?

Carefully, and with the limits understood. Preview features may change before general availability and do not carry standard service level agreements, so nothing critical should depend solely on one. Microsoft supporting these particular capabilities for production use through Customer Support is a stronger signal than most previews carry, but the evaluation still belongs before the dependency rather than after.

Is this relevant if we only have one tenant?

Not directly, and it is not aimed at you yet. The transferable point is that cross-tenant application permissions and B2B access are relationships reaching into your environment, and they deserve the same scrutiny as the accounts inside it. An ungoverned tenant holding a cross-tenant permission into your primary one is a path in, which is why this is a security question rather than an inventory question.

Need help working out how this fits your Microsoft 365 environment?

Managed M365 support

or call 0403 401 250