⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Microsoft 3659 min read

Microsoft Entra Tenant Governance (Preview): Visibility and Control Across Your Tenant Landscape

Most large organisations (and plenty of mid-sized ones) end up with more Microsoft tenants than they planned for.

Mergers and acquisitions, test environments, privacy-partitioned workloads, and the inevitable “shadow IT” tenants that users create without central IT knowing. It adds up quickly, and before long, nobody has a clear picture of what tenants exist, how they’re configured, or whether they’re introducing risk.

Microsoft Entra Tenant Governance, now in public preview, is designed to solve exactly this problem, giving organisations visibility across all their tenants and the tools to govern them consistently.

This article covers what the feature does, the four capability areas it introduces, licensing, and why it matters for organisations managing Microsoft 365 and Entra ID at any scale.

The problem: tenants you don’t know about (and can’t control)

In most environments, the challenge isn’t just managing the tenants you know about. It’s finding the ones you don’t.

Shadow IT tenants created by individual users or business units often sit outside central governance. They may have weak security configurations, unmonitored external access, or multitenant applications with permissions into your primary tenant.

Until now, there hasn’t been a native Microsoft tool to discover these relationships and bring them under control.

What is Microsoft Entra Tenant Governance?

Tenant Governance is a new set of capabilities within the Microsoft Entra admin center that helps organisations:

  • Discover tenants that are related to theirs
  • Establish governance relationships across tenants
  • Monitor configuration drift against a known-good baseline
  • Control how new tenants are created

It’s broken into four capability areas.

1. Related Tenants: discover what’s out there

This is the discovery engine. It automatically identifies tenants that have a relationship with yours, based on signals like:

  • B2B access (inbound and outbound guest access, admin access)
  • Multitenant applications with cross-tenant permissions
  • Shared billing accounts

You get visibility into how many relationships exist, how active they are, and which tenants represent the most risk. This alone is valuable. Many organisations will discover tenants they didn’t know existed.

2. Governance Relationships: establish cross-tenant control

Once you’ve identified tenants that need oversight, Governance Relationships let you formalise that arrangement. This includes:

  • Invitation, request, and approval workflows for setting up cross-tenant administrative access
  • Least-privilege access so governing tenant admins can perform tasks in governed tenants
  • Governance policy templates to standardise permissions across multiple tenants
  • Streamlined app provisioning into governed tenants

Think of it as a structured way to extend your security governance across an entire tenant ecosystem, without needing to maintain separate admin credentials for every tenant.

3. Configuration Management: monitor for drift

This is where it gets really practical. Configuration Management lets you:

  • Author a configuration baseline (in JSON format) that defines the desired state of tenant resources
  • Take configuration snapshots of a tenant’s current state
  • Create monitors that automatically compare actual configuration against your baseline every six hours
  • View configuration drifts: which properties have changed and how they differ from your baseline

Over 200 resource types are supported across Entra, Intune, Exchange Online, Teams, Purview, and Defender. For organisations that need to maintain consistent security posture across multiple tenants, this is a significant capability.

4. Secure Tenant Creation: control the front door

Rather than trying to find shadow IT tenants after they’ve been created, Secure Tenant Creation gives you controls at the point of creation:

  • Define governance policy templates that automatically apply when users create new tenants
  • Control which users can create new add-on tenants via billing account access
  • Streamline recovery of admin access to add-on tenants if the original admin leaves or the tenant is compromised

This is prevention rather than remediation, and it’s arguably the most important long-term capability in the set.

Licensing

Tenant Governance is available at two service levels:

  • Tenant Governance Basic
  • Tenant Governance Premium

Specific feature availability at each tier is detailed in Microsoft’s Entra licensing documentation. The configuration management APIs are generally available; other capabilities are in preview but are supported by Microsoft Customer Support for production use.

A note on public preview

As with Entra Backup and Recovery, this is currently in public preview:

  • Features may change before General Availability
  • Preview services don’t carry standard SLAs
  • It should be evaluated carefully before relying on it for critical governance workflows

That said, the breadth of what Microsoft is delivering here (discovery, governance, configuration monitoring, and tenant creation controls) signals a serious commitment to multi-tenant management as a first-class capability.

Why this matters

For organisations using Microsoft 365 and Entra ID, tenant sprawl is a real and growing risk. Every ungoverned tenant is a potential entry point, a compliance gap, or an unmonitored configuration that could cause an incident.

Tenant Governance gives you a way to see what’s out there, bring it under control, and keep it aligned with your security and compliance requirements, all from within the Entra admin center.

If you manage more than one Microsoft tenant, or suspect your organisation has tenants you don’t know about, this is worth paying attention to.

Need help understanding how Tenant Governance fits into your Microsoft 365 environment?

or call 0403 401 250