Microsoft Entra Tenant Governance is now generally available, giving organizations a more coherent way to discover and govern the Microsoft Entra tenants connected to their business. The release matters because many organizations operate more tenants than their official inventory shows: acquisitions, subsidiaries, labs, regional programs, vendor projects, and employee-created environments all leave identity and application relationships behind.
The product is not an automatic cleanup button. Its value comes from combining four disciplines: discover related tenants, formalize administrative relationships, monitor configuration drift, and govern how new tenants are created. The platform can surface evidence and enforce parts of the model, but the organization still needs ownership decisions, escalation paths, and an approved baseline.
What Tenant Governance brings together
| Capability | What it does | Operational question |
|---|---|---|
| Related tenants | Uses Microsoft signals to surface tenants with observable relationships to the governing tenant. | Do we own, trust, tolerate, investigate, or isolate this relationship? |
| Governance relationships | Establishes approved cross-tenant administration with group-mapped, least-privilege roles. | Who can administer which tenant, through which governed path? |
| Configuration management | Defines configuration baselines and reports settings that drift from the desired state. | Which change is expected, which is an exception, and who owns remediation? |
| Secure tenant creation | Limits who can create add-on tenants and applies a governance relationship at creation. | Can the business create what it needs without producing another orphaned tenant? |
Related-tenant discovery is evidence—not an ownership registry
Microsoft Entra can infer tenant relationships from signals including inbound and outbound B2B activity, multitenant application access, and shared billing relationships. These signals are valuable because they reveal connections that procurement spreadsheets and architecture diagrams often miss.
They also need interpretation. Microsoft is explicit that a related-tenant result does not prove legal ownership or administrative control. A customer, supplier, partner, or software publisher may appear because a legitimate relationship exists. The right response is classification, not immediate takeover or removal.
A sound classification model should capture:
- Business owner and technical owner
- Relationship type and evidence source
- Whether the tenant is owned, partnered, unknown, or no longer required
- Administrative access and emergency-access coverage
- Applications, B2B users, billing, domains, and data dependencies
- Target action, due date, and accepted exceptions
Understand the one-way discovery decision
Related-tenant discovery is disabled by default for new tenants. Microsoft’s current guidance says that after an administrator enables it, the setting cannot be reverted. The tenant must also continue to meet the applicable licensing requirements.
That does not make discovery unsafe, but it raises the bar for preparation. Before enabling it, assign a Tenant Governance Administrator or Global Administrator to the task, agree who will review results, decide how long unknown tenants can remain unclassified, and document what happens when a relationship appears risky.
Govern administration without creating another identity sprawl problem
A governance relationship lets a governing tenant administer a governed tenant through an explicit request-and-approval model. Security groups in the governing tenant can be mapped to built-in Microsoft Entra roles in the governed tenant, reducing dependence on unmanaged local administrator accounts or scattered guest identities.
The design still needs least privilege. Avoid one broad group that receives the same powerful role everywhere. Separate routine operations, security response, identity administration, and emergency access. Require privileged activation where appropriate, review membership, and retain an independent break-glass plan for each governed tenant.
Turn configuration drift into an accountable workflow
Tenant configuration management can compare live settings with an approved baseline across supported Microsoft workloads. Microsoft documents support for more than 200 settings through its configuration-management foundation, with monitors currently evaluating at six-hour intervals.
A drift result is not automatically a security incident. It can represent an approved project, an emergency fix, a service change, or a genuine unauthorized deviation. The operating model should route each result through four states:
- Expected: tied to an approved change and within its implementation window.
- Accepted exception: documented business reason, owner, compensating control, and expiration.
- Needs remediation: return the setting to baseline through a controlled change.
- Needs investigation: owner or intent is unknown, or the drift affects a high-risk control.
Start with controls that materially affect access or data exposure—Conditional Access, privileged roles, external collaboration, application consent, authentication methods, and critical service configurations—before attempting an exhaustive baseline.
Secure tenant creation closes the next shadow-tenant gap
Discovery helps with tenants that already exist. Secure tenant creation is about preventing the next unmanaged environment. Approved users can create add-on tenants through a governed path that links the new tenant to the organization’s commercial relationship and creates a governance relationship from the start.
The control should not become a blanket denial of legitimate experimentation. Give engineering, acquisition, and regional teams a fast request path, a clear tenant purpose, an expiration or review date, approved naming and domain rules, and automatic governance ownership. Speed is part of security: if the governed route takes weeks, people will look for another route.
A practical rollout sequence
| Phase | Work | Exit criterion |
|---|---|---|
| Prepare | Confirm licensing, roles, review ownership, classification fields, escalation paths, and data handling. | The team can explain what it will do with every discovery result. |
| Discover | Enable related tenants and classify the first results using B2B, application, billing, and business-owner evidence. | High-risk and unknown relationships have accountable owners. |
| Govern | Establish relationships for owned tenants and map narrowly scoped admin groups to required roles. | Routine administration no longer depends on unmanaged standing accounts. |
| Baseline | Define a small high-value configuration baseline and route drift into change, exception, or incident workflows. | Every monitored control has a remediation owner and response target. |
| Create safely | Move future add-on tenant creation into the governed process. | New tenants receive ownership, billing linkage, and governance on day one. |
Where organizations commonly overreach
- Treating every related tenant as owned: a signal needs business and technical validation.
- Enabling discovery without a queue owner: visibility without follow-through becomes another ignored dashboard.
- Mapping broad roles everywhere: centralized administration can centralize excessive privilege just as easily as least privilege.
- Building an enormous first baseline: start with controls whose drift would create real exposure or outage risk.
- Confusing monitoring with prevention: a six-hour drift monitor is not a real-time block on every configuration change.
- Ignoring lifecycle: governed tenants still need periodic ownership review, retirement criteria, and recovery plans.
Frequently Asked Questions
What does Tenant Governance discover? It surfaces tenants with observable relationships based on signals such as B2B activity, multitenant applications, and shared billing.
Does discovery prove ownership? No. A related tenant is an investigative lead, not a legal or administrative ownership determination.
Can discovery be disabled later? Microsoft currently documents the enablement as nonreversible, so establish ownership and review processes first.
How quickly does drift appear? Microsoft says configuration monitors currently run at six-hour intervals. Use that timing for governance and investigation, not as a real-time preventive control.
Who benefits most? Organizations with multiple business units, acquisitions, regional tenants, labs, B2B relationships, shared applications, or recurring tenant creation.
Does this replace tenant backup? No. Governance helps discover relationships and configuration drift; recovery capabilities address supported restore scenarios. A mature program uses both.
Make every tenant visible, owned, and governed
Accred Consulting can build the tenant inventory, classification model, least-privilege administration design, configuration baseline, drift workflow, and secure creation process behind a practical Entra Tenant Governance rollout.
Plan Tenant Governance