All articles

Entra Tenant Governance Is Here: Stop Losing Track of Your Microsoft 365 Tenants

Updated 2 min read

Most organizations know about the production tenant. The test tenant from three years ago, the acquisition tenant and the temporary project tenant are where the interesting conversations start.

Microsoft announced general availability of Entra Tenant Governance on 10 August. The capability is designed to help organizations discover related tenants and manage governance relationships and configuration at a broader level.

Before thinking about policy enforcement, I would use it to answer a simpler question: which tenants are actually part of our organization?

Create a real tenant inventory

Start with the discovered tenants and compare them with the list your organization already believes it owns. For each tenant, record the business purpose, legal entity, primary owner, technical owner, lifecycle state and whether production data is allowed.

Mark unknown tenants for investigation rather than immediately treating them as malicious. There are plenty of legitimate reasons a tenant exists, but “nobody remembers why” is not a governance model.

I would also record emergency access ownership and the domain relationship, because those details become important when the only person who created a lab tenant leaves.

Define a small baseline first

Do not begin with 150 controls. Pick a handful of high-value expectations that you can explain and verify, such as named administrative ownership, emergency access accounts, MFA for privileged roles, a documented external collaboration setting and an agreed lifecycle state.

Use Tenant Governance to help identify configuration differences, then investigate the reason before forcing every tenant to look identical. A test tenant and a regulated production tenant may intentionally have different configurations.

The important part is whether the difference is known and approved.

Separate governance relationships from administration

A central view does not mean every administrator should automatically receive broad permissions across every related tenant. Keep least privilege and separation of duties in the design.

Document who can establish or maintain governance relationships and who approves changes to the baseline. For organizations with subsidiaries or acquired companies, include the local owner in the decision process.

Add tenant creation to the conversation

Discovery helps with the tenants you already have. Governance should also address how new tenants appear. Decide who is allowed to create or request one, what naming and ownership information is required, and how the new tenant enters your inventory.

Without that process, the inventory becomes stale as soon as the next proof of concept starts.

Review the preview features separately

The 10 August announcement includes generally available Tenant Governance capabilities alongside other experiences that may have different release stages. Check the current licensing and status for the specific function you plan to use rather than extending the GA label to every related feature.

Final thoughts

Tenant Governance gives central IT a much better place to start, but discovery is only valuable when it leads to ownership. Find the tenants, name the people responsible, agree a small baseline and then work through the exceptions deliberately.

Share LinkedInX / Twitter

Comments

No account needed. Your name is optional — leave it blank to post anonymously.

0/4000

Loading comments…

Keep reading