Microsoft Entra Tenant Governance is now generally available
We’re thrilled to share that Microsoft Entra Tenant Governance is now generally available! This inbuilt feature is designed to help organisations manage and secure their multi-tenant environments efficiently.
Tenants are essentially digital representations of your company, containing its identities, applications, data, and cloud, as well as AI services. Safeguarding these tenants is not just a matter of security; it’s a vital step towards being ready for AI, which in turn supports the secure and resilient infrastructure that AI-driven operations rely on.
Many companies function across numerous tenants, ranging from primary to production, testing, demo, and sometimes even by employees themselves. Over time, primary tenants can drift in configuration, leading to serious security vulnerabilities. Meanwhile, unmanaged or outdated tenants can create blind spots for central IT, expanding the risk landscape. Centralised tenant governance bridges these gaps by bringing all tenants into the spotlight, allowing security and identity teams to enforce consistent security measures, minimise the risks of shadow tenants, and effectively manage all tenants at scale.
Drawing from lessons learned during Microsoft’s response to a high-profile incident, Microsoft Entra Tenant Governance equips you with the tools to shift from a reactive approach to a proactive, streamlined governance model throughout the tenant lifecycle. This solution brings together four key capabilities:
- Identifying Related Tenants: Locate tenants within your organisation and understand their relationships to your business, allowing you to decide which ones to govern and to reduce blind spots before they spiral into issues. Check out our Microsoft Entra tenant estate architecture guide for tips on organising your tenants.
- Governance Relationships: Establish governance for related tenants using least-privileged, cross-tenant delegated administration, enabling management of multi-tenant agents and Microsoft Defender XDR.
- Tenant Configuration Oversight: Set configuration guidelines that dictate the necessary settings across various Microsoft platforms like Microsoft Defender, Microsoft Entra, Microsoft Exchange Online, Microsoft Intune, Microsoft Purview, and Microsoft Teams, and continuously ensure compliance with those standards.
- Secure Tenant Creation: Manage new tenants from their inception by controlling which users are allowed to create them and automatically establishing governance links.
“Tenant Governance allows us to initiate least-privileged governance relationships and continuously monitor each tenant for configuration drift against our Golden Security Baseline, providing consistent visibility across our tenant estate.”
– A Global Enterprise software firm
Since our public preview, we’ve rolled out several enhancements and features:
- Expanded Configurations: We’ve increased the limits on configuration monitors and snapshots per tenant, enhancing scalability for customers with ID Governance, Entra Suite or Microsoft E7 licenses.
- Deeper Tenant Discovery Insights: New features provide richer visibility into interrelated tenants within your organisation.
- Streamlined Configuration Monitoring: A revised admin portal (currently in preview) simplifies creating monitors from snapshots while ensuring permissions are properly configured.
- Enhanced Delegated Admin Features: These improvements streamline tenant switching and governance management across multiple tenants.
- Broadened Secure Tenant Creation: Support for governed add-on tenants under existing billing arrangements, including Enterprise Agreements and Pay-As-You-Go subscriptions.
“With these newly available capabilities, we’re excited to see that Microsoft has introduced enhancements to the Tenant Governance admin portal, making it simpler to set up monitors from snapshots and ensure permissions are appropriately established.”
– A Global Enterprise software firm
To illustrate how companies can leverage Microsoft Entra Tenant Governance, let’s consider two scenarios involving a fictional company named Caldova. First, we’ll focus on bringing an unmanaged tenant under control, and then we’ll ensure that their primary tenant remains secure.
The Scenario: An employee at Caldova set up a test tenant, Caldova-Test, to experiment with a new feature planned for launch in the coming months. Unfortunately, Caldova-Test falls outside the purview of central IT – a type of shadow tenant often lacking essential policies like Conditional Access.
Step 1: Discover Related Tenants. Using Microsoft Entra Tenant Governance, the team can identify all existing tenants—surfacing Caldova-Test as it’s linked to a shared billing account, revealing that several users are accessing admin applications in this tenant.
Step 2: Establish Governance Relationships. The team brings Caldova-Test under central control via a request-approval process, establishing a governance relationship that allows the Tenant Governance Administrator role to be assigned. This means Caldova admins can now deploy configuration monitors without needing additional identities.
Step 3: Define the Baseline. Since Caldova-Test is missing critical settings like Conditional Access policies, there’s a glaring security risk. The team decides to define a configuration baseline for the tenant. Instead of starting from scratch, they take a snapshot of the compliant primary Caldova tenant to use as their guide.
Step 4: Monitor for Configuration Drift. They continuously check for any discrepancies from the baseline to spot issues early.
Step 5: Address and Refine. Whenever drift is detected, the team takes targeted actions to fix things and makes necessary adjustments to their monitoring processes as their governance program evolves.
While managing tenants outside central IT control is one aspect, ensuring that the primary tenant remains compliant is equally vital and often overlooked.
The Scenario: Caldova’s IT team needs to ensure that all configurations in the primary tenant meet security and compliance standards. However, during an audit, they discover that it no longer meets device compliance standards. Swift action is required to identify the cause and return to compliance.
Step 1: Capture a Desired Configuration Baseline. From within the Microsoft Entra admin centre, the team previously took a snapshot of the tenant in an approved, compliant state and creates a monitor based on this snapshot.
Step 2: Automatically Detect Configuration Drift. The monitor continually checks for drift and flags modifications to the Intune device compliance policy, confirming that the changes were made in error.
Step 3: Remediate with Confidence. With a clear record of the intended policy, the team can easily restore the Intune policy to its approved state, bringing the tenant back into compliance. Without drift monitoring, they’d face the tedious job of sifting through audit logs, guessing whether changes were intentional or accidental, and reconstructing the proper policy settings. Tenant Governance simplifies this process, providing transparent documentation of the baseline and automatically highlighting discrepancies.
As companies increasingly integrate AI agents into their operations, effective multi-tenant governance is essential for securing these systems. With Microsoft Entra Tenant Governance, multi-tenant agent management enhances how organisations manage risk across tenants. Once a governance link is established in the Entra admin centre, admins can review agent activities and pinpoint any risky agents, and choose to install or block them based on insights obtained through the Microsoft 365 admin centre. Licensing requirements include a Microsoft Entra Tenant Governance license in the governing tenant, as well as a Microsoft Agent 365 license for accessing agent activity and risk insights in the governed tenant.
The governance model also extends across Microsoft’s security offerings and the partner ecosystem. Administrators can utilise delegated access through the Defender multi-tenant management experience (currently in preview) to manage environments, security incidents, alerts, and configurations across governed tenants efficiently. This allows partners, such as MSPs and MSSPs, to securely manage customer tenants without needing full administrative access.
If you’re interested in getting started, check out the documentation to learn how to enable Microsoft Entra Tenant Governance in your production environment.
– Cindy Crane, Principal Product Manager
Additional Resources
Discover More About Microsoft Entra
Avoid identity attacks, ensure least privilege access, centralise access control, and improve user experiences with holistic identity and network access solutions across both on-premises and cloud environments.
Share this content:
Discover more from Qureshi
Subscribe to get the latest posts sent to your email.