Microsoft made Entra Tenant Governance generally available on August 10, 2026. It discovers tenants related to yours, lets you administer them without creating accounts in them, and monitors their configuration drift. What it actually does, what it requires, and the contractual prerequisite that blocks a lot of organizations.
The tenant nobody meant to create
An organization that believes it has a single Microsoft tenant often has three or four. An Azure trial a developer opened to test a service, a sandbox tenant that was never closed, an acquired subsidiary that kept its own, a regional team that went its own way. None of them shows up in the main portal, all of them carry the organization's name, and several hold real data and real users.
Until now, finding them was manual detective work. Microsoft made Entra Tenant Governance generally available on August 10, 2026, after a preview that opened in late March. It is the first native Microsoft 365 multi-tenant governance tool: it discovers tenants related to yours, lets you administer them without creating accounts in them, and monitors their configuration.
Multi-tenant governance: discover first, classify second
Discovery relies on signals already present in your tenant: B2B collaboration, multitenant applications, a shared billing account. You turn it on in the Entra admin center, under Tenant governance then Related tenants, and you need to let a few days of signal aggregation pass before the list is usable.
One detail to know before you click: enabling it is irreversible. Microsoft documents this plainly, discovery cannot be turned back off.
Microsoft then offers three classifications. Known and acceptable, for a partner or vendor whose relationship is documented. Requires governance, for an internal tenant with no clear owner. Potentially risky, for an unknown tenant you may want to quarantine. It is the second pile that holds the surprises, because it is almost always bigger than expected.
Administering without creating accounts
The second building block is called a governance relationship. Once it is established, an administrator in the governing tenant signs in directly to the governed tenant, at entra.microsoft.com followed by the tenant identifier, with the roles defined in a policy template. No local account, no shared password, no service account left lying around. The mechanism runs on GDAP and also covers Intune, Exchange, SharePoint, Teams and the Microsoft 365 admin centers.
Connecting the two tenants is a formal exchange, not a button. Two steps if both tenants already share a billing account, three otherwise. Governance requests expire after 14 days, invitations after 30. Another trap: editing a template does not update existing relationships, you have to resend the request.
Monitoring configuration drift
The third piece continuously compares a tenant against a configuration baseline written in JSON. You generate a snapshot of the current state through an API, edit it to describe the desired state, then a monitor runs the comparison every six hours and flags the gaps.
Two limits frame the exercise: 200 resource instances per baseline, and 800 instances per day across all monitors. So this is not a tool for monitoring everything. It is a tool for locking down the small number of settings that must stay identical everywhere: conditional access, external sharing settings, privileged role assignments. And it flags drift without correcting it, remediation stays manual.
What it takes in licences, and what blocks it
Configuration monitoring and governance relationships with delegated administration work with Entra ID P1, which is included in Microsoft 365 E3 and Business Premium. Discovering related tenants, however, requires Entra ID Governance, included in the Entra Suite and in Microsoft 365 E7. Creating an already-governed tenant is available to any paying customer.
The counting is more reasonable than you might fear: one licence per administrator who configures, not one per governed tenant. A team overseeing five tenants does not need five licences.
The real obstacle is elsewhere. Enterprise Agreement subscriptions are not supported, only Microsoft Customer Agreement contracts are. Many organizations will hit that wall before they even take the first step.
Where to start
A tenant nobody watches produces neither usable logs nor alerts. In front of a cyber insurer, a prime contractor or a privacy regulator, that is a blind spot that is hard to explain. Discovery has just become the easy part, which shifts the real question: who, in your organization, owns those tenants?
- Inventory before you enable: list the known tenants, their owner and their stated purpose. Discovery reads much better when you know what you expect to find in it.
- Check the contract type, MCA or EA, before planning anything else.
- Assign someone the Tenant Governance Administrator role rather than doing everything as Global Administrator.
- Start monitoring with a short, defensible baseline and widen it later. The 200-resource limit forces you to prioritize anyway.
Want to talk it through?
Let's spend 30 minutes on your situation.
A free assessment with an io4 architect. No commitment, no pressure.
Book my assessment
