← Back to blog
Security

Entra Tenant Governance: track shadow tenants and monitor configuration drift — now generally available

By Zarioh Digital Solutions6 min read
Share
Entra Tenant Governance: track shadow tenants and monitor configuration drift — now generally available

How many Microsoft tenants exist within your organisation? More than you think. Entra Tenant Governance, now generally available, discovers unmanaged and shadow tenants via B2B, app and billing signals, and monitors configuration drift across more than 200 resource types in Entra, Intune, Exchange, Teams, Purview and Defender.

Every larger organisation has them: Microsoft 365 tenants created for a project, a subsidiary, a merger, or by an IT employee who quickly needed a test environment. Sometimes central IT does not even know they exist. Yet they contain identities, data and configurations that carry risks as soon as they fall outside any governance structure. Microsoft Entra Tenant Governance, which became generally available on 10 August 2026, gives IT teams a central place for the first time to discover, manage and check those tenants for configuration drift.

The product combines three things that until now existed separately: tenant discovery based on observable signals, cross-tenant delegated administration via GDAP technology, and automated configuration monitoring across six Microsoft services. This article explains how those three layers work together and what that means concretely for IT teams responsible for multiple tenants.

The shadow-tenant problem is larger than expected

A shadow tenant is any Microsoft Entra tenant that is connected to your organisation but not centrally managed. That can mean a subsidiary that set up its own Microsoft 365 environment, an acquisition from last year that has not yet been integrated, a dev tenant a developer created three years ago, or a test environment that grew into a production environment.

The risk is multifaceted. Users in an unmanaged tenant fall outside your Conditional Access policies, your MFA requirements and your DLP rules. Data that ends up in such a tenant is outside your compliance perimeter. And if the tenant is connected via B2B collaboration, its users can access resources in your main tenant without governance controls. The first step in any approach is knowing what exists.

Entra Tenant Governance does not discover related tenants by actively scanning — it reads existing signals within your own tenant. There are three types of signals.

The first signal is B2B collaboration. The system measures inbound and outbound B2B access, B2B registration and B2B administrative access between your tenant and other tenants. If users from tenant B regularly sign in to resources in your tenant A, tenant B becomes visible as a related tenant.

The second signal is multitenant applications. If an application is registered in multiple tenants or links tenants through app consent, the system marks the involved tenants as related.

The third signal is shared billing. If two tenants are linked to the same billing account, Tenant Governance recognises that relationship. Through this signal you can also send a governance request to the administrator of the other tenant.

The result is a map of your tenant landscape: which tenants exist, how strong the connection is, and whether they are already being managed or still fall outside the governance structure.

Monitoring configuration drift: 200+ resource types, every six hours

Discovery is step one. Step two is ensuring that managed tenants comply with the required configuration standard. This is where configuration monitoring comes in. You define a baseline in a JSON format that describes the desired state for settings in Entra, Intune, Exchange Online, Teams, Purview and Microsoft Defender. You then create a configuration monitor that compares the actual state with your baseline every six hours.

The system monitors more than 200 resource types. That means you can check not only whether MFA is enabled, but also whether Intune policies enforce the correct update settings, whether specific Exchange transport rules are in place, whether Defender recommendations have been followed up, and whether Teams meeting policies align with your governance frameworks. If drift occurs, you receive an alert.

This is similar to what infrastructure-as-code teams do with Terraform or Bicep for Azure resources, but then for the configuration layer of Microsoft 365. You capture desired state as code and the system automatically flags deviations.

Cross-tenant management with GDAP: no local accounts needed

Once a tenant is in scope, you also want to be able to manage it. Classically that meant creating a local administrator account in each tenant, or distributing B2B guest accounts. Both approaches carry their own risks. Entra Tenant Governance uses GDAP technology instead — Granular Delegated Admin Privileges — allowing administrators in the governing tenant to sign in to managed tenants with their own credentials, without needing a local account there.

Setting up such a governance relationship proceeds via a request-and-approval workflow. The administrator in the governing tenant sends a governance request; the administrator of the other tenant approves it. After approval, governance-relationship objects are created in both tenants and cross-tenant access settings are updated. You can assign roles via policy templates that you define centrally.

The result is a least-privilege administration model across tenant boundaries: you assign only the roles that are actually needed, manage them from one central location, and can revoke access without anyone needing to delete local accounts.

Licensing and availability

Entra Tenant Governance is available for organisations with more than one Microsoft Entra tenant. Basic capacity is included in Microsoft 365 E3 and provides monitoring for up to 800 monitored resources per day. For larger tenant landscapes, an additional Tenant Governance Premium licence is required.

For cross-tenant delegated administration, administrators in the governing tenant need a Microsoft Entra P1, P2 or Entra ID Governance licence. Managed tenants do not need an additional licence for the governance relationship itself.

The feature is available in the Microsoft Entra portal under Identity Governance > Tenant Governance. Organisations that used the preview have been automatically migrated to the GA version.

How do you get started?

Four concrete steps to get started with Entra Tenant Governance. First, open the Entra portal and navigate to Identity Governance > Tenant Governance > Tenant Discovery. Review the list of related tenants and the signals on which they were found. This immediately provides insight into your tenant landscape.

Second, identify which tenants fall outside management and what risk that entails. Use the governance request feature to contact tenants found via a shared billing account.

Third, define a configuration baseline for the tenants you already manage. Do not start with all 200+ resource types at once — choose a set of ten to fifteen critical settings: MFA policy, Conditional Access, Intune compliance policies, Defender recommendations. Create a monitor and observe the first results.

Fourth, set up governance relationships for tenants you want to manage centrally. Use policy templates to standardise role assignments and document which administrators have access to which tenants.

Entra Tenant Governance does not solve all multi-tenant questions at once, but for the first time gives IT teams the visibility needed to know what exists and whether it is compliant. Want support mapping your tenant landscape, setting up governance relationships, or building configuration baselines for your Microsoft 365 environment? Contact Zarioh.

Z

Zarioh Digital Solutions

IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Related articles

← Back to all articles
Share