Entra ID

Entra TCM APIs GA for Tenant Configuration Management

3 min read

Summary

Microsoft has made the Tenant Configuration Management (TCM) APIs in Microsoft Graph generally available, giving organizations a scalable way to define, export, monitor, and manage tenant configurations. The release matters because it enables a configuration-as-code approach in Microsoft Entra, helping IT teams reduce drift, improve compliance, and automate governance across multi-tenant environments.

Need help with Entra ID?Talk to an Expert

Introduction

Microsoft has announced general availability of the Tenant Configuration Management (TCM) APIs for Microsoft Entra. For IT administrators managing complex or multi-tenant environments, this is an important step toward more consistent, automated, and auditable configuration management.

As tenant settings grow across identity, security, and productivity workloads, configuration drift becomes harder to control. The new GA APIs help organizations move from manual, reactive processes to a declarative and continuous management model.

What’s new

The TCM APIs are now generally available in Microsoft Graph and provide the underlying engine for Microsoft Entra Tenant Governance.

Key capabilities include:

  • Snapshots to capture the current state of tenant configurations
  • Baselines to define a desired or compliant configuration state
  • Monitors to continuously compare live settings against the baseline
  • Configuration drift detection to identify deviations from the expected state

This creates a repeatable workflow for configuration management:

  1. Capture the current state
  2. Define the desired state
  3. Continuously monitor for drift
  4. Take governance or remediation actions

Why this matters for administrators

For Entra and Microsoft 365 admins, the biggest benefit is the ability to treat tenant settings more like infrastructure-as-code. Instead of relying on portal checks and one-off reviews, teams can programmatically manage and validate configuration over time.

This is especially useful for organizations that:

  • Manage multiple tenants
  • Need stronger compliance and auditability
  • Want to integrate tenant configuration checks into automation workflows
  • Need better visibility into changes that introduce security risk

Because the APIs are exposed through Microsoft Graph, they can also be connected to existing operational, compliance, and security tooling.

How it fits with Entra Tenant Governance

Microsoft clarified that Entra Tenant Governance is the product experience, while the TCM APIs are the platform layer behind its configuration management features. Organizations can use Tenant Governance for a built-in administrative experience, while partners and advanced teams can use the APIs directly for custom integrations and managed services.

Microsoft also noted that Tenant Governance will continue evolving toward a single pane of glass for centrally managing multiple tenants.

Next steps

Admins and architects should consider these actions:

  • Review the Microsoft Graph TCM API documentation
  • Evaluate which tenant settings should become your initial baseline
  • Identify automation scenarios for drift monitoring and reporting
  • Assess whether Entra Tenant Governance or direct API integration better fits your operating model

For organizations focused on governance at scale, the GA of the TCM APIs provides a solid foundation for more proactive tenant configuration control.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft EntraMicrosoft Graphtenant governanceconfiguration managementmulti-tenant

Related Posts

Entra ID

Global Secure Access Operations Guide Now Available

Microsoft has published a new Microsoft Entra Global Secure Access operations guide on Microsoft Learn to help teams manage day 2 operations after deployment. The guide provides prescriptive monitoring, health checks, role assignments, templates, and automation guidance so IT teams can run Global Secure Access more consistently and proactively.

Entra ID

Microsoft Entra Agent ID GA Secures AI Agents

Microsoft Entra Agent ID is now generally available, giving organizations a dedicated identity and access foundation for AI agents in production. Combined with the Microsoft Agent 365 CLI and SDK, it helps IT and security teams onboard, govern, audit, and secure agent instances across Microsoft and non-Microsoft frameworks.

Entra ID

Microsoft Entra June 2026: Passkeys, Linux MFA, B2C

Microsoft Entra’s June 2026 updates bring major identity improvements across passkeys, phishing-resistant MFA for Linux desktops, and Azure AD B2C migration to External ID. The release also adds cross-tenant group sync, app deactivation, redesigned My Account pages, and new governance features that help IT teams strengthen security and simplify administration.

Entra ID

Microsoft Entra Tenant Governance Finds Shadow Tenants

Microsoft Entra Tenant Governance now helps organizations discover shadow tenants connected through B2B collaboration, multitenant apps, and shared billing signals. The new related tenants capability gives IT teams continuous visibility into hidden tenant sprawl so they can assess risk, quarantine unsanctioned tenants, and tighten identity governance.

Entra ID

macOS Platform SSO in ADE Now Generally Available

Microsoft has made Platform SSO during Automated Device Enrollment generally available for macOS. The update lets organizations register devices and enable Platform SSO automatically during setup, reducing user prompts and helping IT teams deliver a more secure, consistent onboarding experience from day one.

Entra ID

Microsoft Identity Manager 2016 SP3 Now Available

Microsoft Identity Manager 2016 SP3 is now generally available, bringing improved stability, broader platform compatibility, and a new Azure SQL Database deployment option for the Synchronization Service. The update matters for organizations running hybrid identity environments because it reduces operational risk, supports newer infrastructure components, and gives customers a supported path forward while planning longer-term moves to Microsoft Entra.