Entra ID

Microsoft Entra Tenant Governance Finds Shadow Tenants

3 min read

Summary

Microsoft Entra Tenant Governance now helps organizations discover shadow tenants connected through B2B collaboration, multitenant apps, and shared billing signals. The new related tenants capability gives IT teams continuous visibility into hidden tenant sprawl so they can assess risk, quarantine unsanctioned tenants, and tighten identity governance.

Need help with Entra ID?Talk to an Expert

Microsoft Entra Tenant Governance helps uncover shadow tenants

Introduction

As organizations expand through acquisitions, development projects, and partner collaboration, Microsoft tenant sprawl can quickly become a security blind spot. Microsoft Entra Tenant Governance aims to address that problem with a new related tenants discovery capability that helps admins find shadow tenants before they become an incident response issue.

This matters because tenants outside central IT oversight can still have trusted connections, app permissions, or shared billing ties to your environment. That creates risk even if those tenants were forgotten years ago.

What’s new

Microsoft highlighted the Related Tenants pillar in Entra Tenant Governance, now available in public preview. After enabling discovery in the Microsoft Entra admin center, organizations can identify connected tenants using signals such as:

  • B2B collaboration relationships
  • Multitenant application registrations
  • Shared billing accounts

The process is designed to be simple:

  1. Go to Tenant governance > Related tenants in the Entra admin center
  2. Turn on discovery with a single click
  3. Review surfaced tenants and the signals behind each relationship
  4. Investigate unknown or unsanctioned tenants and take action

Microsoft says the inventory is continuously updated, so this is not just a one-time scan. New tenant relationships can surface automatically as your environment changes.

Why it matters for IT admins

For identity and security teams, the biggest benefit is visibility. Hidden tenants from acquisitions, proof-of-concept work, legacy testing, or partner activity may still expose your organization through user sign-ins, app consent, or cross-tenant access.

Microsoft recommends several response options for suspicious tenants:

  • Confirm exposure by reviewing app permissions, admin consent, and affected users or workloads
  • Block inbound and outbound sign-ins using cross-tenant access settings
  • Contain app-based access by revoking permissions or removing service principals
  • Apply tenant restrictions v2 through Global Secure Access and universal tenant restrictions
  • Validate impact through sign-in and audit logs before deciding whether to onboard or isolate the tenant

Organizations can also expand discovery with additional telemetry, including Azure subscription billing data, Entra sign-in logs, Microsoft 365 activity, and audit logs.

Action items and next steps

Admins should consider the following next steps:

  • Enable related tenants discovery in the Entra admin center or via the tenant governance API
  • Review newly discovered tenants and classify them as trusted, unknown, or unsanctioned
  • Use tenant quarantine workflows for risky tenants pending review
  • Update tenant creation practices, since the legacy workforce tenant creation flow retires on August 15, 2026

For organizations focused on reducing identity attack surface, this preview gives a practical way to find hidden tenant relationships and bring them under governance before attackers do.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft EntraEntra IDtenant governanceshadow tenantsidentity security

Related Posts

Entra ID

macOS Platform SSO in ADE Now Generally Available

Microsoft has made Platform SSO during Automated Device Enrollment generally available for macOS. The update lets organizations register devices and enable Platform SSO automatically during setup, reducing user prompts and helping IT teams deliver a more secure, consistent onboarding experience from day one.

Entra ID

Microsoft Identity Manager 2016 SP3 Now Available

Microsoft Identity Manager 2016 SP3 is now generally available, bringing improved stability, broader platform compatibility, and a new Azure SQL Database deployment option for the Synchronization Service. The update matters for organizations running hybrid identity environments because it reduces operational risk, supports newer infrastructure components, and gives customers a supported path forward while planning longer-term moves to Microsoft Entra.

Entra ID

Microsoft Entra Face Check Secures High-Risk Identity Flows

Microsoft is expanding Face Check in Microsoft Entra Verified ID to strengthen identity verification during remote onboarding, access requests, and account recovery. The update removes per-user Face Check limits in Microsoft Entra Suite and highlights general availability for verified account recovery, helping organizations reduce impersonation risk and help desk dependency.

Entra ID

Microsoft Entra May 2026: Global Secure Access GA

Microsoft Entra’s May 2026 updates focus heavily on Global Secure Access, certificate-based authentication, and stronger privileged access controls. The new capabilities help IT teams extend Zero Trust protections to branch offices, mobile devices, external users, and AI workloads while improving usability and policy enforcement.

Entra ID

Microsoft Entra ID Passkeys: Fixing Recovery Gaps

Microsoft is expanding its passkey-first strategy in Entra ID by addressing the security gaps that remain after passkey deployment, including fallback credentials and weak account recovery. New capabilities such as Windows passkeys, passkey-preferred authentication, and generally available Entra ID account recovery help organizations reduce phishing and social engineering risk while improving user experience.

Entra ID

Microsoft Entra Webinar Series Strengthens Identity Security

Microsoft has launched a five-part Secure identity foundation with Microsoft Entra webinar series focused on passwordless authentication, Conditional Access, ID Protection, Tenant Governance, and Backup and Recovery. The series gives IT and security teams practical deployment guidance to strengthen access management, improve tenant visibility, and build more resilient identity protections across cloud and hybrid environments.