Microsoft Unified SecOps Platform
General

Configure delegated access with governance relationships for multitenant organizations

In brief

The article now clarifies tenant relationships, governing-tenant accounts and group representation, the disabled-by-default Enable invitations setting, and that Sentinel Azure RBAC grants management-plane—not data-plane—access.

What Defender admins need to know

Enable invitations in the governed tenant before configuring delegated access. Assign separate data-plane roles when access to Storage blobs or Key Vault secrets is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure delegated access with governance relationships for multitenant organizations (preview)

Overview

Governance relationships enableA governance relationship is a directional connection between two Microsoft Entra tenants that enables a governing tenantstenant (the home tenantstenant that managemanages access) to manage security operations across multiple customer tenants (the tenants that grant delegated access) with fine-grained role assignments. This capability supports multitenant organizations (MTOs) and managed security service providers (MSSPs) that need to provide security services across multiple Microsoft Entra tenants.

Governance relationships for Microsoft Defender use the same model as Microsoft Entra ID for delegating administrative access, but extended to support Microsoft Defender XDRMicrosoft Defender XDR (cross-domain threat detection and response) workloads. By configuring governance relationships for Microsoft Defender, you can assign specific security roles to groups in the governing tenant, allowing them to manage security incidents, alerts, and configurations in the governed tenant without granting full administrative access.

Administrators continue to use their accounts in the governing tenant. Tenant Governance doesn't create local administrator accounts or Microsoft Entra B2B guest accounts in the governed tenant. Instead, security groups selected in the governance policy template are represented in the governed tenant as remote tenant groups. You can automate governance relationships and templates by using the Tenant Governance APIs in Microsoft Graph.

Key concepts

The following terms are used throughout this article:

  • Governing tenant: The home tenant that manages access to other tenants (also called home tenant or managing tenant)
  • Governed tenant: The customer tenant that grants access to the governing tenant (also called target tenant or managed tenant)
  • Governance relationship: directional connection between two Microsoft Entra tenants. One tenant acts as the governing tenant, and the other acts as the governed tenant.

Enable tenant governance settings

Before you can configure delegated access, you must enable the governed tenant to receive governance invitations. ThisThe Enable invitations setting is disabled by default.

In the governed tenant in the Microsoft Defender portal, go to System > Permissions > Delegated Access, and turn on the Enable invitations toggle.

Step 2: Create and send access request from governing tenant

After itthe governing tenant receives the invitation, the governing tenantit creates a relationship template that defines delegated access permissions.

  1. In the governing tenant, sign in to the Microsoft Defender MTO portal.

Security groups used in the relationship template are synchronized to the governed tenant as "remote tenant groups." You can assign these groups to Microsoft Sentinel roles in the governed tenant to enable multitenant management capabilities. You can assign these groups to Azure Resource Manager (ARM) resources to enable Microsoft Sentinel management capabilities.

The Microsoft Sentinel Azure RBAC assignments described in this section grant management-plane access to the selected resources. They don't automatically grant data-plane access, such as permission to read Azure Storage blob data or Azure Key Vault secrets. Assign any required data-plane roles separately and follow least-privilege principles.

Assigning Microsoft Sentinel roles enables multitenant management features including:

  • Alert and incident management