Microsoft Unified SecOps Platform
General

Create and manage tenant groups in Microsoft Defender multitenant management

In brief

The article now separates setup and tenant management links and simplifies guidance about tenant visibility, switching groups, and refreshing after changes.

What Defender admins need to know

Administrators have clearer references and instructions when creating, reviewing, or updating tenant groups.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create and manage tenant groups in Microsoft Defender multitenant management

Prerequisites

Before you create tenant groups, onboard your tenants to the Microsoft Defender multitenant portal. Only onboarded tenants appear when you create or edit a group.

For setup steps, see Set up Microsoft Defender multitenant management. To learn more,manage tenants, see Set up Microsoft Defender multitenant management and Manage tenants with Microsoft Defender multitenant management.

Required permissions

Product-specific RBAC (for example, Microsoft Defender for Endpoint or Microsoft Defender for Identity)

Unified role-based access control (URBAC)

To learn more about URBAC permissions, see Manage unified role-based access control (URBAC) for multitenant management.

Users only see tenants they canhave access to through B2B or granular delegated admin privileges (GDAP). A tenant group might containcan include tenants that a user can't access.see.

Access tenant groups

:::image type="content" source="media/mto-tenant-groups/multitenant-view-settings.png" alt-text="Screenshot of the Multi-tenant view settings page in the Microsoft Defender portal, with the Open multitenant management icon highlighted in the top-right corner." lightbox="media/mto-tenant-groups/multitenant-view-settings.png":::

After you switch groups, check the views in the multitenant portal. Confirm that the portal shows data comes only from tenants in the selectedthat group.

If someone adds or removes tenants from achanges the group while you have that viewit open, the portal shows a notification.notice. Refresh the view to load the updatednew data.

:::image type="content" source="media/mto-tenant-groups/group-changes-detected.png" alt-text="Screenshot of the Group changes detected dialog with Refresh and reload and Cancel buttons.":::