Microsoft Defender for Cloud
Cloud and workloads

Cross-tenant management

In brief

The documentation now explains that Azure Lighthouse grants managing-tenant identities access to delegated resources without creating local users or role assignments in the managed tenant. It also states that the managed tenant’s Azure Activity Log records these actions and identifies the acting user.

What Defender admins need to know

Administrators should use the Activity Log to monitor delegated access and understand why these users and assignments do not appear on the managed subscription’s Access control (IAM) page.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Cross-tenant management in Defender for Cloud

Azure delegated resource management is one of the key components of Azure Lighthouse. Set up cross-tenant management by delegating access to resources of managed tenants to your own tenant using these instructions from Azure Lighthouse's documentation: Onboard a customer to Azure Lighthouse.

Security and access considerations

Azure Lighthouse grants identities in the managing tenant access to delegated Azure resources. The users and their Azure role assignments aren't created as local objects in the managed tenant. As a result, the users and assignments don't appear on the subscription's Access control (IAM) page. To review or remove delegations, use the Service providers page.

The managed tenant's Azure Activity Log records actions performed through Azure Lighthouse. The Event initiated by field identifies the acting user, whether the user is from the managing tenant or the managed tenant. For more information, see Monitor service provider activity.

How cross-tenant management works in Defender for Cloud

You're able to review and manage subscriptions across multiple tenants in the same way that you manage multiple subscriptions in a single tenant.