Microsoft Entra ID Governance

Use cross-tenant delegated administration

In brief

Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials

Documentation change

Use cross-tenant delegated administration

Sign in to a governed tenant as a delegated administrator

After the governance relationship is active and GDAP role assignments are in place, members of the configured security group can sign in to the governed tenant.

After the governance relationship is active and GDAP role assignments are in place, members of the configured security group can sign in to the governed tenant. Confirm that your account is a member of a security group in the governing tenant that's assigned roles in the governance policy template.

  1. Confirm that your account is a member of a security group in the governing tenant that is assigned roles in the governance policy template.

You can sign in to a governed tenant in two ways:

  • From the Governed tenants page in the Microsoft Entra admin center.
  • By opening a supported admin portal URL directly.

Sign in from the Microsoft Entra admin center

Use the Governed tenants page to sign in to a governed tenant and choose which admin portal to open.

  1. In the governing tenant, go to the Governed tenants page in the Microsoft Entra admin center.

  2. Select the governed tenant that you want to sign in to.

  3. On the command bar, select Sign in to tenant. A side pane opens that shows:

    • Whether you can sign in to the governed tenant.
    • The roles that you'll have in the governed tenant.
  4. If your group membership is configured with Privileged Identity Management (PIM) and your membership is eligible, the side pane shows an Activate button. Select Activate to activate your eligible group membership before you sign in.

  5. In the side pane, select the admin portal that you want to open. A new tab opens and prompts you to authenticate.

  6. Sign in with your governing tenant credentials to access the governed tenant.

Sign in by using an admin portal URL

  1. Open a supported admin portal URL and append the domain or tenant ID of the governed tenant. For a list of supported portals and workloads, see GDAP supported workloads. For example:

https://entra.microsoft.com/{governed-tenant-domain-or-id}

`https://entra.microsoft.com/{governed-tenant-domain-or-id}`
  1. Sign in with your governing tenant credentials.

  2. After successful sign-in, perform administrative tasks in the governed tenant based on the roles assigned to your security group.

Update delegated administration roles