Microsoft Entra ID Governance

Create a governed workforce tenant

In brief

Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.

Documentation change

Create a governed workforce tenant

This article is for IT administrators who need to create an add-on tenant that is governed from an existing Microsoft Entra tenant. Review the prerequisites before you use the secure add-on tenant creation flow.

When you create a tenant using the Governed Workforce option in the Microsoft Entra admin center, the secure add-on tenant creation flow automatically:

This article doesn't cover creating an external tenant configuration for consumer-facing apps. For customer identity and access management scenarios, see Microsoft Entra External ID for customers.

Prerequisites

  • You must have at least Tenant Contributor permissions on at least one Microsoft Customer Agreement (MCA) subscription.
  • Enterprise Agreement (EA) subscriptions aren't supported.
  • The default governance policy template must be configured in the governing tenant. The tenant creation service uses only the default template (ID: default). If the default template isn't defined, the secure add-on tenant creation flow doesn't establish a governance relationship, even if other templates exist.

Before you create a governed workforce tenant, confirm that you meet these requirements:

Create the tenant