Microsoft Entra ID Governance

Deploy Microsoft Entra Tenant Governance end to end

In brief

Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring

Documentation change

Deploy Microsoft Entra Tenant Governance end to end

  • A Microsoft Entra tenant with the appropriate license for Tenant Governance. For details, see Microsoft Entra licensing.
  • An account with the Tenant Governance Administrator or Global Administrator role.
  • For configuration management: an account with the Global Administrator or Privileged Role Administrator role.
  • For secure tenant creation: at least Tenant Contributor permissions on a Microsoft Customer Agreement (MCA) subscription. Enterprise Agreement (EA) subscriptions aren't supported.

Phase 1: Enable related tenant discovery

Use the secure add-on tenant creation feature to create new tenants that are immediately governed.

  1. Sign in to the Microsoft Entra admin center with at least Tenant Contributor permissions on a Microsoft Customer Agreement subscription.
  1. Sign in to the Microsoft Entra admin center with the Tenant Contributor or Subscription Owner/Creator role for the selected subscription.
  1. Create a new tenant using the Governed Workforce option.
  2. Select the Azure subscription and resource group for the Microsoft Entra ID Free billing asset.