Microsoft Entra ID Governance
Governance

Create a governed workforce tenant

In brief

The documentation now specifies paid-account, billing, tenant-creation permission, role, and default governance-policy requirements for creating governed workforce tenants. Free or trial tenants cannot create additional tenants, and EA or pay-as-you-go billing accounts are supported.

What Entra admins need to know

Administrators planning to create a governed workforce tenant should verify these billing, permission, role, and policy prerequisites before starting.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create a governed workforce tenant

This article is for IT administrators who need to create an add-on tenant that is governed from an existing Microsoft Entra tenant. Review the prerequisites before you use the secure add-on tenant creation flow.

When you create a tenant using the Governed Workforce option in the Microsoft Entra admin center, the secure add-on tenant creation flow automatically:

This article doesn't cover creating an external tenant configuration for consumer-facing apps. For customer identity and access management scenarios, see Microsoft Entra External ID for customers.

Prerequisites

Before you create a governed workforce tenant, confirm that you meet these requirements:

  • Your organization is a paid customer. Customers using a free tenant or trial subscription can't create additional tenants from the Microsoft Entra admin center. If you need a new tenant, sign up for a free Azure account.
  • Your selected Azure subscription is associated with an Enterprise Agreement (EA) or pay-as-you-go billing account. Legacy and modern billing experiences are supported. To identify your billing account type, see View your billing accounts in the Azure portal.
  • Your Microsoft Entra tenant allows member users to create add-on tenants. If Restrict non-admin users from creating tenants is set to Yes, your account needs the Tenant Creator role.
  • You must have at leastthe required permissions for the selected subscription through the Tenant Contributor permissions on at least one Microsoft Customer Agreement (MCA) subscription.
  • Enterprise Agreement (EA) subscriptions aren't supported.or Subscription Owner/Creator role.
  • The governing tenant has a configured default governance policy template must be configured in the governing tenant.. The tenant creation service uses only the default template (ID: default). If the default template isn't defined, the secure add-on tenant creation flow doesn't establish a governance relationship, even if other templates exist.

Create the tenant

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…