Deployment Guide
In brief
The secure tenant creation prerequisites were updated to clarify the required Azure Resource Manager permissions.
What Entra admins need to know
Administrators should verify these permissions when preparing secure tenant creation.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- A Microsoft Entra tenant with the appropriate license for Tenant Governance. For details, see Microsoft Entra licensing.
- An account with the Tenant Governance Administrator or Global Administrator role.
- For configuration management: an account with the Global Administrator or Privileged Role Administrator role.
- For secure tenant creation: a paid Azure subscription associated with an Enterprise Agreement (EA) or pay-as-you-go billing account. Legacy and modern billing experiences are supported. You also need the required Azure Resource Manager (ARM) permissions for the selected subscription through the Tenant Contributor or Subscription Owner/Creator role. To identify your billing account type, see View your billing accounts in the Azure portal.
Phase 1: Enable related tenant discovery
@@ -21,7 +21,7 @@ Before you begin, confirm that your environment meets these requirements: - A Microsoft Entra tenant with the appropriate license for Tenant Governance. For details, see [Microsoft Entra licensing](~/fundamentals/licensing.md#microsoft-entra-tenant-governance). - An account with the Tenant Governance Administrator or Global Administrator role. - For configuration management: an account with the Global Administrator or Privileged Role Administrator role.-- For secure tenant creation: a paid Azure subscription associated with an [Enterprise Agreement (EA)](/azure/cost-management-billing/manage/understand-ea-roles) or [pay-as-you-go](https://azure.microsoft.com/pricing/offers/ms-azr-0003p?cid=msft_learn) billing account. Legacy and modern billing experiences are supported. You also need the required permissions for the selected subscription through the Tenant Contributor or Subscription Owner/Creator role. To identify your billing account type, see [View your billing accounts in the Azure portal](/azure/cost-management-billing/manage/view-all-accounts).+- For secure tenant creation: a paid Azure subscription associated with an [Enterprise Agreement (EA)](/azure/cost-management-billing/manage/understand-ea-roles) or [pay-as-you-go](https://azure.microsoft.com/pricing/offers/ms-azr-0003p?cid=msft_learn) billing account. Legacy and modern billing experiences are supported. You also need the required Azure Resource Manager (ARM) permissions for the selected subscription through the Tenant Contributor or Subscription Owner/Creator role. To identify your billing account type, see [View your billing accounts in the Azure portal](/azure/cost-management-billing/manage/view-all-accounts). ## Phase 1: Enable related tenant discovery 