Braintree Insights | 28 August 2026
The tenants your IT team does not know about
Microsoft Entra Tenant Governance brings multiple Microsoft tenants into a single view, monitors their configuration for drift and helps establish cross-tenant administrative access. The licensing table draws a line worth reading before budgeting: configuration drift monitoring is available with Entra P1, and therefore inside Microsoft 365 E3 and Business Premium, while the capability that discovers tenants you do not already know about requires Microsoft Entra ID Governance.
What changed
Microsoft’s What’s new in Microsoft Security post of 27 August 2026 describes Tenant Governance as bringing an organisation’s tenants into a single view to address security gaps and blind spots, and names a configuration drifts report showing drift details including types, properties and timestamps. The overview documentation sets out four capability areas. Configuration management covers over 200 types of resources across six Microsoft services, being Entra, Intune, Exchange Online, Teams, Purview and Defender, with monitors that currently run at six-hour intervals and report each property whose value differs from a declared baseline. Related tenants discovery detects tenants related to yours through three signals: business-to-business collaboration, registered multitenant applications with permissions in your tenant, and shared billing accounts.
The risk is structural rather than incidental. An unknown tenant is not a misconfigured tenant that a monitoring tool will flag; it is a tenant outside the scope of every tool that was bought to do the flagging. It holds identities that no joiner-mover-leaver process touches, data that no retention policy covers, and an administrative account whose owner may already have left. It becomes visible at the moment somebody needs it to be, which is usually during an incident or a due diligence exercise.
What the term means in plain language
A Microsoft Entra tenant is a distinct instance of an organisation’s Microsoft identity directory. Most organisations of any size operate more than one, and Microsoft’s own documentation gives the reasons: mergers and acquisitions, requirements for partitioning security or privacy-sensitive workloads, and test environments. It adds a fourth that is harder to plan for, stating that most organisations also have user-created shadow IT tenants that central IT does not administer and often does not know about. Microsoft Entra Tenant Governance is the capability set that addresses this estate, covering the discovery of related tenants, the establishment of governance relationships for cross-tenant administration, configuration monitoring across tenants, and controls on how new tenants are created.
This distinction matters because product status is not the same as business readiness. Availability, support and compatibility are separate questions. A service can be available but unsupported, supported but capacity-constrained, or technically updated while a customer-specific process has stopped working.
Why this matters to a South African organisation
South African teams often operate with tight specialist capacity, rand-sensitive budgets and business processes that cannot be paused while a replacement is sourced. Localisation, regional cloud capacity and long procurement lead times can narrow the recovery options. The practical response is to use the available test window before it becomes an emergency window.
The consequence belongs to the business process, not only the technology team. Finance month-end, customer transactions, data pipelines and ERP extensions all cross technical and operational ownership. A change should therefore be accepted only when the service owner and the business owner can see the same evidence.
The hidden exposure
Microsoft Entra Tenant Governance brings multiple Microsoft tenants into a single view, monitors their configuration for drift and helps establish cross-tenant administrative access. The licensing table draws a line worth reading before budgeting: configuration drift monitoring is available with Entra P1, and therefore inside Microsoft 365 E3 and Business Premium, while the capability that discovers tenants you do not already know about requires Microsoft Entra ID Governance.
Normal operation is weak evidence. It proves only that yesterday’s combination of platform, configuration and workload completed. It does not prove that the next capacity allocation, lifecycle enforcement or major release will preserve the same result. An owner needs an inventory, a representative test and a dated decision.
Decision path
The capability divides cleanly in two, and the licensing table divides it along the same line, which is the fact worth carrying into a budget conversation. The half that monitors configuration drift is available with Microsoft Entra P1 and P2, at up to 30 monitors and 800 configuration resources per tenant per day, and Microsoft notes that P1 is included in Microsoft 365 E3 and Business Premium while P2 is included in E5. For most organisations that means the drift monitoring is already paid for. The half that discovers related tenants through business-to-business collaboration, multitenant applications and shared billing accounts is ticked only in the Microsoft Entra ID Governance column, which is not P1 and not P2, and therefore not E3 and not E5. Braintree’s reading rather than Microsoft’s wording: the included half watches the tenants you already administer, which is precisely not the shadow-tenant problem, and the half that addresses the problem described in the opening paragraph of Microsoft’s own overview is the half that has to be bought. One further line belongs in the same conversation before anyone sizes a purchase. Microsoft states that after discovery is enabled, every administrator who uses Related tenants needs a licence, whether they view results, trigger a refresh or act on signals, and that the administrator who enables discovery also needs one. The licence count is therefore the number of people who will look, not one.
Record the alternatives that were rejected and why. That prevents the next reviewer from reopening the entire question without context. Where the preferred path cannot be completed inside seven days, approve a time-bound exception with a responsible owner, expiry date and compensating control.
Technical test plan
Begin with the free exercise, because it is the input to every subsequent decision and it needs no capability at all. Enumerate the tenants the organisation knows about and name an accountable administrator for each. Then approach it from the direction IT cannot see: ask finance which Microsoft billing accounts appear on the ledger, since a tenant that nobody in IT administers still tends to be paid for by somebody. Microsoft’s own billing discovery signal works on exactly this principle, identifying tenants that share billing accounts where either your tenant or the related tenant is an associated billing tenant, which is a useful indication that the finance route is a reasonable manual proxy. Where configuration monitoring is in scope, the model is baseline and compare. A configuration baseline expresses the desired state of tenant resources in a standard JSON format, and a configuration snapshot documents the current state; Microsoft suggests taking a snapshot from a known-good tenant to start the authoring of a baseline, and notes that snapshots can also help satisfy certain audit requirements. A monitor then compares actual state to the baseline and reports drifts, each identifying the affected resource and listing each property whose current value differs. Monitors currently run at six-hour intervals, and after a drift is remediated the next execution automatically marks it as fixed. Size the scope against the capacity figures rather than against ambition: the Basic capacity included with P1 or P2 covers up to 30 monitors and 800 configuration resources per tenant per day and up to 20,000 resources per tenant per month for snapshots, and Microsoft’s worked example shows each Premium licence adding capacity for 10 resources per day, so an estate needing 1,000 daily resources against an 800 limit requires 20 Premium licences for the shortfall. Prioritising accordingly is the practical move: authentication methods, Conditional Access policies and role settings before the long tail.
Use production-representative conditions without exposing production data unnecessarily. Capture the starting configuration, exact version, time of test and expected result. A pass requires evidence from the real workflow, not only a successful login or an unchanged dashboard.
Primary owner
Primary owner: Whoever owns Microsoft Entra and the identity estate, with the finance contact who can see which Microsoft billing accounts exist and the group or divisional IT lead in an organisation formed by acquisition.
The named owner coordinates platform, application, commercial and business-process decisions. Contributors may perform the work, but accountability cannot be distributed across a meeting invite. The owner closes the test, exception and evidence record.
Action within seven days
Action within seven days: Write the list of Microsoft tenants the organisation knows it has, naming an accountable administrator for each one, and ask finance which Microsoft billing accounts appear on the ledger. That exercise costs nothing and requires no licence. Compare the two lists: tenants on the billing list that are not on the IT list are the finding. Only once the known list exists is it possible to judge whether the discovery capability, and the licence it requires, is worth buying.
Start with the highest-consequence workload. Assign the people, date and pass criteria before the test begins. If the first test fails, record the failure as evidence and open remediation with a deadline rather than hiding it behind a general project status.
Evidence to retain
Evidence to retain: The dated tenant register listing each known Microsoft tenant, its purpose, its accountable administrator and the business unit it serves, alongside the list of Microsoft billing accounts obtained from finance. Where the two lists disagree, retain the reconciliation. Where configuration monitoring is later enabled, retain the configuration baseline and the first drift report as the starting position.
Store the evidence with the platform or change record. Include source exports and machine-readable results where possible. The next reviewer should be able to reproduce the conclusion without rebuilding it from email, chat or memory.
Frequently asked questions
Is this capability generally available?
This article does not state a general availability date. A Microsoft Community Hub post announcing general availability exists, but that site returns title-only content to automated retrieval, so no publication date could be confirmed from a primary source. The capability descriptions and the licensing entitlements quoted here are taken from live Microsoft Learn documentation.
What is included with our existing Microsoft 365 licences?
Microsoft’s licensing table shows single-tenant configuration monitoring and drift reporting, and single-tenant configuration snapshots, against Entra P1 and P2. Microsoft notes that P1 is included in Microsoft 365 E3 and Business Premium and that P2 is included in E5.
What requires Microsoft Entra ID Governance?
Discovering related tenants through business-to-business collaboration, multitenant apps and shared billing accounts is ticked only under Microsoft Entra ID Governance. Governance relationships using custom multitenant app injection also require it. Cross-tenant delegated administration is available with P1, P2 or ID Governance.
How many licences would we actually need?
For Related tenants, Microsoft states that every administrator who uses the feature needs a licence, whether they view results, trigger a refresh or act on signals, including the administrator who enables discovery. For governance relationships, one licence is required for each administrator who configures relationships, and the number of relationships does not change the count.
What can we do this week without buying anything?
Write the list of tenants you know you have with a named administrator for each, and ask finance which Microsoft billing accounts exist. The gap between those two lists is the finding, and it is the only honest input to a decision about whether the discovery capability is worth its licence.
Why does this matter particularly in South Africa?
The pattern Microsoft describes, of tenants arriving through mergers and acquisitions, maps closely onto how many South African groups are structured. Acquiring a company frequently means inheriting its Microsoft tenant, and the inheritance is often recorded in the transaction documents rather than in the identity estate.
The Braintree view
Microsoft’s announcement supplies the platform fact. The customer control begins after that fact: identify the exposed process, name the owner, test the real dependency and retain a decision that can survive audit or staff turnover. Braintree can help structure the inventory, build the representative test and translate the result into a controlled implementation plan.
Use the seven-day action as the entry point. Do not wait for a renewal, support refusal or enforced update to reveal work that can be measured now.