Bilješka
Pristup ovoj stranici zahtijeva provjeru vjerodostojnosti. Možete pokušati da se prijavite ili promijenite direktorije.
Pristup ovoj stranici zahtijeva provjeru vjerodostojnosti. Možete pokušati promijeniti direktorije.
This article is for IT administrators who need to create an add-on tenant that is governed from an existing Microsoft Entra tenant. Review the prerequisites before you use the secure add-on tenant creation flow.
When you create a tenant using the Governed Workforce option in the Microsoft Entra admin center, the secure add-on tenant creation flow automatically:
- Creates the new workforce tenant
- Establishes a governance relationship between your home tenant and the new tenant if your home tenant has a default governance policy template
- Provisions a Microsoft Entra ID Free billing asset under your selected Azure subscription and resource group
This article doesn't cover creating an external tenant configuration for consumer-facing apps. For customer identity and access management scenarios, see Microsoft Entra External ID for customers.
Prerequisites
Before you create a governed workforce tenant, review the following requirements:
- Your home tenant has at least one paid, license-based Microsoft product (for example, Microsoft Entra ID P1 or P2, Microsoft 365, or Windows Enterprise E3). Free and trial licenses don't qualify.
- You have either a paid Enterprise Agreement (EA) or Pay-As-You-Go subscription. Both Microsoft Online Subscription Agreement (MOSA) and Microsoft Customer Agreement (MCA) billing accounts are supported. To identify your billing account type, see View your billing accounts in the Azure portal.
- Your account has the Tenant Creator role. This role is required regardless of the Restrict non-admin users from creating tenants setting.
- You have the required Azure Resource Manager (ARM) permissions for the selected subscription through the Tenant Contributor or Subscription Owner/Creator role.
- (Optional) Your home tenant has a configured default governance policy template. The tenant creation service uses only the default template (ID:
default). If the default template isn't defined, the secure add-on tenant creation flow doesn't establish a governance relationship, even if other templates exist.
Create the tenant
For step-by-step instructions on creating a governed workforce tenant, see the Governed Workforce tab in Quickstart: Create a new tenant in Microsoft Entra ID.
What happens after tenant creation
After the system creates the tenant:
- If your home tenant has a default governance policy template, a governance relationship forms between your home tenant and the new tenant. The template provisions resources, including cross-tenant access settings, granular delegated admin privileges (GDAP) assignments, and service principals.
- A Microsoft Entra ID Free billing asset appears in your Azure subscription under the resource group you selected.
- The new tenant appears in your related tenants inventory.
To learn more about governance relationships and policy templates, see Governance relationships and Governance policy templates.