Uredi

Create a governed workforce tenant

This article is for IT administrators who need to create an add-on tenant that is governed from an existing Microsoft Entra tenant. Review the prerequisites before you use the secure add-on tenant creation flow.

When you create a tenant using the Governed Workforce option in the Microsoft Entra admin center, the secure add-on tenant creation flow automatically:

This article doesn't cover creating an external tenant configuration for consumer-facing apps. For customer identity and access management scenarios, see Microsoft Entra External ID for customers.

Prerequisites

Before you create a governed workforce tenant, review the following requirements:

Create the tenant

For step-by-step instructions on creating a governed workforce tenant, see the Governed Workforce tab in Quickstart: Create a new tenant in Microsoft Entra ID.

What happens after tenant creation

After the system creates the tenant:

  1. If your home tenant has a default governance policy template, a governance relationship forms between your home tenant and the new tenant. The template provisions resources, including cross-tenant access settings, granular delegated admin privileges (GDAP) assignments, and service principals.
  2. A Microsoft Entra ID Free billing asset appears in your Azure subscription under the resource group you selected.
  3. The new tenant appears in your related tenants inventory.

To learn more about governance relationships and policy templates, see Governance relationships and Governance policy templates.