Instance of the Entra ID directory dedicated to an organisation, with an initial .onmicrosoft.com domain picked when it is created. Every Azure subscription trusts one tenant only.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-700SC-500AZ-900AB-900SC-300ALZ
Each book explains Microsoft Entra tenant in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Dedicated
Running Azure Functions on an App Service plan, which removes the execution time limit and offers VNet integration on Basic and higher tiers.
- Initial domain
The domain in the form <name>.onmicrosoft.com that each Entra tenant receives at creation; it cannot be deleted or altered.
- Azure subscription
Container for Azure resources that also marks the edge of their billing, quotas and scale limits, governance, security and identity. Each one trusts a single Microsoft Entra tenant, and it isn't bound to any region.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
Related terms
- Custom domain name
A DNS domain you own, contoso.com for example, added to a Microsoft Entra tenant next to the permanent onmicrosoft.com initial domain. Users can sign in with it once you have proved ownership through a TXT or MX record.
- External tenant
For consumer and business-customer applications, External ID uses a separate Microsoft Entra tenant set up in its external configuration, distinct from the workforce tenant where staff accounts live.
- Microsoft 365
Formerly Office 365, Microsoft's software-as-a-service productivity suite. A Microsoft Entra tenant provides its identity, and its data is not governed by Azure RBAC.
- Platform landing zone
Typically one per Microsoft Entra tenant, this is the shared core that everything else rests on. It comprises the management group structure, common services for networking, identity, management and security, and the route by which teams receive their own landing zones.