A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
Also called Microsoft Entra tenant.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Tenant in context, with comparison tables and the common traps.
Terms in this definition
- Dedicated
Running Azure Functions on an App Service plan, which removes the execution time limit and offers VNet integration on Basic and higher tiers.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
Related terms
- Admin consent
Approval of an app's permissions for the whole tenant, given by an administrator with the right authority. Application permissions always need it, and owning the app does not grant it.
- Agent Dashboard
Gives leaders and analysts a picture of agent uptake and the credits those agents burn through, inside Viva Insights. It won't show data until a tenant has 50 or more Microsoft Copilot licences plus some agent usage.
- AI Administrator
Microsoft Entra role for managing Microsoft 365 Copilot and other AI settings; holders may also consent on behalf of the whole tenant, Microsoft Graph application permissions excepted.
- ANC
Tells Windows 365 which Azure subscription, virtual network and subnet to place Cloud PCs in (plus, where they're hybrid joined, which AD OU and domain). Provisioning policies use it, Intune checks its health at intervals of one to six hours, and you can have 50 per tenant.
- Application object
An app's single global definition, i.e. its app registration in the home tenant; every tenant using the app gets a service principal created from it.
- Autopatch groups
A way of grouping devices in Windows Autopatch, joining Microsoft Entra groups to update policies. Each includes a Test ring and a Last ring with room for up to 15 deployment rings, and one tenant can create 300 of them.
- Autopilot deployment profile
Controls how the out-of-box experience runs on Windows Autopilot devices: which deployment mode and join type to use, and whether every targeted device should be converted to Autopilot. Up to 350 of these Intune profiles can exist in a tenant.
- Azure custom roles
Roles you author yourself in Azure RBAC, listing your own permitted actions, for cases no built-in role covers; a tenant can hold as many as 5,000.