Skip to main content

Multi-Tenant Management

Users who manage multiple Microsoft 365 tenants switch between the tenants they manage from a single sign-in. Click the tenant name in the top bar and use Change Directory to pick from the tenants you have signed into; the app switches to that tenant's context.

Roles and access

  • Onboarding a tenant requires a Global Administrator. Admin consent is granted once to the app's read-only application permissions. This is a one-time step per tenant.
  • Viewing a tenant's data requires Global Reader or Security Reader (Global Administrator and Security Administrator also qualify).
  • Access to security posture is restricted to these roles. The restriction is enforced both in the interface and server-side; a user without one of these roles cannot view the posture data.

Data isolation

Each tenant's data is isolated by its own tenant id. One tenant's data is never returned to another tenant.