Microsoft Entra ID Governance

Use cross-tenant delegated administration

In brief

Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

Use cross-tenant delegated administration

Sign in to a governed tenant as a delegated administrator

After the governance relationship is active and GDAP role assignments are in place, members of the configured security group can sign in to the governed tenant.

  1. Confirm that your account is a member of a security group in the governing tenant that is's assigned roles in the governance policy template.

    You can sign in to a governed tenant in two ways:

    • From the Governed tenants page in the Microsoft Entra admin center.
    • OpenBy opening a supported admin portal URL directly.

    Sign in from the Microsoft Entra admin center

    Use the Governed tenants page to sign in to a governed tenant and appendchoose which admin portal to open.

    1. In the domain or tenant ID ofgoverning tenant, go to the Governed tenants page in the Microsoft Entra admin center.

    2. Select the governed tenant that you want to sign in to.

    3. On the command bar, select Sign in to tenant. A side pane opens that shows:

      • Whether you can sign in to the governed tenant. For a list of supported portals
      • The roles that you'll have in the governed tenant.
    4. If your group membership is configured with Privileged Identity Management (PIM) and workloads, see GDAP supported workloadsyour membership is eligible, the side pane shows an Activate button. Select Activate to activate your eligible group membership before you sign in.

    5. In the side pane, select the admin portal that you want to open. A new tab opens and prompts you to authenticate.

    6. Sign in with your governing tenant credentials to access the governed tenant.

    Sign in by using an admin portal URL

    1. Open a supported admin portal URL and append the domain or tenant ID of the governed tenant. For a list of supported portals and workloads, see GDAP supported workloads. For example:

      https://entra.microsoft.com/{governed-tenant-domain-or-id}

    2. Sign in with your governing tenant credentials.

    3. After successful sign-in, perform administrative tasks in the governed tenant based on the roles assigned to your security group.

    Update delegated administration roles