Microsoft Entra ID Governance

Create a governed workforce tenant

In brief

Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

Create a governed workforce tenant

This article is for IT administrators who need to create an add-on tenant that is governed from an existing Microsoft Entra tenant. Review the prerequisites before you use the secure add-on tenant creation flow.

When you create a tenant using the Governed Workforce option in the Microsoft Entra admin center, the secure add-on tenant creation flow automatically:

This article doesn't cover creating an external tenant configuration for consumer-facing apps. For customer identity and access management scenarios, see Microsoft Entra External ID for customers.

Prerequisites

Before you create a governed workforce tenant, confirm that you meet these requirements:

  • Your organization is a paid customer. Customers using a free tenant or trial subscription can't create additional tenants from the Microsoft Entra admin center. If you need a new tenant, sign up for a free Azure account.
  • You must have at leasteither an Enterprise Agreement (EA) or Pay-As-You-Go subscription. Both Microsoft Online Subscription Agreement (MOSA) and Microsoft Customer Agreement (MCA) billing accounts are supported. To identify your billing account type, see View your billing accounts in the Azure portal.
  • Your Microsoft Entra tenant allows member users to create add-on tenants. If Restrict non-admin users from creating tenants is set to Yes, your account needs the Tenant Creator role.
  • You have the required Azure Resource Manager (ARM) permissions for the selected subscription through the Tenant Contributor permissions on at least one Microsoft Customer Agreement (MCA) subscription.
  • Enterprise Agreement (EA) subscriptions aren't supported.or Subscription Owner/Creator role.
  • The governing tenant has a configured default governance policy template must be configured in the governing tenant.. The tenant creation service uses only the default template (ID: default). If the default template isn't defined, the secure add-on tenant creation flow doesn't establish a governance relationship, even if other templates exist.

Create the tenant