Create Tenant
The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Governance.
The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.
The documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.
The page removes the standalone setup section and detailed steps for configuring relative time-based triggers, including timing options, offsets, supported attributes, and enablement notes.
Administrators can configure triggers using operators, offsets from 0 to 180 days, before or after event timing, and supported user attributes such as hire date, leave date, and creation date. Both the workflow and its schedule must be enabled for evaluation.
The documentation adds examples describing how designated users can request access packages for others and clarifies that both requestors and targets need the required license.
The allowed offset for Days from event, and Days to event when using Between, increased from 180 to 365 days.
The Event user attribute description in the lifecycle workflow execution conditions documentation was reformatted.
Documentation describes relative comparisons using Exactly, Between, or Less than or equal to, with event offsets from 0 to 180 days before or after supported user-attribute dates. The admin center temporarily shows two choices for the same time-based trigger.
The documentation now explains that relative time-based comparisons expand the standard time-based attribute trigger. During preview, the admin center shows two choices, but both represent the same trigger.
The documentation now specifies selecting an existing Microsoft Customer Agreement (MCA) subscription and resource group from the billing account when creating a tenant with the secure add-on tenant creation feature.
The documentation now specifies that secure add-on tenant creation requires an existing paid Azure subscription and resource group, with the subscription associated with an Enterprise Agreement.
The secure add-on tenant creation documentation now refers to selecting an existing subscription, rather than specifically an existing Microsoft Customer Agreement subscription, from the billing account.
The documentation now specifies paid-account, billing, tenant-creation permission, role, and default governance-policy requirements for creating governed workforce tenants. Free or trial tenants cannot create additional tenants, and EA or pay-as-you-go billing accounts are supported.
The documentation now describes creating a lifecycle workflow by cloning an existing workflow in the Microsoft Entra admin center, including review and customization steps.
The tenant creation guidance now links references to the Microsoft Entra ID Free billing asset to the relevant billing documentation instead of the previous signals-and-metrics page.
The documentation now says the home tenant—not the governing tenant—must have the default governance policy template for this optional prerequisite. The service uses the template with ID `default`.
The documentation now labels the governing tenant’s default governance policy template as optional instead of a required prerequisite. The tenant creation service still uses only the default template (ID: `default`).
The documentation now explicitly states that the required Enterprise Agreement or Pay-As-You-Go subscription must be paid.
The prerequisite now specifies that the home tenant must have at least one paid, license-based Microsoft product. Free and trial licenses do not qualify.
The guide now links the Microsoft Online Subscription Agreement (MOSA) in its billing-account prerequisites. The Enterprise Agreement and Pay-As-You-Go references remain.
The prerequisite now refers to Enterprise Agreement or Pay-As-You-Go subscriptions and identifies MOSA and MCA subscriptions, replacing billing-account wording.
The tenant creation guide now explicitly states that the required subscription permissions are Azure Resource Manager (ARM) permissions, provided through the Tenant Contributor or Subscription Owner/Creator role.
The deployment guide now documents a paid Azure subscription linked to an Enterprise Agreement or pay-as-you-go billing account, with Tenant Contributor or Subscription Owner/Creator access for the selected subscription.
The mover workflow templates now list the “Remove all access package assignments for user” task, with removal scheduled by default for 15 days.
The task is now listed for both Leaver and Mover templates. The documentation also states that setting daysUntilExpiration schedules removal instead of removing assignments immediately.
The lifecycle workflows task table now lists “Remove all access package assignments for user” for both Leaver and Mover workflow templates.
The tutorial now includes a task that removes all access package assignments for a user, scheduled by default for 15 days.
The documentation now covers delegating multi-resource access reviews in addition to access package approvals. It also documents restrictions for delegate selection and maximum delegation duration.
The access package assignments page no longer includes a note stating that assignment managers cannot bypass required approval settings or directly assign identities without approval.
The documentation now expands its guidance that administrators must verify users meet existing access package policy requirements before assigning them; otherwise, assignment may fail.
The documentation removes an inaccurate statement implying that direct assignment to an access package requires approval. It now states only that assigned users must meet the policy’s eligibility requirements.
The entitlement management delegation documentation removes a note about access package assignment managers being unable to bypass approval requirements when directly assigning identities.
The documentation no longer labels Catalog Access Reviews or custom data provided resources as preview. It also generalizes reviewers beyond managers and adds a note that changes within 12 hours before a review starts may not appear.
The page no longer labels Catalog Access Reviews or Custom Data Provided Resource as preview. It updates wording from managers to reviewers, removes the statement that managers are primary reviewers, adds a 12-hour data-change limitation before review start, and updates links.
The guide removes the Preview label and adds steps for creating the resource and Logic App, automatic upload notifications, manual result application, and new resource parameters.
The page no longer labels the capability as Preview and now documents catalog resource setup, Logic App integration, manual uploads, and applying results to non-Approve decisions. The previous note about single-stage reviews with manager reviewers was removed.
The governance licensing documentation now includes “PIM - Custom extensions for role activation (Preview)” with licensing indicators.
The article was revised to use lowercase “account discovery,” clarify connector and limitation wording, update the GitHub reference, and change its date from May 26, 2026, to August 11, 2026. It continues to describe the existing discovery process and requirements.
The documentation now states that support for the `memberOf` rule operator ends November 3, 2026, replacing October 27, 2026. Policies using it will be quarantined and stop processing assignments from that date.
The documentation states that, starting October 27, 2026, automatic assignment policies using memberOf will be quarantined. Assignment processing will stop, and no assignments will be added or removed until memberOf is removed.
When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.
Learn how to assign or remove the application permissions and roles that the Tenant Configuration Management service uses to create snapshots and run monitors
Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift
Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.
Learn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
This article walks you through managing unsponsored guests using the **Unsponsored guest cleanup (Preview)** workflow template.
Learn how to view monitor results and configuration drifts and manage configuration monitors in Microsoft Entra Tenant Governance
Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.
In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.
- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.
Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
Learn how to use Microsoft Graph to retrieve the underlying users and applications behind Tenant Governance related tenant discovery signals.
With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:
- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).
Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.
The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.
Learn how to use the What-if tool in Lifecycle Workflows to simulate workflow execution and preview results without impacting actual users.
Learn how Microsoft Entra ID is licensed for guest users.
Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra
Microsoft Entra will block new assignments to Partner Tier1 and Tier2 Support roles starting August 3, 2026, as these roles are retired. Existing assignments remain valid. Admins should update scripts and use alternative roles like User Administrator. No impact if these roles aren't used.
Assign Azure RBAC roles to access packages and catalogs in Microsoft Entra Entitlement Management. Learn how to manage access with least privilege principles.
Learn how to set tenant-wide and workflow-specific execution limits and manage quarantined workflows in Lifecycle Workflows to prevent large-scale impact.
This article a tutorial on how to provision users and groups using cloud sync.
This article a tutorial on how to provision users and groups from and managed in Microsoft Entra ID to Active Directory.
Learn how to integrate Darwinbox HR with Microsoft Entra ID to automate user provisioning, manage lifecycle workflows, and streamline HR-driven processes.
List Microsoft Entra Backup and Recovery snapshots that can help recover directory objects used by Global Secure Access.
Learn how to set tenant-wide and workflow-specific execution limits and manage quarantined workflows in Lifecycle Workflows to prevent large-scale impact.
1. Assign all discovered users to a specific access package:
Learn how to configure whether requestors can see approver details for pending access package requests in the My Access portal at the tenant or package level.
In entitlement management, you can see who is assigned to access packages, their policy, status, and identity lifecycle (preview). If an access package has an appropriate policy, you can also directly assign identities to an access package. This article describes how to view, add, and remove assignments for access packages.
Guest users that already existed in your tenant by being invited are ungoverned. After an ungoverned guest that requests access packages lose their last access package assignment, they'll remain in the tenant indefinitely. If there are guests that have an access package assignment, and only need access from that access package, and there's no other need for them to remain in the tenant, you can convert them to be governed during the time they have that access package assignment. You can directly convert those ungoverned users to be governed by using the **Mark Guests as Governed** functionality in the top menu bar of an access package.
To determine the least privileged role for a task, you can also reference [Least privileged roles by task in Microsoft Entra ID](../identity/role-based-access-control/delegate-by-task.md#entitlement-management-least-privileged-roles).
This article describes how to reprocess assignments in an existing access package.
- The ability to see active access package assignment of all of their direct reports.
Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.
Learn about new features and updates in Microsoft Entra Agent ID at general availability, including non-Microsoft integrations, migration guides, and enterprise governance.
Learn how to use Account Discovery to find and categorize existing user accounts in target applications, match them to Microsoft Entra ID users, and prepare for provisioning governance.
This article explains how access packages provide governance for agent identity access to resources.
Learn ways to identify app risk levels, stop breaches and leaks in real time, and use app connectors to take advantage of provider APIs for visibility and governance.
In this article, you learn how to integrate SCC LifeCycle with Microsoft Entra ID. When you integrate SCC LifeCycle with Microsoft Entra ID, you can:
This article a tutorial on how to provision users and groups using cloud sync.
This article a tutorial on how to provision users and groups using connect sync.
This article a tutorial on how to provision users and groups from and managed in Workday.
This article a tutorial on how to provision users and groups from on-premises to cloud using MIM.
This article a tutorial on how to provision users and groups to AD with Workday.
This article a tutorial on how to provision users and groups to Active Directory using MIM.
Learn how to apply sensitivity labels to cloud security groups in Microsoft Entra ID for consistent classification and governance.
This article describes use cases Microsoft Entra ID Governance.
Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.
Learn about new features and updates in Microsoft Entra Agent ID at general availability, including non-Microsoft integrations, migration guides, and enterprise governance.
Learn how to configure custom extensions in Microsoft Entra Privileged Identity Management (PIM) to integrate custom business logic into role activation workflows.
Learn how to configure single sign-on between Microsoft Entra ID and SCC LifeCycle.
Learn how to configure single sign-on between Microsoft Entra ID and Smart Global Governance.
Learn how to integrate Darwinbox HR with Microsoft Entra ID to automate user provisioning, manage lifecycle workflows, and streamline HR-driven processes.
|[EM - Agents and service principals assigned to access packages](~/id-governance/entitlement-management-access-package-create.md#allow-users-service-principals-and-agent-identities-in-your-directory-to-request-the-access-package)|||||| :white_check_mark: |
Microsoft Entra Agent ID requires every [agent identity](/entra/agent-id/agent-identities) and [agent identity blueprint](/entra/agent-id/agent-blueprint) to have at least one sponsor. A sponsor is a human user, or supported group, that holds business accountability for the agent's lifecycle, such as deciding when the agent is no longer needed, approving extensions when access expires, and authorizing suspension during incidents. A sponsor is different from an owner, which designates the human users responsible for technical operations and incident response.
Microsoft Entra Agent ID introduced two identity types: [agent identities](/entra/agent-id/agent-identities) and [agent identity blueprint principals](/entra/agent-id/agent-blueprint). These identity objects derive from service principals, and so carry the same requirements and best practices for ownership, lifecycle management, and cleanup as any service principal. Blueprint principals are the provisioning surface from which agent identities are created and can hold grants that propagate to child agents. Having a designated owner for these objects helps in two important areas of agent identity management:
1. Select **Next: Resource roles**. On the **Resource roles** tab, you select the resource roles to include in the access package. Access packages for agent identities can have security group memberships, directory roles, or API permissions as resource roles. For more information, see [add a group](/entra/id-governance/entitlement-management-access-package-resources#add-a-group-or-team-resource-role), [add a Microsoft Entra role](/entra/id-governance/entitlement-management-access-package-resources#add-a-microsoft-entra-role-assignment), and [add an API permission](/entra/id-governance/entitlement-management-access-package-resources#add-an-api-permission-preview). Don't add application roles, SAP roles, or SharePoint Online site roles to an access package for agent identities.
Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.
1. Browse to **ID Governance** > **Entitlement management** > **Access packages**.
In SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.
Learn how to view, add, and remove assignments for an access package in entitlement management.
Lifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.
This article explains how access packages provide governance for agent identity access to resources.
Learn about new features and updates in Microsoft Entra Agent ID at general availability, including third-party integrations, migration guides, and enterprise governance.
Learn how Microsoft Entra Tenant Governance automatically establishes governance relationships when you create add-on tenants using secure tenant creation.
Learn about configuration management capabilities in Microsoft Entra Tenant Governance, including baselines and drift monitoring
Learn how to create a new Microsoft Entra tenant using the secure add-on tenant creation workflow in Tenant Governance
Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift
Learn about cross-tenant delegated administration and how it enables centralized management across tenants in Microsoft Entra
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring