A tenant is an organization's dedicated instance of Microsoft Entra ID: the directory holding its users, groups, devices, applications, and license subscriptions, isolated from every other organization's. Everything discussed on this site, nesting, inheritance, drift, happens inside a tenant.
What lives in a tenant#
The objects that make up directory structure:
- Users and guests: the human identities, internal and external.
- Groups: the containers that grant access and licenses, including through nesting.
- Devices, service principals, and contacts: the non-human members.
- Subscriptions: the purchased SKUs whose seats assignments consume.
Why tenant structure is a governance object#
Access, licensing, and compliance in Microsoft 365 are all computed from tenant structure, yet the structure itself is rarely governed as a first-class asset. Tenants that treat their group hierarchy as architecture, with rules, reviews, and measurement, avoid the drift that the rest discover during incidents and audits.
VisualizerEngine
Tenants in VisualizerEngine
Each tenant onboards independently through a read-only admin-consent link and is mirrored into per-tenant storage isolated by database row-level security, proven by automated tests. The whole tenant's structure becomes explorable as a hierarchy, graph, or sunburst.