Question about device and security management in multi-tenant (sub-tenant) configuration

Shawn Goodwin 176 Reputation points
2024-10-09T15:04:23.94+00:00

My company is growing and has created several LLCs for various product lines. The business intent is to spin off these companies into subsidiaries. It remains to be seen if they will be a "wholly owned" or "affiliate" type subsidiary.

I have to determine the best way to separate these potential subsidiaries within M365/InTune/Exchange/Azure/Defender/etc in a way that does not significantly increase our workload but also setup these subsidiaries so they can be severed from the parent company if/when that ever happens.

I have read all the documentation about multi-tenant orgs in EntraID. That seems fairly straight forward and will not result in a lot of duplicative work.

I am concerned about InTune, Exchange/Defender/Azure. Over the past 3 years we've rolled out just about every MDM and security tool available for corporate endpoints and Application Protection Policies for personal devices; we've published data labels, DLP policies, and sensitivity labels through Purview; we've added VDRs for SharePoint; we've employed Azure services for automation, access, and storage solutions; the list goes on and on.

Will there be a way for us to propagate those policies and configurations down to the subsidiary tenants, or will we have to recreate everything from scratch for inside each tenant?

P.S. Before posting this question, I reviewed the "similar questions" that display while drafting a new question. Those questions address the "how to" for multi-tenant management and do not answer my question.

SharePoint
SharePoint
A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
10,904 questions
Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,612 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,251 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
214 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,305 questions
{count} votes

Accepted answer
  1. Vasil Michev 108.8K Reputation points MVP
    2024-10-09T15:42:33.8466667+00:00

    No, you will have to recreate them in each tenant. Or use some "configuration as code" third-party tool that can copy these across tenants. MTO simply does not cover any of these.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.