Hello @JND,
Thank you for posting your query on Microsoft Q&A.
Based on your description, I understand that your query involves multiple service areas in Azure. Allow me to provide an explanation specific to my area of expertise.
Guest Account / Cross-Tenant Sync: Guest accounts cannot be used to connect to VMs, as they are shadow accounts without locally stored passwords.
This is a well-known limitation (or by design) regarding VM sign-in with Microsoft Entra Guest accounts. Microsoft Entra Guest accounts cannot connect to Azure VMs or Azure Bastion-enabled VMs using Microsoft Entra authentication.
For further details, please refer to the official documentation:
Authentication requirements for Azure VM sign-in
Automating Customer Onboarding and Account Lifecycle Management
You can simplify customer onboarding and manage account lifecycles effectively using Lifecycle Workflows in Microsoft Entra ID Governance. Additional governance capabilities include:
- Entitlement Management
- Access Reviews
- Privileged Identity Management (PIM)
Please review the following resources for detailed guidance:
Lifecycle Workflows Deployment
Entitlement Management Scenarios
Privileged Identity Management Deployment Plan
Using a single account to manage all customer tenants across Azure services may lead to limitations, such as the inability to sign in to VMs with guest accounts. These restrictions make managing multiple tenants less user-friendly.
As you are already aware of these challenges, I would recommend requesting this on the Microsoft Feedback Portal. This is a great way to let them know how important this feature is for your organization. You can provide details with Microsoft can help push for the development of more integrated solutions in the future about how would benefit your use case and any other relevant information as Engineers constantly check there for features.
I hope this information is helpful. Please feel free to reach out if you have any further questions.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Thanks,
Raja Pothuraju.