Managing the same groups in multiple Entra tenants?

🔒 Secure Bits 💡

𝗠𝗮𝗻𝗮𝗴𝗶𝗻𝗴 𝘁𝗵𝗲 𝘀𝗮𝗺𝗲 𝗴𝗿𝗼𝘂𝗽𝘀 𝗶𝗻 𝗺𝘂𝗹𝘁𝗶𝗽𝗹𝗲 𝗘𝗻𝘁𝗿𝗮 𝘁𝗲𝗻𝗮𝗻𝘁𝘀? 𝗧𝗵𝗮𝘁 𝗺𝗮𝘆 𝗻𝗼 𝗹𝗼𝗻𝗴𝗲𝗿 𝗯𝗲 𝗻𝗲𝗰𝗲𝘀𝘀𝗮𝗿𝘆.

📆 Newly added feature in May 2026

Organizations with multiple Entra tenants often end up maintaining the same access groups repeatedly across environments.

One group for employees in Tenant A.

Another group for the same employees in Tenant B.

And then someone has to keep them in sync.

Microsoft is 𝗲𝘅𝘁𝗲𝗻𝗱𝗶𝗻𝗴 𝗖𝗿𝗼𝘀𝘀-𝗧𝗲𝗻𝗮𝗻𝘁 𝗦𝘆𝗻𝗰𝗵𝗿𝗼𝗻𝗶𝘇𝗮𝘁𝗶𝗼𝗻 to support security group synchronization, allowing groups and their memberships to be synchronized between tenants automatically.

🤔 𝗪𝗵𝘆 𝘁𝗵𝗶𝘀 𝗺𝗮𝘁𝘁𝗲𝗿𝘀

Access management is usually driven by groups. The larger the organization, the bigger the problem becomes.

When groups are duplicated across tenants:

– Memberships drift over time

– Offboarding becomes inconsistent

– Access reviews become harder

– Administrators spend time maintaining the same identities multiple times

🧠 𝗪𝗵𝗮𝘁’𝘀 𝗿𝗲𝗮𝗹𝗹𝘆 𝗵𝗮𝗽𝗽𝗲𝗻𝗶𝗻𝗴

Instead of synchronizing only users, organizations can synchronize selected groups and their memberships. That means when you 𝗮𝗱𝗱 𝗼𝗿 𝗿𝗲𝗺𝗼𝘃𝗲 𝗮 𝘂𝘀𝗲𝗿 from the source group, the membership 𝘂𝗽𝗱𝗮𝘁𝗲𝘀 𝗶𝗻 𝘁𝗵𝗲 𝘁𝗮𝗿𝗴𝗲𝘁 𝘁𝗲𝗻𝗮𝗻𝘁. Applications, SharePoint sites, Teams, and other resources can rely on synchronized groups instead of manually maintained copies. Group 𝗺𝗲𝗺𝗯𝗲𝗿𝘀𝗵𝗶𝗽 𝗶𝘀 𝗺𝗮𝗻𝗮𝗴𝗲𝗱 𝗶𝗻 𝗼𝗻𝗲 𝗽𝗹𝗮𝗰𝗲 and propagated to connected tenants.

🛠️ 𝗪𝗵𝗲𝗿𝗲 𝗶𝘀 𝘁𝗵𝗶𝘀 𝘂𝘀𝗲𝗳𝘂𝗹

Even though this is a niche use for most of you, these are places where this comes handy:

– Mergers and acquisitions

– Multi-tenant enterprises

– Subsidiaries with separate tenants

– Shared services organizations

🛡️ 𝗗𝗼 𝘁𝗵𝗶𝘀 𝗯𝗲𝗳𝗼𝗿𝗲 𝘀𝘆𝗻𝗰𝗵𝗿𝗼𝗻𝗶𝘇𝗶𝗻𝗴 𝗴𝗿𝗼𝘂𝗽𝘀

– Review which groups are truly authoritative

– Limit synchronization scope

– Monitor privileged groups carefully

– Validate access assignments in target tenants

⚠️ 𝗜𝗺𝗽𝗼𝗿𝘁𝗮𝗻𝘁

Synchronizing groups also means 𝘀𝘆𝗻𝗰𝗵𝗿𝗼𝗻𝗶𝘇𝗶𝗻𝗴 𝗺𝗶𝘀𝘁𝗮𝗸𝗲𝘀. If an incorrect membership grants access in the source tenant, that access may now propagate automatically to other tenants as well.

Treat synchronized groups as a privileged identity management process, not just an administrative convenience.

✅ This is one of those features that seems insignificant, but can reduce operational overhead in multi-tenant environments while improving consistency and governance.

💬 Question for admins

Is Cross-Tenant Group Synchronization a feature you were waiting for or is it a nice-to-have?

𝘈𝘶𝘵𝘩𝘰𝘳 𝘰𝘧 𝘵𝘩𝘦 𝘱𝘰𝘴𝘵:

Martin Strnad