Set up multi-tenant management in Microsoft Defender XDR

Applies to:

This article describes the steps you need to take to start using multi-tenant management in Microsoft Defender XDR.

Note

In multi-tenant management, interactions between the multi-tenant user and the managed tenants could involve accessing data and managing configurations. The ability to undertake these actions is determined by the permissions a managed tenant has granted the multi-tenant user.

  1. Review the requirements
  2. Verify your tenant access
  3. Set up multi-tenant management in Microsoft Defender XDR

Note

Data privacy, role-based access control (RBAC) and Licensing are respected by multi-tenant management in Microsoft Defender XDR.

Review the requirements

The following table lists the basic requirements you need to use multi-tenant management in Microsoft Defender XDR.

Requirement Description
Microsoft Defender XDR prerequisites Verify you meet the Microsoft Defender XDR prerequisites
Multi-tenant access To view and manage the data you have access to in multi-tenant management, you need to ensure you have the necessary access. For each tenant you want to view and manage, you need to have either:

- Granular delegated admin privileges (GDAP)
- Microsoft Entra B2B authentication

To learn more about how to synchronize multiple B2B users across tenants, see Configure cross-tenant synchronization.
Permissions Users must be assigned the correct roles and permissions at the individual tenant level, in order to view and manage the associated data in multi-tenant management. To learn more, see:

- Manage access to Microsoft Defender XDR with Microsoft Entra global roles
- Custom roles in role-based access control for Microsoft Defender XDR

To learn how to grant permissions for multiple users at scale, see What is entitlement management.

Note

Setting up multi-factor authentication trust is highly recommended for each tenant to avoid missing data in multi-tenant management Microsoft Defender XDR.

Verify your tenant access

In order to view and manage the data you have access to in multi-tenant management, you need to ensure you have the necessary permissions. For each tenant you want to view and manage, you need to either:

Verify your tenant access with Microsoft Entra B2B

  1. Go to My account.

  2. Under Organizations > Other organizations you collaborate with see the list of organizations you have guest access to.

    Screenshot of organizations in the myaccount portal

  3. Verify all the tenants you plan to manage appear in the list.

  4. For each tenant, go to the Microsoft Defender portal and sign in to validate you can successfully access the tenant.

Verify your tenant access with GDAP

  1. Go to the Microsoft Partner Center.
  2. Under Customers you can find the list of organizations you have guest access to.
  3. Verify all the tenants you plan to manage appear in the list.
  4. For each tenant, go to the Microsoft Defender portal and sign in to validate you can successfully access the tenant.

Set up multi-tenant management

The first time you use multi-tenant management in Microsoft Defender XDR, you need setup the tenants you want to view and manage. To get started:

  1. Sign in to Multi-tenant management in Microsoft Defender XDR

  2. Select Add tenants.

    Screenshot of the Microsoft Defender XDR multi-tenant portal setup screen

  3. Choose the tenants you want to manage and select Add

Note

The multi-tenant view in Microsoft Defender XDR currently has a limit of 50 target tenants.

The features available in multi-tenant management now appear on the navigation bar and you're ready to view and manage security data across all your tenants.

Screenshot of multi-tenant management in Microsoft Defender XDR

Next step

Use these articles to get started with multi-tenant management in Microsoft Defender XDR: