Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
APIs under the /beta version in Microsoft Graph are subject to change. Use of these APIs in production applications is not supported. To determine whether an API is available in v1.0, use the Version selector.
Tenants are the foundation of your organization's cloud environment, providing the boundaries for collaboration, identity, access, and resource management. Microsoft Graph provides a growing set of APIs to programmatically manage, configure, and govern those tenants at scale—from maintaining consistent settings and establishing cross-tenant governance relationships to controlling how users collaborate across organizational boundaries and migrating content between tenants.
Available services and APIs
Backup and restore
The backup and restore APIs provide a programmatic surface for building business continuity into applications and managed service offerings.
- Microsoft 365 Backup Storage protects SharePoint sites, OneDrive accounts, and Exchange mailboxes with up to one year of retention and recovery points every ten minutes. Backups use append-only, immutable storage that prevents ransomware and compromised accounts from corrupting historical data. Restores are free, and data never leaves the Microsoft 365 trust boundary.
- Microsoft Entra Backup and Recovery extends that resilience to the identity layer: it automatically captures daily snapshots of critical directory objects—users, groups, applications, and other identity objects—through a Microsoft-managed process that no user or application, regardless of privilege, can disable or tamper with.
Using these APIs, your application can programmatically enable protection policies, run preview jobs to inspect what would change before committing a recovery, run targeted restore operations at scale, and monitor job progress end-to-end—so your solution can respond to bulk accidental changes, HR provisioning errors, or security compromises without manual portal intervention.
Configuration management
Define a baseline of your tenant configuration settings and monitor them over time. Detect and resolve configuration drift across workloads such as Conditional Access policies, security defaults, and identity providers.
Governance
Discover related tenants and establish governance relationships at scale. Configure cross-tenant delegated administration, manage multitenant applications across governed tenants, and enforce consistent governance policies.
Cross-tenant access
Define and control the external organizations that your users can collaborate with for seamless and secure collaboration. Configure cross-tenant access policies to specify:
- Which organizations and in what Microsoft Azure clouds can your users collaborate with?
- Is the collaboration limited to specific users in the organizations?
- What authentication controls are applied to users from the organizations?
Cross-tenant migration
Programmatically migrate user content across Microsoft 365 tenants for mergers, acquisitions, or organizational restructuring. Create and manage migration jobs for Exchange, Teams, and SharePoint data, and monitor progress end to end.
Multitenant organizations
Define and manage an organization that spans multiple Microsoft Entra tenants. Add or remove member tenants, configure roles, and set up cross-tenant access and synchronization templates so all tenants collaborate as a single entity.