Cross-Tenant Group Synchronization in Microsoft Entra ID

Cross-Tenant Group Synchronization

Cross-tenant synchronization already allows organizations to sync users across Entra tenants. But in many environments, access is assigned through groups rather than directly to individual users.

Cross-Tenant Group Synchronization extends this model by allowing groups and their memberships to be synchronized between a source and a target tenant. The capability became generally available a few months ago and can be particularly relevant for organizations managing access across multiple tenants

It works by managing the security group in the source tenant and provisioning a corresponding security group in the target tenant. Users within the synchronization scope are provisioned along with their group memberships, and any subsequent membership changes in the source tenant are synchronized to the target tenant.

  • Static and dynamic security groups and Microsoft 365 groups can be synchronized from the source, but they’re represented as static security groups in the target tenant.
  • Nested groups and role-assignable groups aren’t supported.
  • Provisioning must be scoped to sync only assigned users and groups.
  • The feature requires the appropriate Entra ID Governance or Entra Suite licensing.

If this availability update passed under your radar, it may be useful to review it against your current cross-tenant architecture, particularly where group membership is being maintained separately across tenants.

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to Newsletter

Subscribe to our email newsletter to get the latest posts delivered right to your email.
Powered by Amail.