Cross-tenant group sync is GA: one group, many tenants
Multi-tenant organisations can now sync security groups from a source tenant into target tenants, alongside the users already synced with cross-tenant sync.
Cross-tenant synchronisation has been able to provision users from one Entra tenant into another for a while. That solved half the problem for multi-tenant organisations, such as groups with separate tenants per subsidiary or after an acquisition. The other half was groups: access in the target tenant still had to be granted by hand.
Cross-tenant group synchronisation, now generally available, syncs security groups from a source tenant to target tenants. Users and their group memberships arrive together.
Why it matters
- Single source of truth. Manage membership once in the home tenant, and access follows into every tenant that consumes the group.
- Cleaner offboarding. Remove someone from the source group and they lose access everywhere it's synced.
- Fewer duplicate groups with slightly different names and memberships in each tenant.
How it works
It builds on the cross-tenant synchronisation setup you may already have. The source tenant runs a sync configuration that scopes users and groups. The target tenant has to allow it in its cross-tenant access settings, with inbound user sync and automatic redemption enabled for the source tenant.
Before you start
- Licensing. Group sync needs Entra ID Governance licences.
- Scope carefully. Only sync the groups the target tenant actually uses for access.
- Agree ownership. Decide who in the target tenant may assign synced groups to apps and roles, and who can change them in the source.
- Cross-tenant sync for users already working between the tenants
- Inbound sync allowed in the target's cross-tenant access settings
- Entra ID Governance licences in place
- A short list of groups the target actually needs
- Naming agreed, so synced groups are recognisable in the target
- Owners in both tenants who know who changes what
What it doesn't do
- It syncs security groups for access. It isn't a way to replicate every Microsoft 365 group and its content between tenants.
- Groups are managed at the source. Changes made to the synced copy in the target are overwritten.
- Nested and dynamic group behaviour can differ from what you expect. Check the documentation for the current support before you design around it.
Do target admins lose control?
They keep control over what synced groups can access. They just don't manage membership, which is the point.
Can I use this for a merger?
Yes, it's a strong fit while tenants coexist. It doesn't replace a tenant-to-tenant migration if the end goal is one tenant.