azureblog.co.uk
← cd ~/posts

Cross-tenant group sync is GA: one group, many tenants

Multi-tenant organisations can now sync security groups from a source tenant into target tenants, alongside the users already synced with cross-tenant sync.

2 min read✓ checked 3 Jun 2026Entra ID · Governance · What's new
On this page
  1. Why it matters
  2. How it works
  3. Before you start
  4. What it doesn't do

Cross-tenant synchronisation has been able to provision users from one Entra tenant into another for a while. That solved half the problem for multi-tenant organisations, such as groups with separate tenants per subsidiary or after an acquisition. The other half was groups: access in the target tenant still had to be granted by hand.

Source tenantGroup membership managed hereSubsidiary ASubsidiary BAcquired companyShared services
One source group, consumed in several tenants.

Cross-tenant group synchronisation, now generally available, syncs security groups from a source tenant to target tenants. Users and their group memberships arrive together.

Why it matters

  • Single source of truth. Manage membership once in the home tenant, and access follows into every tenant that consumes the group.
  • Cleaner offboarding. Remove someone from the source group and they lose access everywhere it's synced.
  • Fewer duplicate groups with slightly different names and memberships in each tenant.

How it works

Source tenantSync engineTarget tenantSync config scopes users andgroups1Provision users as members(B2B)2Provision security groupsand memberships3Target assigns the syncedgroup to appsMember removed at source5Membership removed in target6
Users and their groups arriving in a target tenant.

It builds on the cross-tenant synchronisation setup you may already have. The source tenant runs a sync configuration that scopes users and groups. The target tenant has to allow it in its cross-tenant access settings, with inbound user sync and automatic redemption enabled for the source tenant.

Before you start

  • Licensing. Group sync needs Entra ID Governance licences.
  • Scope carefully. Only sync the groups the target tenant actually uses for access.
  • Agree ownership. Decide who in the target tenant may assign synced groups to apps and roles, and who can change them in the source.
  • Cross-tenant sync for users already working between the tenants
  • Inbound sync allowed in the target's cross-tenant access settings
  • Entra ID Governance licences in place
  • A short list of groups the target actually needs
  • Naming agreed, so synced groups are recognisable in the target
  • Owners in both tenants who know who changes what

What it doesn't do

  • It syncs security groups for access. It isn't a way to replicate every Microsoft 365 group and its content between tenants.
  • Groups are managed at the source. Changes made to the synced copy in the target are overwritten.
  • Nested and dynamic group behaviour can differ from what you expect. Check the documentation for the current support before you design around it.
Do target admins lose control?

They keep control over what synced groups can access. They just don't manage membership, which is the point.

Can I use this for a merger?

Yes, it's a strong fit while tenants coexist. It doesn't replace a tenant-to-tenant migration if the end goal is one tenant.

You've reached the end of Shrinking hybrid identityBack to the path →