What is a tenant, organisation or workspace?¶
It is a provider-managed environment containing a customer's identities, resources, policies and records. It is a logical boundary inside the cloud service, not a particular server or building. Providers use different labels, but the practical question is the same: which customer environment contained this user, file or event?
Put Dave inside the right boundary¶
Northstar subscribes to Microsoft 365. That subscription uses a Microsoft Entra tenant with an initial domain such as northstar.onmicrosoft.com and Northstar's verified custom domain. Inside it are Dave's user object, groups, administrator roles, SharePoint sites, OneDrive resources and audit records.
A supplier also invites Dave into its own Entra tenant as a guest. Dave may sign in using his Northstar identity, but the supplier's guest object, permissions and activity belong to the supplier's environment.
Do not ask only “Which provider?” Microsoft may authenticate the home identity while a different customer's tenant governs the resource and holds the guest activity.
The tenant IDs in the illustration are fictional shorthand, not real Microsoft identifiers.
The tenant is the first container to identify¶
An investigation involving dave@northstar.example should distinguish:
| Layer | Example question | Useful identifier or record |
|---|---|---|
| Provider | Which service is involved? | Microsoft 365, Google Workspace or another named platform |
| Customer environment | Which organisation's logical boundary? | Tenant, customer, organisation or workspace ID |
| Directory identity | Which member, guest or workload object? | User/object ID, type and home environment |
| Resource | Which file, site, mailbox, shared drive or application? | Object ID, URL, path or service-specific identifier |
| Permission | Why could the identity reach it? | Group membership, sharing grant, role or invitation |
| Event | What did the provider record? | Operation, actor, target, time, client and result |
This hierarchy prevents records from two organisations being combined merely because the same email address or person's name appears in both.
Tenant, organisation and organisational unit are not interchangeable
Microsoft currently says that Microsoft 365, Azure and Dynamics CRM Online subscribers already use Microsoft Entra ID and that each tenant is automatically a Microsoft Entra tenant. A new directory has an initial onmicrosoft.com domain and can add custom domains.
Google Workspace uses organisation and account language for the customer's managed environment. Inside it, an organisational unit is a subdivision used to group users and apply settings. It is not automatically equivalent to the whole customer environment.
Record the provider's own label and identifier. Translating everything into “tenant” may be convenient in conversation but can conceal which level a returned field actually describes.
Guests and applications can cross the boundary
Microsoft Entra distinguishes internal members and guests from external members and guests. An external identity may authenticate through its home environment while receiving access in another tenant.
Connected applications and service identities can also operate inside a tenant. A record attributed to an application context should not be rewritten as a fresh human sign-in merely because the application acts for a named user.
Use the boundary to choose the evidence holder¶
If Dave opens a supplier's SharePoint file:
- Northstar may hold the home identity and device-management records.
- Microsoft operates the platform and defines the provider fields.
- The supplier may hold the guest invitation, resource permissions and tenant audit export.
- Dave's device may hold the local browser, application and file evidence.
No single label tells the whole story. The tenant boundary shows who controlled the resource and where the relevant administrative and audit records should be sought.
The point to remember
Identify the customer environment before joining users or events. Provider, tenant, directory object, resource and permission are different layers - and a guest can connect two environments without merging them.