Skip to content
Skip to main content
Cloud Services Technical Explainer

What is a tenant, organisation or workspace?

It is a provider-managed environment containing a customer's identities, resources, policies and records. It is a logical boundary inside the cloud service, not a particular server or building. Providers use different labels, but the practical question is the same: which customer environment contained this user, file or event?

Put Dave inside the right boundary

Northstar subscribes to Microsoft 365. That subscription uses a Microsoft Entra tenant with an initial domain such as northstar.onmicrosoft.com and Northstar's verified custom domain. Inside it are Dave's user object, groups, administrator roles, SharePoint sites, OneDrive resources and audit records.

A supplier also invites Dave into its own Entra tenant as a guest. Dave may sign in using his Northstar identity, but the supplier's guest object, permissions and activity belong to the supplier's environment.

The tenant IDs in the illustration are fictional shorthand, not real Microsoft identifiers.

The tenant is the first container to identify

An investigation involving dave@northstar.example should distinguish:

Layer Example question Useful identifier or record
Provider Which service is involved? Microsoft 365, Google Workspace or another named platform
Customer environment Which organisation's logical boundary? Tenant, customer, organisation or workspace ID
Directory identity Which member, guest or workload object? User/object ID, type and home environment
Resource Which file, site, mailbox, shared drive or application? Object ID, URL, path or service-specific identifier
Permission Why could the identity reach it? Group membership, sharing grant, role or invitation
Event What did the provider record? Operation, actor, target, time, client and result

This hierarchy prevents records from two organisations being combined merely because the same email address or person's name appears in both.

Tenant, organisation and organisational unit are not interchangeable

Microsoft currently says that Microsoft 365, Azure and Dynamics CRM Online subscribers already use Microsoft Entra ID and that each tenant is automatically a Microsoft Entra tenant. A new directory has an initial onmicrosoft.com domain and can add custom domains.

Google Workspace uses organisation and account language for the customer's managed environment. Inside it, an organisational unit is a subdivision used to group users and apply settings. It is not automatically equivalent to the whole customer environment.

Record the provider's own label and identifier. Translating everything into “tenant” may be convenient in conversation but can conceal which level a returned field actually describes.

Guests and applications can cross the boundary

Microsoft Entra distinguishes internal members and guests from external members and guests. An external identity may authenticate through its home environment while receiving access in another tenant.

Connected applications and service identities can also operate inside a tenant. A record attributed to an application context should not be rewritten as a fresh human sign-in merely because the application acts for a named user.

Use the boundary to choose the evidence holder

If Dave opens a supplier's SharePoint file:

  1. Northstar may hold the home identity and device-management records.
  2. Microsoft operates the platform and defines the provider fields.
  3. The supplier may hold the guest invitation, resource permissions and tenant audit export.
  4. Dave's device may hold the local browser, application and file evidence.

No single label tells the whole story. The tenant boundary shows who controlled the resource and where the relevant administrative and audit records should be sought.

The point to remember

Identify the customer environment before joining users or events. Provider, tenant, directory object, resource and permission are different layers - and a guest can connect two environments without merging them.

Provider sources - checked 2 September 2026
Reference: CLD-017Cloud Services