What is a tenant identifier?¶
A tenant identifier distinguishes one organisation's cloud environment, directory or workspace from another. It tells you where an account, resource or event belongs within the provider - not who used it or where the user was located.
The organisation name is not enough¶
One organisation may maintain separate production, testing, regional or subsidiary tenants. Names and domains can change after rebranding, acquisition or migration, while a stable tenant ID continues to identify the historical environment.
Record the tenant ID exactly with the provider, service, organisation name, domain and relevant account or resource IDs. This prevents similarly named environments from being merged when records from several organisations are combined.
Guest identities cross tenant boundaries¶
A person may authenticate through a home organisation but access a resource as a guest object in the host tenant. The home account ID and guest-object ID can refer to the same person in different identity contexts, yet they are not interchangeable.
For each event, distinguish:
- the tenant hosting the resource;
- the tenant or identity provider authenticating the account; and
- the account or guest object recorded as acting.
Historical configuration and directory records may be needed to show how those identities were linked at the relevant time. A tenant ID alone supplies organisational context, not personal attribution.
The point to remember
A tenant ID anchors an event to a particular cloud environment. Preserve it when separating organisations, migrations and guest access across tenant boundaries.