Enterprise IT · 19 August 2026 · 4 min
After the acquisition: multi-tenant is not a transitional phase
Why tenant consolidation takes years, and what you do in the meantime
The integration plan after an acquisition always has the same item: "Consolidate IT platform, Q3." Five years later the group still has eleven tenants. This is not incompetence. It is the normal course of events, and planning should start from that.
Why consolidation drags on
Merging two Entra tenants is not a migration of user objects. It is a migration of everything hanging off them:
- Mailboxes and OneDrive content have to be moved across tenants, with downtime and follow-up on delegations that do not survive the move.
- Devices have to be rejoined. An Entra-joined machine cannot be moved to a new tenant without being wiped and rolled out again — which means physical logistics for every single employee, and an Autopilot deregistration in the right order.
- SSO integrations have to be rebuilt in the new tenant, with new app registrations, new claims, and a contract owner at each SaaS vendor who has to approve the change.
- Domains can only be verified in one tenant at a time, which makes cutover a hard, non-incremental event.
- Compliance history — retention policies, eDiscovery holds, audit logs — does not come along.
Add to that the fact that the acquired company usually has a quarterly close underway, production that cannot stop, and an IT department of two people who are already overworked. Consolidation gets postponed until "after the new year", every year.
And then the next acquisition arrives.
The conclusion: multi-tenant is the end state
This is the strategic reassessment many groups have not made: if consolidation never finishes, multi-tenant is not a transitional phase to be endured — it is the operating model, and it should be governed as a model and not as a backlog.
Microsoft has tools for this, and their limits are worth knowing.
Cross-tenant access settings govern B2B collaboration between the tenants. The defaults are open: inbound and outbound B2B collaboration are allowed, no organizations are preconfigured, and external MFA or device state is not trusted by default. Changing the last of these — trust settings — requires P1. That has a concrete consequence: without P1 and explicit configuration, a subsidiary's MFA will not count when the user works in the parent company's resources, and the user has to authenticate again.
Cross-tenant synchronization can create and maintain B2B users automatically in another tenant. Requires P1.
B2B direct connect (for shared Teams channels) is blocked by default and requires P1 in both tenants.
None of these give you shared administration. They give you collaboration. The administrative work — user creation, licensing, group membership, device rollout, offboarding — is still performed per tenant, in separate consoles, with separate role assignments and separate audit logs each with its own 30-day retention.
The arithmetic in separate consoles
Consider a perfectly ordinary hire in a group with eleven tenants. The new employee needs access in three of them — their own company, the group's shared services, and a project environment. That means:
- One user creation in the home tenant, with license, group membership and device rollout
- Two B2B invitations, each with its own guest object with no expiry date
- Three separate audit trails, in three separate logs, with three separate retention clocks
On departure all three have to be reversed, in the right order, by three different administrators who do not necessarily know about each other. This is where "access-after-departure" becomes a systemic condition and not an isolated error: the guest object in tenant two survives both the disabling of the account in tenant one and the departure of the inviting employee.
The due diligence angle
At the next acquisition this is also a negotiating question. How many privileged accounts does the target company have? How many guest users, invited by whom, active when? How many device objects with no owner? How many app registrations with Directory.ReadWrite.All and a client secret that expires in four months?
Answering this manually takes weeks of consultant hours, and the answer is out of date by the time it is delivered. It is also exactly the kind of risk that is not caught in a financial due diligence, but that becomes the buyer's problem from day one.
For companies covered by the Norwegian Digital Security Act (digitalsikkerhetsloven) — energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure — the requirement in section 12 of the regulations to «følge opp at personell ikke har flere tilganger enn nødvendig» [Unofficial translation: "follow up that personnel do not have more access rights than necessary"] is not suspended by the fact that the group consists of eleven tenants. The requirement is the same; the complexity of meeting it is eleven times greater.
What this means for Entra Logic
Entra Logic is multi-tenant from the ground up, not bolted onto a single-tenant product after the fact. Tenant switching sits in the global top menu, every module has per-tenant configuration, field names and enabled modules can be adapted per company, and cost reporting is allocated to company or customer.
The practical effect: the same governed model for one tenant or a hundred. Growth through acquisition does not require a corresponding increase in the number of privileged operators — and a newly acquired company's identity landscape can be made searchable in days instead of mapped manually over months.
Amesto is the proof that matters here: 58 companies, more than 1,000 employees, NOK 1.4 billion in revenue — run by three people in IT.
One clarification worth keeping sharp: group and portfolio management is the primary use case. MSP operations are a related, but not identical, use case. The two should not be presented as the same thing.
—
Sources
- Microsoft Learn — Cross-tenant access overview
- Microsoft Learn — Configure external collaboration settings
- Microsoft Learn — Windows Autopilot registration overview
- Microsoft Learn — Data retention for Microsoft Entra monitoring and health
- Lovdata — Digitalsikkerhetsforskriften (FOR-2025-06-20-1131)
RELEVANT SOLUTION
See how this is handled in practice:
Norwegian version: Les artikkelen på norsk
Related reading
- No, NIS2 does not yet apply in Norway
Enterprise IT · 7 min
- License leakage
Enterprise IT · 5 min
- One console, many tenants: what MSPs actually need from Entra ID tooling
Practice · 6 min