2.1 Creating a Microsoft 365 Tenant

Key Takeaways

  • A Microsoft 365 tenant is the organization's dedicated instance of Microsoft's cloud, anchored to an initial .onmicrosoft.com domain that cannot be renamed after creation
  • Every M365 tenant is backed by exactly one Microsoft Entra ID directory, and one Entra ID directory can serve multiple Microsoft cloud subscriptions
  • Creating a tenant produces the first Global Administrator account, the highest-privilege role in Entra ID, which can create other admins and assign billing ownership
  • The initial .onmicrosoft.com domain name and the tenant's primary geographic/datacenter region are permanent decisions that cannot be changed later without a new tenant
  • Single-tenant designs serve most enterprises; multi-tenant designs are used for strict sovereignty, merger/isolation, or partner/customer cloud separation scenarios
Last updated: August 2026

Quick Answer: A Microsoft 365 tenant is your organization's dedicated instance of Microsoft's cloud. It is anchored to a unique <name>.onmicrosoft.com domain and backed by a single Microsoft Entra ID directory. You create one by signing up at microsoft365.com, choosing a plan, and completing provisioning. The first account becomes the Global Administrator. Two decisions are permanent: the initial .onmicrosoft.com name and the tenant's primary region.

What a Tenant Actually Is

A Microsoft 365 tenant is the organization-level container for everything Microsoft 365: identities, subscriptions, data, and admin settings. It is not the same as a subscription — a tenant can hold many subscriptions — and it is not the same as a domain, although one initial .onmicrosoft.com domain is permanently attached to it at creation time.

Three concepts sit at the top of the Microsoft 365 hierarchy:

  • Tenant — the org boundary; where billing, data residency, and admin relationships live
  • Microsoft Entra ID directory — the identity backbone (formerly Azure Active Directory); every tenant has exactly one Entra ID directory, and one Entra ID directory can back multiple Microsoft cloud subscriptions across M365, Azure, and Dynamics 365
  • Subscriptions — the billed SKUs (e.g., Microsoft 365 E5, Business Premium) that license users and unlock workloads

Think of the tenant as the building, Entra ID as the ID badge system at the door, and subscriptions as the floor-by-floor leases that grant access to specific services like Exchange Online, SharePoint, or Teams.

Planning Decisions Before You Create a Tenant

Several decisions are effectively permanent. Get them right up front.

| Decision | Why it matters | Permanent? | ||---|---| | Initial .onmicrosoft.com domain name | Stamped into every default URL, SharePoint tenant URL (<name>.sharepoint.com), and OneDrive URLs; appears in sender addresses when no custom domain is configured | Yes — cannot be renamed | | Tenant primary region / datacenter geo | Determines where provisioned Exchange Online mailboxes, SharePoint, and Teams data initially store at rest | Effectively yes — migration between geos is limited and often requires a support-led move | | Billing country/region | Drives available SKUs, pricing currency, tax, and data residency options | Yes | | Subscription plan | Determines which workloads and admin centers appear | No — can add/remove plans anytime | | Global admin identity | The first account; should be a break-glass, MFA-enforced, audited account | No — can add/remove Global admins |

For the initial .onmicrosoft.com name: pick something stable and org-identifying, e.g., contoso.onmicrosoft.com. You cannot change it later. If you rebrand, you can add a new custom domain and make it default, but the .onmicrosoft.com name remains stamped onto SharePoint/OneDrive URLs and several internal identifiers.

For region: Microsoft 365 honors the country/region you select during sign-up to choose a default datacenter geo. Some regions (EU, UK, India, Australia, Japan, Canada, and others) have dedicated geos; customers in the United States default to the North America geo. You can review actual data-at-rest location later in the Microsoft 365 admin center under Settings → Org settings → Organization profile → Data location.

How a Tenant Is Created

The exam expects you to know the three valid creation paths:

  1. Self-service sign-up on the Microsoft 365 product site — A business owner picks a plan at microsoft.com/microsoft-365, enters payment and an initial domain, and a tenant is provisioned automatically. The account that signs up becomes the first Global Administrator.
  2. Microsoft Entra admin center (creating an additional tenant) — An existing administrator creates a second tenant from Identity → Overview → Manage tenants → Create in the Entra admin center (the same action is available from Microsoft Entra ID in the Azure portal). Note the trap: you cannot create a tenant from the Microsoft 365 admin center — Settings → Org settings only configures the tenant you are already signed in to.
  3. Partner Center / Cloud Solution Provider (CSP) — A Microsoft partner provisions a tenant on behalf of a customer, often with delegated administration privileges. This is the standard path for managed-service providers.

Provisioning typically completes within minutes for small business plans and a few hours for enterprise plans with custom domains and many service plans.

The Global Administrator Role

Whichever path you use, the first user account becomes a Global Administrator — the most powerful role in Entra ID and Microsoft 365. A Global Admin can:

  • Create and delete other admins and assign any role
  • Manage subscriptions and billing
  • Read and reset any user's password
  • Consent to applications on behalf of the org
  • Access every workload's admin center

Because of this power, Microsoft recommends keeping Global Admins to five or fewer (Microsoft's documented best practice: limit Global Administrators to a small, audited set), requiring MFA on every Global Admin, and creating a dedicated, cloud-only break-glass Global Admin account for emergency access.

Single-Tenant vs Multi-Tenant

Most organizations run one tenant for their entire Microsoft 365 footprint. Multiple tenants are introduced when one of the following applies:

  • Legal or data sovereignty — A subsidiary in a regulated region must keep data in a specific geo with separate admin jurisdiction
  • Mergers, acquisitions, and divestitures — Acquired companies often have their own tenants that must be integrated or migrated
  • Partner/customer separation — A consulting or hosting firm keeps each client's environment in its own tenant
  • Dev/test isolation — A non-production tenant used for safe admin experimentation

Multi-tenant designs add cost and complexity: identities, custom domains, and Conditional Access policies do not cross tenant boundaries natively. Cross-tenant collaboration typically uses B2B collaboration (guest users in Entra ID) or cross-tenant synchronization rather than domain federation across tenants.

Tenant-Level vs Workload-Level Administration

Microsoft 365 administration is layered:

  • Tenant-level admin centers — Microsoft 365 admin center, Microsoft Entra admin center, Purview compliance portal — control org-wide settings, identity, billing, and compliance
  • Workload-level admin centers — Exchange admin center, SharePoint admin center, Teams admin center, Intune (Endpoint Manager), Defender portal — control settings scoped to a single service

A Global Admin can enter any workload admin center, but day-to-day administration is typically delegated to scoped roles: Exchange Administrator, SharePoint Administrator, Teams Administrator, Intune Administrator, Security Administrator, and Compliance Administrator. These roles follow the principle of least privilege and are assigned in Entra ID or via the M365 admin center's role management page.

Key Takeaways

  • The tenant is the org boundary; Entra ID is its identity backbone; subscriptions license the workloads
  • The initial .onmicrosoft.com domain name and tenant region are permanent — choose carefully
  • The first account created during sign-up becomes a Global Administrator; keep the count low and enforce MFA
  • Most orgs need a single tenant; multi-tenant designs exist for sovereignty, M&A, and partner scenarios
  • Tenant-level admin centers handle org-wide settings; workload admin centers handle service-specific configuration
Loading diagram...
Microsoft 365 Tenant → Entra ID → Subscriptions → Workloads
Test Your Knowledge

You are creating a new Microsoft 365 tenant for Contoso Ltd. Which two decisions are effectively permanent and cannot be changed later without creating a new tenant?

A
B
C
D
Test Your Knowledge

What is the relationship between a Microsoft 365 tenant, a Microsoft Entra ID directory, and a Microsoft 365 subscription?

A
B
C
D
Test Your Knowledge

A company signs up for Microsoft 365 Business Premium at microsoft365.com using the owner's personal email. What happens to that account after provisioning completes?

A
B
C
D