IAMinerva
HomeBlogAbout
m3M365 NewscoMicrosoft CopilotteMicrosoft TeamsshSharePoint & OneDriveinIntune & SecurityexExchange & OutlookpoPower PlatformazAzure & Entra IDtuTutorials & GuidesevEvents & ConferencesseSecuritywiWindows
IAMinerva

Professional blog dedicated to the Microsoft 365 ecosystem.

Quick links

HomeBlogAboutNewsletter

Stay informed

Get the latest Microsoft 365 news delivered straight to your inbox.

© 2026 IAMinerva. All rights reserved.

Built withNext.js&Tailwind
Nouvelle interface utilisateur pour gérer les restrictions de tenant dans Entra ID
BlogAzure & Entra IDNew user interface to manage tenant restrictions in Entra ID
Azure & Entra ID#Entra ID#Azure#Security

New user interface to manage tenant restrictions in Entra ID

Microsoft simplifies the management of tenant restrictions for multi-tenant Entra ID applications with an intuitive graphical interface.

Houssem MAKHLOUF
January 12, 2026
3 min read

TL;DR par Minerva

généré par IA

Microsoft simplifies the management of tenant restrictions for multi-tenant Entra ID applications with an intuitive graphical interface.

Introduction

Microsoft has recently introduced a graphical user interface to simplify the management of tenant restrictions on multi-tenant Entra ID applications. This new feature allows administrators to control access to applications without relying exclusively on Graph API methods.

i

Context

This functionality follows the introduction of tenant restrictions for Entra ID integrated applications, which allow limiting access to multi-tenant applications to specific tenants.

Accessing the new interface

Configuring tenant restrictions is now accessible directly from the Entra ID administration portal. Here's how to proceed:

1

Navigation to app registrations

Access the Entra ID administration portal and navigate to Entra ID > App registrations.

2

Application selection

Choose the application object you want to configure from the list of registered applications.

3

Access to authentication settings

Navigate to the Authentication (Preview) page then switch to the Supported account types tab.

Tenant restriction configuration interface

Configuring tenant restrictions

By default, multi-tenant applications do not enforce any tenant restrictions. To enable this feature:

Enabling restrictions

Select the Allow only certain tenants (Preview) option. The system will immediately present an error message, as at least one tenant value must be provided.

!

Important prerequisite

An application cannot have an empty list of authorized tenants. At least one tenant must be specified when enabling restrictions.

Managing authorized tenants

Click the Manage authorized tenants button to open the configuration panel. This interface allows:

  • Addition of up to 20 different tenants
  • Referencing by tenant ID or by verified domain name
  • Support for .onmicrosoft.com domains by default
  • Search by verified custom domain

Authorized tenants management panel

Authorized tenants configuration

Finalization and saving

1

Validation of changes

Confirm the changes by clicking the Apply button. You will be redirected to the Supported account types tab with the updated list of authorized tenants.

2

Settings saving

Click the Save button to definitively validate the changes. An Application authentication update notification will confirm the successful operation.

Constraints and technical limitations

Configuration prerequisites

The list of authorized tenants can only be configured when the application audience is set to Multiple Entra ID tenants ("AzureADMultipleOrgs").

Ă—

Warning

Changing the supported account type to another value will automatically clear the list of authorized tenants. The interface will display a confirmation warning in this case.

Account type modification warning

Managing changes

To remove all tenant restrictions, you must select the Allow all tenants option rather than clearing the list.

Advantages of the new interface

This user interface brings several significant improvements:

  • Simplified management: No longer need to master Graph API calls
  • Intelligent search: Support for domain name search
  • Real-time validation: Automatic warnings and confirmations
  • Clear limit: Maximum of 20 tenants per application
✦

Practical tip

The domain search functionality uses the findTenantInformationByDomainName method from the Graph API in the background, providing a smooth user experience without technical exposure.

Conclusion

This new interface represents a positive evolution for managing multi-tenant Entra ID applications. It democratizes access to tenant restriction features by offering a graphical alternative to Graph API methods. Administrators can now effectively configure the security of their applications without deep technical expertise in API development.

Share:
HM

Houssem MAKHLOUF

Microsoft 365 enthusiast & IT professional.

Previous article

Microsoft Teams May 2025: AI News, Contact Center and Major Evolutions

Jan 8, 2026
Next article

Microsoft Launches High-Volume Email in General Availability: A Revolution for High-Volume Enterprises

Jan 15, 2026

Related articles

Réseau de données avec une loupe et graphiques informatiques.azure

Azure Copilot Observability Agent: Diagnosing Your Applications

Discover Azure Copilot Observability Agent: automatically diagnose application problems and reduce resolution time with Azure AI.

Jun 29, 20267 min
Cadenas stylisé avec des éléments graphiques abstraits et du texte sur la sécurité.securite

New Microsoft 365 Security Adoption Model

Discover the Microsoft 365 security adoption guide based on Zero Trust principles: modular approaches and modern strategies.

Jun 29, 20264 min
Exécution de scripts PowerShell pour auditer des applications AI et gérer leurs enregistrements.copilot

Audit and Manage AI Applications with PowerShell

Audit unauthorized AI applications in Entra ID with PowerShell and Microsoft Graph to strengthen control and security.

Jun 28, 20264 min