Enterprise Identity & Access Management Platform  ·  View 03 of 27  ·  Context and scope

Identity Estate & Tenancy Model

Which classes of identity exist, and which directory each one lives in.

Editable source SVG draw.io All views
Corporate Entra tenant — contoso.com
Corporate Entra tenant — contoso.com
Workforce identities — HR-sourced, never hand-created
Workforce identities — HR-sourced, never hand-created
Employees
45,000
Employees...
Contractors
8,000 · expiry mandatory
Contractors...
Administrators
190 · eligible only
Administrators...
Break-glass
2 · permanent Global Admin
Break-glass...
Guest identities — governed by cross-tenant access settings
Guest identities — governed by cross-tenant access settings
B2B guests
6,500 · 90-day review
B2B guests...
Partner tenants
34 · inbound trust
Partner tenants...
Trusted MFA claims
cross-tenant inbound
Trusted MFA claims...
Workload identities — no human owner, always an app owner
Workload identities — no human owner, always an app owner
Managed identities
2,600 · user + system
Managed identities...
Federated credentials
640 · OIDC subjects
Federated credentials...
App registrations
900 · roles & scopes
App registrations...
Secret-bearing SPs
170 · legacy, decreasing
Secret-bearing SPs...
Entra External ID tenant — customers.contoso.com
Entra External ID tenant — customers.contoso.com
Customer identities
Customer identities
Customer accounts
1.2M
Customer accounts...
Social & partner IdPs
Google · Apple · SAML
Social & partner IdPs...
Customer-facing applications
Customer-facing applications
Customer web & mobile
user flows
Customer web & mobile...
Customer APIs
tenant-scoped tokens
Customer APIs...
Workday HCM
system of record
Workday HCM...
On-prem AD DS
Kerberos apps
On-prem AD DS...
provisioning, hourly
provisioning, hourly
Cloud Sync
Cloud Sync
invited, sponsored
invited, sponsored
federated sign-up
federated sign-up
migration target
migration target
Identity Estate & Tenancy Model
Identity Estate & Tenancy Model
Person or role
Person or role
Risk / gap
Risk / gap
External / third party
External / third party
Security / platform
Security / platform
Application we own
Application we own
Interface / broker
Interface / broker
batch
batch
synchronous
synchronous
failure / alternate
failure / alternate
Two tenants, one platform. The line between them is a tenant boundary rather than a policy, so no customer identity can ever be evaluated against a corporate administrative role.
Two tenants, one platform. The line between them is a tenant boundary rather than a policy, so no customer identity can ever be evaluated against a corporate administrative role.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display

The tenant decision

  • Two tenants: corporate and CIAM. The alternative — one tenant with customers as guests or B2C users — was rejected because the blast radius of a customer-facing misconfiguration would then include workforce administrative roles.
  • The cost is real and stated: two Conditional Access estates, two policy pipelines, and B2B configuration for partner staff who need corporate resources. That cost buys a boundary a reviewer can verify in one screen.
  • Workload identity is a first-class identity class, not an afterthought attached to applications. 3,400 workload identities outnumber administrators by eighteen to one, and they are governed with owners, reviews and expiry like any other principal.

Rules that hold everywhere

  • No human identity is created by hand. Employees and contractors arrive from Workday; a contractor without a sponsor and an expiry date cannot be created at all.
  • Every workload identity has an owning group, never an owning person, so an engineer leaving does not orphan a running integration.
  • Guests are reviewed every 90 days and inherit nothing by default: a guest gains access only through an access package with an explicit sponsor.

The visible debt

  • 170 service principals still hold client secrets because their target systems cannot federate. Tracked as a named burn-down with an owner per principal, not accepted as steady state.
  • Two permanent break-glass accounts. Reduced from six; two is the floor, because one is a single point of failure during an incident.
  • AD DS remains for Kerberos-dependent applications. Retiring it is a separate programme, and until then Cloud Sync is a dependency with its own failure mode (view 27).