Managing Tenants & Multi-Directory Governance

PAM-Pro is engineered from the ground up for multi-tenant governance. Whether you are managing multiple enterprise business units, regional Entra ID directories, or functioning as an MSSP managing distinct client organizations, PAM-Pro maintains strict cryptographic and operational isolation across every tenant boundary.

Multi-Tenant Architecture

PAM-Pro decouples the administrative governance plane from individual client directories:

  • Dedicated Azure Key Vaults & WORM Storage: Each onboarded tenant maintains its own isolated credential vault and tamper-proof audit container, protected by a unique Tenant Root Key (TRK).
  • Cross-Tenant Microsoft Graph Integration: PAM-Pro interacts with target Entra ID directories using certificate-based Workload Identity Federation (WIF) or multi-tenant Enterprise Applications, requiring no standing client secrets.
  • Tenant Context Switching: Administrators can switch organizational contexts instantly via the top-right tenant dropdown, scoping accounts, discovery groups, audit logs, and compliance scorecards to that specific boundary.

The Tenant Management Console

To inspect and manage configured tenant environments, navigate to Settings › System and locate the Tenants panel. This table displays:

  • Tenant Name & ID: The display alias and unique Microsoft Entra Directory GUID.
  • Primary Contact: Administrative contact email used for compliance reports and critical notifications.
  • Onboarding Status: Indicates whether administrative consent and directory role assignments are complete.
  • Live Verification Status: Real-time confirmation of Graph API connectivity and permissions.
The Connected Tenants panel listing two Entra ID directories with their display names and tenant GUIDs, the administrator that added each, and per-tenant Setup, Verify and Remove actions.
The tenant console. Each row carries the directory GUID the tenant is bound to, and its own verification control.

Live Tenant Verification

Introduced in Version 3.13.2, PAM-Pro features automated Live Tenant Verification (POST /api/tenants/:tenantId/verify). Rather than relying on static checkboxes or cached assumptions, administrators can click Verify on any tenant row to test live readiness in real time:

  1. Graph API Reachability: Requests an application token and checks /organization access against the target Entra tenant. This confirms administrative consent was granted and the Service Principal exists.
  2. Service Principal Resolution: Resolves the target tenant's Service Principal Object ID required for role assignments.
  3. Directory Role Verification: Inspects active directory role assignments to confirm the Service Principal holds both required administrative roles:
    • Global Reader: Required for account discovery, hybrid attribute inspection, and directory synchronization reads.
    • Privileged Authentication Administrator: Required to rotate credentials and execute emergency password resets for privileged accounts.

Zero-Cache Integrity: Verification results are evaluated live and are never persisted as a static green checkmark. If an administrator revokes a directory role or consent in Entra ID, the next verification check immediately detects the gap.

De-Provisioning & Data Retention

When offboarding an organizational boundary, select the tenant and click Terminate Governance. PAM-Pro securely purges the cached configuration and removes active discovery schedules. To satisfy legal compliance mandates, existing Write-Once, Read-Many (WORM) audit blobs remain locked within the tenant's Azure storage account according to their defined retention policy.

© 2026 Huntoso LLC. All rights reserved.