Azure Tenant
A dedicated instance of Microsoft Entra ID representing a single organization, serving as the identity boundary that contains users, groups, and app registrations, with one or more Azure subscriptions trusting it for authentication.
Azure Tenant
A tenant is your organization's identity root — every user, group, and service principal that can authenticate into your Azure subscriptions lives inside exactly one tenant.
Why It Matters in Production
Hotstar's engineering org operates under a single Entra ID tenant, so an employee's offboarding immediately revokes their access across every subscription trusting that tenant — no per-subscription cleanup needed.
az account show --query tenantIdRememberA subscription can only trust one tenant at a time, though a tenant can have many subscriptions trusting it.
Frequently Asked Questions
How does an Azure Tenant relate to an Azure Subscription?
A tenant is the identity boundary — one Microsoft Entra ID instance holding your organization's users, groups, and app registrations. A subscription is the billing and resource-management boundary underneath it. One tenant commonly has multiple subscriptions (e.g., separate ones for dev, staging, and production), and all of them trust the same tenant for authentication, so a user account created once in the tenant can be granted access across any subscription that trusts it via RBAC.
What's a mistake companies make when a merger or acquisition is involved?
Assuming subscriptions can be freely moved between tenants like resource groups. Moving a subscription to a different tenant is a distinct, disruptive operation that resets all role assignments, service principals, and managed identities tied to that subscription, since those are tenant-scoped, not subscription-scoped. Teams that don't plan for this during an M&A integration find every automation pipeline and app registration broken post-move and have to rebuild identity configuration from scratch.