What do MTO, GDAP, URBAC and Azure Lighthouse mean for a service provider?
Reviewed by ContraForce team ยท Updated 2026-09-04
> Eight terms decide how a service provider reaches customer data on the Microsoft stack, and several are routinely confused with each other. Each definition below states what the mechanism is, which data plane it reaches, and where it stops, with the primary source linked.
Last verified: 2026-09-04. Definitions are quoted from Microsoft documentation and linked at the foot of the page.What is Defender multitenant management (MTO)?
Defender multitenant management is the Microsoft Defender portal experience for operating several tenants from one console. It carries a multitenant incident queue, a device inventory with a Tenant name column, cross-tenant advanced hunting, and content distribution. It is available to GCC, GCC High, DoD and Commercial customers, and it does not support Microsoft Defender for Business tenants. Access requires GDAP or Microsoft Entra B2B for Defender data.
What is GDAP?
Granular Delegated Admin Privileges is the Microsoft delegated access model for CSP partners. It grants time-bound, scoped Microsoft Entra directory roles in a customer tenant, replacing the older all-or-nothing delegated administration. GDAP reaches Defender data. Microsoft states it is not supported for Microsoft Sentinel data and provides access to Defender data only, describing that as the position "at this time".
What is Unified RBAC (URBAC)?
Microsoft Defender Unified RBAC is the single access model for Defender and Sentinel portal experiences, replacing the separate permission systems each workload carried. Under Message Center notice MC1457836, tenants are auto-enabled starting late September 2026 and completing by December 2026, with a 30-day notification before activation, existing roles imported at activation, and opt-out available afterwards rather than before.
What is Azure Lighthouse?
Azure Lighthouse is delegated resource management for Azure. It lets a provider manage customer Azure resources, including Microsoft Sentinel workspaces, from its own tenant without signing in to the customer's. It is the mechanism cross-tenant Sentinel querying depends on, including inside the Defender portal. Delegation across a national cloud and the Azure public cloud, or across two national clouds, is not supported.
What are tenant governance relationships?
A governance relationship establishes a directional connection between two Microsoft Entra tenants. Microsoft announced tenant governance relationships as public preview in March 2026, and documents that the cross-tenant delegated administration in them uses GDAP technology. Being preview and being built on GDAP both matter: it inherits GDAP's boundaries rather than escaping them, and it carries no general availability commitment.
What is cross-tenant synchronization?
Cross-tenant synchronization automatically provisions users from one Microsoft Entra tenant into another. Microsoft states that for privacy reasons it is intended for use within an organization, and that it can be used across organizations though doing so introduces additional considerations. It is a multi-tenant-organization feature rather than a service-provider delegation model, and the 100-tenant multitenant organization default does not apply to cross-tenant synchronization by itself.
What is a content distribution profile?
A distribution profile defines a source tenant, a set of target tenants, and the content copied between them, and it is how detection content reaches many customers from one place in Defender multitenant management. Automation rules that trigger a playbook cannot be distributed, and playbooks are not a distributable type. No API, Graph resource or PowerShell cmdlet is documented for creating, editing or syncing a profile.
What is delegated access, and how do the models differ?
Delegated access is the general term for a provider operating in a customer's environment without holding a permanent account there. The models are not interchangeable, because each reaches a different plane.
| Model | Plane | Reaches |
|---|---|---|
| GDAP | Microsoft Entra directory roles | Defender data, not Sentinel data |
| Microsoft Entra B2B | Guest identity in the customer directory | Sentinel data in the Defender portal |
| Azure Lighthouse | Azure resource management | Cross-tenant Sentinel queries |
| Tenant governance | Built on GDAP | Public preview |
How do these compose in practice?
Most providers end up running GDAP for Defender and Microsoft 365 administration, Microsoft Entra B2B for Sentinel data access, and Azure Lighthouse for cross-tenant Sentinel querying, maintained per customer. Three models, three sets of per-tenant configuration, and a platform change to any one of them arriving once per customer.
An operating layer with its own identity and role model changes what has to be maintained per tenant rather than what Microsoft supports. ContraForce holds analysts, roles and approval gates in the platform and connects to each customer through a scoped Microsoft Entra enterprise application consented per module, so analyst permissions are modelled once rather than rebuilt inside every tenant.
Sources
- Microsoft Defender multitenant management overview
- Microsoft Defender multitenant management requirements
- Granular delegated admin privileges
- What is Azure Lighthouse?
- Configure cross-tenant synchronization
- Microsoft Entra service limits and restrictions
- Manage multitenant content distribution
Continue the evaluation
Sources and review method
Product capabilities were reviewed against the page-specific primary sources below on 2026-09-04. Performance claims require the population and limitations stated in the linked methodology.
- Microsoft Defender multitenant management requirements (verified 2026-09-04)
- Automation in Microsoft Sentinel (verified 2026-09-04)
Related microsoft resources
- Can PIM be activated once across multiple tenants?, The supported partner pattern for just-in-time elevation, and why one activation cannot span customers.
- Why a connected tenant does not appear for content distribution, The one cause Microsoft names, the eligibility rules that explain the rest, and what has no published diagnostic.