What do MTO, GDAP, URBAC and Azure Lighthouse mean for a service provider?

Reviewed by ContraForce team ยท Updated 2026-09-04

> Eight terms decide how a service provider reaches customer data on the Microsoft stack, and several are routinely confused with each other. Each definition below states what the mechanism is, which data plane it reaches, and where it stops, with the primary source linked.

Last verified: 2026-09-04. Definitions are quoted from Microsoft documentation and linked at the foot of the page.

What is Defender multitenant management (MTO)?

Defender multitenant management is the Microsoft Defender portal experience for operating several tenants from one console. It carries a multitenant incident queue, a device inventory with a Tenant name column, cross-tenant advanced hunting, and content distribution. It is available to GCC, GCC High, DoD and Commercial customers, and it does not support Microsoft Defender for Business tenants. Access requires GDAP or Microsoft Entra B2B for Defender data.

What is GDAP?

Granular Delegated Admin Privileges is the Microsoft delegated access model for CSP partners. It grants time-bound, scoped Microsoft Entra directory roles in a customer tenant, replacing the older all-or-nothing delegated administration. GDAP reaches Defender data. Microsoft states it is not supported for Microsoft Sentinel data and provides access to Defender data only, describing that as the position "at this time".

What is Unified RBAC (URBAC)?

Microsoft Defender Unified RBAC is the single access model for Defender and Sentinel portal experiences, replacing the separate permission systems each workload carried. Under Message Center notice MC1457836, tenants are auto-enabled starting late September 2026 and completing by December 2026, with a 30-day notification before activation, existing roles imported at activation, and opt-out available afterwards rather than before.

What is Azure Lighthouse?

Azure Lighthouse is delegated resource management for Azure. It lets a provider manage customer Azure resources, including Microsoft Sentinel workspaces, from its own tenant without signing in to the customer's. It is the mechanism cross-tenant Sentinel querying depends on, including inside the Defender portal. Delegation across a national cloud and the Azure public cloud, or across two national clouds, is not supported.

What are tenant governance relationships?

A governance relationship establishes a directional connection between two Microsoft Entra tenants. Microsoft announced tenant governance relationships as public preview in March 2026, and documents that the cross-tenant delegated administration in them uses GDAP technology. Being preview and being built on GDAP both matter: it inherits GDAP's boundaries rather than escaping them, and it carries no general availability commitment.

What is cross-tenant synchronization?

Cross-tenant synchronization automatically provisions users from one Microsoft Entra tenant into another. Microsoft states that for privacy reasons it is intended for use within an organization, and that it can be used across organizations though doing so introduces additional considerations. It is a multi-tenant-organization feature rather than a service-provider delegation model, and the 100-tenant multitenant organization default does not apply to cross-tenant synchronization by itself.

What is a content distribution profile?

A distribution profile defines a source tenant, a set of target tenants, and the content copied between them, and it is how detection content reaches many customers from one place in Defender multitenant management. Automation rules that trigger a playbook cannot be distributed, and playbooks are not a distributable type. No API, Graph resource or PowerShell cmdlet is documented for creating, editing or syncing a profile.

What is delegated access, and how do the models differ?

Delegated access is the general term for a provider operating in a customer's environment without holding a permanent account there. The models are not interchangeable, because each reaches a different plane.

ModelPlaneReaches
GDAPMicrosoft Entra directory rolesDefender data, not Sentinel data
Microsoft Entra B2BGuest identity in the customer directorySentinel data in the Defender portal
Azure LighthouseAzure resource managementCross-tenant Sentinel queries
Tenant governanceBuilt on GDAPPublic preview
A Microsoft Entra account can belong to a maximum of 500 tenants counted as member or guest, which is the ceiling B2B-based delegation eventually meets.

How do these compose in practice?

Most providers end up running GDAP for Defender and Microsoft 365 administration, Microsoft Entra B2B for Sentinel data access, and Azure Lighthouse for cross-tenant Sentinel querying, maintained per customer. Three models, three sets of per-tenant configuration, and a platform change to any one of them arriving once per customer.

An operating layer with its own identity and role model changes what has to be maintained per tenant rather than what Microsoft supports. ContraForce holds analysts, roles and approval gates in the platform and connects to each customer through a scoped Microsoft Entra enterprise application consented per module, so analyst permissions are modelled once rather than rebuilt inside every tenant.

Sources

Verified on the date shown. Microsoft renames and repackages these mechanisms regularly; confirm against the linked source before relying on any definition here.

Continue the evaluation

Sources and review method

Product capabilities were reviewed against the page-specific primary sources below on 2026-09-04. Performance claims require the population and limitations stated in the linked methodology.

Related microsoft resources