One Microsoft 365 Tenant or Many? Holding Companies, Franchises, PE Roll-Ups and Shared-Services Groups
Holding companies, franchisors, private-equity platforms and shared-services groups all ask this in the first month, and it has no default answer. One Microsoft 365 tenant gives you one directory, one Teams, one admin plane and one bill. Several tenants give each entity its own boundary and its own bill, at the cost of collaboration friction and duplicated administration. This article covers what a single tenant cannot separate, what multi-tenant organizations bridge, the domain and billing rules that often decide it, when a separate tenant is forced, and the cost of changing your mind.
The single-tenant default, and what it is good at
A tenant is a Microsoft Entra directory plus the Microsoft 365 services attached to it. Everything inside it shares an address book, a Teams instance, a SharePoint pool, one set of Purview policies, one audit log, one Copilot boundary and one set of global administrators. For entities that work together, that sharing is the point.
It is also the lowest-cost structure to run: one Conditional Access design, one Intune estate, one security baseline. Licensing is per user regardless of entity, so an employee who moves between subsidiaries keeps the same license. The one structural licensing catch is the Business-plan ceiling: the 300-license limit counts every entity in the tenant, so a group of five 80-person companies has already passed it.
Our starting recommendation for a group under common ownership, with shared leadership and HR and a plausible future of staying together, is one tenant, with the separations below applied inside it.
Where one tenant strains: branding, billing, admin separation and compliance
The complaints a year after a single-tenant decision fall into four groups.
Branding. Each entity can have its own verified domain, email addresses, Teams and SharePoint sites, and Exchange address book policies can carve up the global address list so entity A does not browse entity B's staff. What cannot be separated is the tenant itself: one organization name, one default sign-in branding, one onmicrosoft.com name in SharePoint URLs.
Billing. A tenant can hold many subscriptions, and as a CSP we place each entity's licenses on its own subscription and invoice each entity separately from one tenant. It fails when an entity insists on its own Microsoft relationship or partner.
Admin separation. Entra administrative units scope roles such as user or helpdesk administrator to one entity's users, groups and devices; Microsoft's documentation (ms.date 29 October 2024) states that each administrative-unit administrator needs an Entra ID P1 license. They do not scope global administrator, Exchange or SharePoint service administration, or the Purview portal.
Compliance boundaries. Retention, DLP and sensitivity-label policies can be scoped to groups and locations, but the unified audit log, eDiscovery cases and legal holds see the whole tenant, and an insurer's or regulator's questionnaire is answered for the tenant, not the entity. A regulated subsidiary inside a tenant of unregulated siblings drags the whole tenant into its control set.
Multi-tenant organizations: what Microsoft built for exactly this
Microsoft's multi-tenant organization (MTO) feature makes several tenants feel like one company. Microsoft's Entra documentation (ms.date 18 March 2026) describes an MTO as a boundary around the tenants your organization owns, supports up to 100 active tenants including the owner, and requires Microsoft Entra ID P1 licenses in every tenant. Microsoft's limitations page of the same date adds the rule that matters for regulated groups: all tenants must be in the same cloud, and cross-cloud MTOs are not supported.
The engine under an MTO is cross-tenant synchronization. Microsoft's documentation (ms.date 29 May 2026) describes it as automating the creation, update and deletion of B2B collaboration users and groups across tenants, one direction at a time, with Entra ID P1 required in the source tenant for each synchronized user. Synchronized people appear as members rather than guests. It mirrors users; it does not migrate them.
Teams shared channels use B2B direct connect, a mutual trust set in each tenant's cross-tenant access settings, so a franchisee and the franchisor can share a channel without either creating accounts for the other; our guest and external users article covers the licensing. What an MTO does not give you: one SharePoint, one Copilot boundary, one Intune, one audit log or one bill. Each tenant keeps its own.
Domains, shared mailboxes and billing across entities
Three rules do most of the deciding.
One domain, one tenant. Microsoft's Entra documentation (ms.date 7 April 2026) states that Microsoft will not allow a domain name to be verified with more than one Entra tenant, while a subdomain (europe.contoso.com) can be verified in a different tenant from its parent. If two entities share a brand domain and want separate tenants, one of them lives on a subdomain or another domain, and mail routing between them is permanent infrastructure.
Shared mailboxes and groups do not cross tenants. Inside one tenant an entity can own shared mailboxes, distribution lists and Microsoft 365 Groups that other entities use. Between tenants, the same needs become B2B guests, mail contacts and cross-tenant sync.
Billing follows the tenant, then the subscription. Under CSP each tenant is its own billing relationship and can have its own partner. Inside one tenant, subscriptions are the unit we can invoice separately. Azure subscriptions attach to a tenant too, and moving them later is its own project; our Azure Tenant-to-Tenant Resource Migration service is quoted per estate for that reason.
When a separate tenant is forced
Some situations end the debate.
- Government cloud. An entity that needs GCC or GCC High cannot share a commercial tenant, and Microsoft's MTO limitations page rules out cross-cloud MTOs. The defense contractor in the group gets its own tenant; the GCC decision guide covers which one.
- Data residency. A tenant has one primary provisioned geography. Microsoft's Multi-Geo documentation (ms.date 26 September 2025) describes an add-on that hosts licensed users' Exchange, SharePoint, OneDrive and Teams data in satellite geographies within one tenant, sold with E and F plans, including through CSP, with at least one in twenty of eligible users licensed. It does not satisfy a regulator who wants a separate legal boundary.
- An entity that will be sold. If a business will be divested within a few years, its own tenant from day one avoids the separation project in our carve-out article. Private-equity platforms that buy to sell should default to one tenant per portfolio company for this reason alone, with an MTO on top.
- Independent ownership. Franchisees and association members own their businesses. One tenant would make the franchisor their identity provider, data controller and global administrator. The usual answer is a franchisor tenant, a tenant per franchisee, shared channels for the operating relationship, and a standard build deployed to each.
The exit cost either way
Consolidating tenants and splitting them are both tenant-to-tenant migrations, priced by what has to move.
Tenant-to-tenant migration after a merger lays out the phases; the fixed-price building blocks are Entra ID Tenant-to-Tenant Basic Transition ($1,300, five days), Microsoft 365 Tenant-to-Tenant Cutover Email Migration ($35 per mailbox plus a $3,500 tenant fee, five weeks) and SharePoint Online Tenant-to-Tenant Migration ($100 per site plus a $2,500 tenant fee, four weeks), with the whole program scoped as Mergers and Acquisitions Tenant Consolidation (quoted, eight weeks). The MX spooler article covers the domain cutover, the one unavoidable outage.
Splitting is the same work with an extra problem: nothing was ever labeled by entity. Shared sites, mixed Teams, distribution lists and annual-term licenses must be untangled first, which is why the Divestiture and Carve-Out Tenant Separation service starts from $7,500 per project over eight weeks.
Every year an entity spends sharing a tenant adds to the cost of separating it, and every year apart adds to the cost of merging.
Frequently asked questions
Can two companies share one Microsoft 365 tenant?
Yes, if they are under common control and accept one set of global administrators, one audit log and one compliance boundary. Independent companies usually should not share a tenant.
Can the same domain be in two Microsoft 365 tenants?
No. Microsoft's Entra documentation states that a domain name cannot be verified in more than one tenant. A subdomain can be verified in a different tenant from its parent.
What is a multi-tenant organization in Microsoft 365?
A Microsoft Entra feature that defines a boundary around the tenants your organization owns, up to 100 tenants, and synchronizes people between them as members rather than guests. It requires Entra ID P1 in every tenant, and all tenants must be in the same cloud.
Does a franchise need separate tenants?
Usually yes for the franchisees, because they are independent businesses with their own data and legal exposure. The typical design is a franchisor tenant, one per franchisee, shared channels between them, and a standard configuration.
Sources
- Microsoft Learn, "What is a multitenant organization in Microsoft Entra ID?" (ms.date 18 March 2026; opened via the MicrosoftDocs GitHub source)
- Microsoft Learn, "Limitations in multitenant organizations" (ms.date 18 March 2026; opened via the MicrosoftDocs GitHub source; same-cloud rule)
- Microsoft Learn, "What is cross-tenant synchronization?" (ms.date 29 May 2026; opened via the MicrosoftDocs GitHub source)
- Microsoft Learn, "Add and verify custom domain names" (ms.date 7 April 2026; opened via the MicrosoftDocs GitHub source)
- Microsoft Learn, "Administrative units in Microsoft Entra ID" (ms.date 29 October 2024; opened via the MicrosoftDocs GitHub source)
- Microsoft Learn, "Microsoft 365 Multi-Geo" (ms.date 26 September 2025; opened via the MicrosoftDocs GitHub source)
- IT Partner blog: microsoft-365-business-300-license-limit; guest-and-external-users-microsoft-365-who-needs-a-license; gcc-vs-gcc-high-vs-commercial-decision-guide; tenant-to-tenant-migration-after-merger-microsoft-365-azure-guide
- IT Partner engineering notes, September 2026
| Situation | Structure we recommend | What makes it work | Exit cost if you change your mind |
|---|---|---|---|
| Holding company, shared leadership and HR, entities kept long term | One tenant | Domains per entity, address book policies, administrative units, one subscription per entity for billing | Carve-out from $7,500 plus per-mailbox and per-site migration |
| PE platform that buys to sell | One tenant per portfolio company, MTO on top | Cross-tenant sync, shared channels, standard build per tenant | Consolidation quoted per program if the exit plan changes |
| Franchisor with independent franchisees | Franchisor tenant plus one per franchisee | Shared channels via B2B direct connect, standard configuration | None expected; a franchisee leaves with its tenant |
| Group with one defense or GCC entity | Separate GCC or GCC High tenant for that entity | Cross-cloud MTO is not supported, so plan for guests and mail contacts | GCC High migration is its own project |
Key takeaways
- One tenant is the lowest-cost structure to run and the right default for a group under common control that intends to stay together; several tenants are the right default for independent owners and for businesses that will be sold.
- A domain can be verified in only one tenant (subdomains excepted), so brand-sharing groups lean toward one tenant and separately branded groups toward several.
- A multi-tenant organization bridges up to 100 tenants in one cloud with Entra ID P1 in each, syncing people as members and improving Teams across tenants, but it does not merge SharePoint, Intune, audit logs, Copilot boundaries or bills.
- Inside one tenant, administrative units, address book policies and one subscription per entity give most of the separation a holding company needs; global admin, eDiscovery and the audit log stay tenant-wide.
- Both directions are migrations: consolidation starts at $1,300 for identity and $35 per mailbox plus a $3,500 tenant fee; a carve-out starts from $7,500.
We map your entities to tenants and put a number on each path before you commit. The building blocks are Entra ID Tenant-to-Tenant Basic Transition ($1,300, five days), Microsoft 365 Tenant-to-Tenant Cutover Email Migration ($35 per mailbox plus a $3,500 tenant fee, five weeks) and Azure Tenant-to-Tenant Resource Migration (quoted per estate, two weeks); a full consolidation is scoped as Mergers and Acquisitions Tenant Consolidation and a separation as Divestiture and Carve-Out Tenant Separation (from $7,500 per project, eight weeks). Licenses, including Microsoft Entra ID P1 for a multi-tenant organization, are sold at Microsoft's list price. Book a call with your org chart.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.