1Security

Connecting Tenants

Connect additional Microsoft 365 tenants and troubleshoot connection issues.

You can connect multiple Microsoft 365 tenants to a single 1Security account - useful for MSPs, holding companies, and organisations with several tenants.

Adding a tenant

Open the tenant menu

Click the tenant switcher in the top-left of the dashboard, then Add tenant.

Authenticate

A new tab opens to Microsoft's OAuth consent flow. Sign in with a global admin of the tenant you want to add.

Grant permissions

Approve the same permissions you granted during the initial install.

Wait for the initial scan

The new tenant appears in your switcher immediately, but full data takes the duration of the initial scan to populate.

One dashboard for several tenants (combining)

By default every tenant you add is a separate workspace you switch between. If you operate several tenants together - a holding company, a merger, one customer with several Microsoft 365 tenants - you can combine them into a tenant group and read them as one dashboard.

How to combine

When you open Add tenant, eligible targets appear below the main button as Combine with <tenant or group> - one entry per standalone tenant and one per existing group. A target is eligible when it is a non-demo tenant of your organization that you administer. Pick the target, complete the same Microsoft consent flow, and the new tenant joins the target's group.

What you get: the "All tenants" scope

The tenant switcher gains a group entry (named after your organization, with an All tenants badge) next to the individual members. In group scope:

  • Lists, counts, filters, search, and graphs cover every member, and tables gain a Tenant column so identically named rows stay tellable apart.
  • Actions on specific rows (remediation, assignments, policy edits) work as usual - each row is handled in the tenant that owns it.
  • A few surfaces stay single-tenant by design and ask you to switch to a member: tenant-wide settings, the compliance evidence pack (one dated document per tenant), and creating an API key (a key is always bound to one member - the create dialog asks which; the keys table lists every member's keys).

Group scope requires you to be an unrestricted admin on every member. An account missing admin on one member signs in to a single tenant instead.

What stays separate

Combining changes how you read the tenants, not what they are:

  • Each member keeps its own Microsoft consent - combining never extends a permission grant from one tenant to another.
  • Each member keeps its own scans, scan status, licensing, and plan.
  • Members of a group share underlying infrastructure by your explicit choice at connect time; every query stays scoped to its tenant (see Data handling).

Removing a member from your organization also removes it from its group; the remaining members keep working as a smaller group. There is no self-service way to split a combined tenant back onto separate infrastructure - combine tenants you intend to operate together.

Troubleshooting

Tenant permissions

1Security requests read-only permissions by default. Write permissions (used by automations) are opt-in per module.

Each tenant you add grants the same permissions as the first one, and each is consented separately - connecting a second tenant never extends the first tenant's grant.

The full list of permissions per module, the licenses each tenant needs, and the admin roles involved are in Requirements.

On this page