Azure客户身份是否需置于自有租户?客户账户管理的租户选择咨询
Great question—this is a common dilemma when managing customer identities in Azure, and the answer depends entirely on your service model, customer needs, and compliance requirements. Let’s break it down step by step:
Should Azure customer identities be deployed in your own tenant?
Short answer: It depends, but it’s not a one-size-fits-all rule. Your own tenant works if you’re fully managing the customer’s resources and they don’t need independent identity control. But if the customer requires autonomy or you need strict isolation, a separate tenant is often better.
Migrate to your regular tenant vs. dedicated tenant with B2B?
Let’s compare the two options based on real-world use cases:
Option 1: Migrate to your regular tenant (single-tenant model)
This makes sense if:
- You’re providing full end-to-end managed services, and the customer has no need to access or manage their own Azure resources directly
- You want centralized management for all resources (yours + customer’s)—think uniform security policies, monitoring, and license management
- The customer is part of your broader organization (like a subsidiary) or has a tightly integrated partnership where cross-resource access is needed
Key considerations:
- Enforce strict permission boundaries: Use Azure RBAC (Role-Based Access Control) to create separate role assignments for customer-specific resources. Never let internal users access customer resources unless explicitly authorized.
- Compliance checks: If the customer operates in a regulated industry (e.g., healthcare, finance), ensure your tenant’s policies meet their compliance standards—you might need to set up separate resource groups with locked-down policies for each customer.
Option 2: Migrate to a dedicated tenant with Azure AD B2B
This is the right call if:
- The customer needs to retain some level of control over their identity and resources (e.g., adding their own internal users, viewing audit logs)
- Compliance or data sovereignty rules require strict tenant-level isolation (e.g., customer data can’t coexist with your internal data in the same tenant)
- You plan to scale this service to multiple customers—dedicated tenants let you manage each customer’s environment independently without cross-contamination
Key considerations:
- Simplify B2B collaboration: Set up Azure AD B2B invitations to grant your team secure access to the customer’s dedicated tenant. Use PIM (Privileged Identity Management) to enforce just-in-time access for your admins, reducing security risks.
- Manage overhead: Multiple tenants mean slightly more administrative work, but tools like Azure AD Tenant Management can help automate tasks like policy deployment and license tracking.
- Clarify billing: Make sure both you and the customer agree on who covers the dedicated tenant’s license costs—this is often part of your service agreement.
Final Recommendation
There’s no "best" choice—align your decision with how you deliver services and what your customer expects. If you’re running a fully managed service where the customer is hands-off, a single tenant is efficient. If autonomy, isolation, or scalability are priorities, go with a dedicated tenant + B2B.
内容的提问来源于stack exchange,提问作者ruedi

