Tenant
Azure Entra directory / identity boundary.
class: AdministrativeBoundary derivation-only - no collection recipe
Realizing resources
This type has no collection recipe - it appears only as the endpoint of derived edges.
As edge target
Exposure sites
None.
Rules that touch Tenant 12
Cosmos DB account with firewall restricted to 0.0.0.0 (all Azure IPs) - accessible from any Azure-hosted workload but not the open internet.
azure
ExposedToTenantAn API connection referencing a resource in a different Entra tenant represents cross-tenant credential trust.
azure
CrossTenantTrustA managing-tenant ExternalPrincipal named in a resource-group-scoped Lighthouse authorization has CanAdminister over that resource group.
azure
CanAdministerA managing-tenant ExternalPrincipal named in a subscription-scoped Lighthouse authorization has CanEnterSubscription into the customer subscription.
azure
CanEnterSubscriptionA Microsoft Entra Global Administrator can call elevateAccess to gain User Access Administrator at root scope (/), controlling the root management group and thus every subscription in the tenant.
A guest/foreign-tenant principal granted a Managed HSM local role gains cross-tenant crypto access.
azure
CanEnterTenantA Private Link Service configured to accept connections from other tenants (via properties.autoApproval or explicit allowedSubscriptions from cross-tenant subscriptions) records a cross-tenant network trust. A PE from a different tenant connecting to this PLS extends network reachability and access across the tenant boundary.
azure
CrossTenantTrustAllow Azure services rule (startIp=endIp=0.0.0.0) exposes the SQL server to all Azure tenants and multi-tenant services - not public internet but broad cross-tenant exposure.
azure
ExposedToTenantA subscription associated/transferred to a different Entra tenant is a boundary-crossing trust (rare, privileged).
azure
CrossTenantTrust