Last year, Microsoft came out with Azure Lighthouse, a service that allows a customer to delegate rights to another party to manage their resources. This service is aimed at service providers, but large companies with multiple Azure AD tenants can benefit from this too.
Previously, when managing multiple Azure Active Directory (AD) tenants, you would invite the accounts of your Azure AD into the customer’s Azure AD. For a few tenants, this is doable. However, it is a bit of a challenge with hundreds of tenants, multiplied by the number of accounts in the managing tenant.
The next step is having to make sure all the accounts in all tenant subscriptions have the correct rights. Obviously you will need some additional scripting magic to keep this all in sync, but for customers where you don’t have access to their Azure AD, this now becomes a manual process. Very tedious indeed!
Once that is all done, to manage each subscription requires that you switch to the context of that subscription— basically logging in again. Done managing customer A? Great, now switch to the next one, and so on.
Azure Delegated Resource Management is one of the key components of Azure Lighthouse. According to Microsoft, “With Azure delegated resource management, service providers can simplify customer engagement and onboarding experiences, while managing delegated resources at scale with agility and precision.” 1

The advantage of Azure Lighthouse is that we only need to do an initial onboarding of the customer, which will give groups in the managing Azure AD tenant the rights to manage the customer’s Azure subscription. Any users in, say, a readers group in our own Azure AD tenant, will be able to view the customer’s subscription, and users in a contributors group will get the rights to actually deploy and manage resources. All the resources will be available from our own Azure Portal as well, so no more subscription switching, and managing user accounts who access customer subscriptions now happens from a single place. Happy days!
Sources:
1. https://learn.microsoft.com/en-us/azure/lighthouse/concepts/architecture
Azure Lighthouse is a Microsoft service that allows one organization to manage Azure resources across multiple customer tenants from a single control plane. Before Lighthouse, managing hundreds of Azure Active Directory tenants required inviting individual accounts into each customer’s environment and manually maintaining permissions across all of them. This became unmanageable at scale. Lighthouse solves this by enabling delegated resource management, where a one-time onboarding process grants specified groups in the managing tenant the appropriate access to customer subscriptions without constant account synchronization.
Azure Delegated Resource Management is the core technology behind Lighthouse. After an initial onboarding, groups in the service provider’s Azure AD tenant receive defined roles to manage a customer’s Azure subscription. Users in a readers group can view customer resources, while users in a contributors group can deploy and manage them. All delegated resources become visible directly in the managing tenant’s Azure Portal, eliminating the need to switch between subscriptions or maintain separate user accounts across every customer environment.
Azure Lighthouse is primarily designed for managed service providers (MSPs) who manage Azure environments for multiple customers. However, it is equally valuable for large enterprises that operate multiple Azure AD tenants, whether due to acquisitions, regional structures, or separate business units. Any organization that needs to manage resources across more than a handful of tenants will benefit from the centralized visibility, simplified access control, and reduced administrative overhead that Lighthouse provides. It eliminates the complexity of maintaining individual user accounts across each tenant.
Lighthouse improves security by replacing broad access with granular, role-based permissions. Instead of granting blanket access to every user in a managing tenant, organizations can assign specific roles to specific groups for each customer. Just-in-time access through Privileged Identity Management (PIM) further reduces standing permissions. Customers maintain full control over which subscriptions or resource groups are delegated and can audit all service provider actions through activity logs. Access can be revoked at any time, giving customers transparency and confidence in how their resources are managed.
Before Lighthouse, managing multiple Azure AD tenants required inviting individual user accounts from the service provider’s tenant into each customer’s Azure AD. For a small number of tenants, this was workable. At scale, with hundreds of customers and multiple accounts per managing tenant, maintaining correct permissions became extremely difficult. Keeping access rights synchronized required custom scripting, and for customers who did not grant Azure AD access directly, the process was entirely manual. Lighthouse eliminates this complexity through a single delegated access model.
Lighthouse centralizes all delegated customer resources into the service provider’s own Azure Portal. This means engineers and administrators no longer need to switch between customer subscriptions or sign in to separate tenants to perform routine management tasks. User accounts, group memberships, and role assignments are all managed from one place. When a new team member joins, they are added to the appropriate group in the managing tenant and automatically receive the correct access level across all delegated customer environments, without any per-customer configuration.
Customers retain full control over their Azure environment when using Lighthouse. They decide exactly which subscriptions or resource groups to delegate and which permissions to grant. Every action performed by the service provider is recorded in the customer’s activity log, providing complete auditability. Customers can review who accessed their resources, what changes were made, and when those actions occurred. If a customer needs to revoke access, they can remove the delegation entirely at any time without requiring action from the service provider.
Yes. Lighthouse is designed to integrate with existing Azure APIs, management tools, and operational workflows. Service providers can continue using the same tooling they already rely on, including Azure Policy, Microsoft Sentinel, Azure Arc, Azure Monitor, and Microsoft Defender for Cloud. The delegated resources appear alongside the provider’s own resources in the Azure Portal, so there is no need to adopt separate interfaces or management consoles. This compatibility ensures that organizations can adopt Lighthouse without overhauling their existing operational processes.
Yes. While Lighthouse is primarily marketed toward service providers, it is equally effective for enterprises managing multiple Azure AD tenants internally. Organizations that have acquired companies, operate across distinct business units, or maintain separate tenants for regulatory reasons can use Lighthouse to centralize management tasks without merging their tenant structures. Users in a designated managing tenant can perform operations across other enterprise tenants using the same delegated resource model, improving consistency, reducing administrative duplication, and simplifying governance across the organization.
An Azure Expert MSP like Intwo brings deep experience in configuring and operating Lighthouse at scale across diverse customer environments. Intwo handles the onboarding process, defines the appropriate role-based access structures, and manages delegated resources with the agility and precision that Lighthouse enables. This partnership gives organizations centralized management, proactive monitoring, and consistent security governance without the internal overhead of building these capabilities themselves. For businesses running complex Azure estates, working with an experienced MSP ensures Lighthouse delivers its full operational and security benefits.
Rest assured. We've got you.
Let's get in touch and tackle your business challenges together.