PageSourceSearch

https://www.contraforce.com/assets/gdap-tenants-missing-content-distribution-BZ1W_vPg.js

js contraforce.com collected 2026-10-03 19:49:13 UTC 3,701 bytes, 43 lines download raw bytes

1const e=`# Why does a connected tenant not appear as a target for content distribution?
2
3> Microsoft documents that a cross-cloud tenant removed from cross-cloud visibility becomes unavailable, and describes this as a recognised limitation of cross-cloud tenant management currently under review. Beyond that case, eligibility for content distribution follows the access model: multitenant management requires GDAP or Microsoft Entra B2B for Defender data, and Microsoft Sentinel data is not reachable through GDAP.
4
5**Last verified: 2026-09-04.** Sources linked at the foot of the page.
6
7## What does Microsoft document about tenants going missing?
8
9One cause is stated plainly. A cross-cloud tenant removed from cross-cloud visibility becomes unavailable, and Microsoft describes this as a recognised limitation of cross-cloud tenant management that is currently under review. If an estate spans clouds, this is the first thing to check.
10
11Beyond that, the documentation describes eligibility rather than failure modes. Tenants are added and removed from the settings page, and access to Defender data requires either GDAP or Microsoft Entra B2B. A tenant reachable by neither is not reachable by multitenant management.
12
13There is no published diagnostic for a tenant that is connected but absent from a picker, which is worth saying directly rather than implying a cause the documentation does not give.
14
15## What is worth checking, in order?
16
17The checks that follow from what is documented, cheapest first.
18
191. **Cloud boundary.** Is the tenant in a different cloud from the one you are working in? That is the one case Microsoft names.
202. **Access model.** Does the relationship carry GDAP or Entra B2B for Defender data? A relationship that exists commercially is not necessarily one that carries the access.
213. **Data type.** Is the content Sentinel-related? GDAP does not reach Sentinel data, so a tenant reachable for Defender content may not be reachable for Sentinel content.
224. **Content type.** Automation rules that trigger a playbook cannot be distributed at all, and playbooks are not a distributable type, so an absent target may be an ineligible content type rather than an absent tenant.
23
24Point four is the one most often mistaken for a tenant problem. The tenant is fine and the content is not distributable.
25
26## Why is this hard to diagnose at scale?
27
28Because the negative case is silent. A tenant that does not appear produces no error explaining why, and the four causes above have no distinguishing signal between them in the console. Verifying coverage means checking each tenant individually, which is the work multitenant management exists to remove.
29
30## How do you make coverage verifiable?
31
32The underlying issue is that intended state and actual state live in different places, and only one of them is written down.
33
34ContraForce manages detection content as versioned repositories deployed to the workspaces you choose, with drift detection that scans a workspace and reports the rules that no longer match the baseline. A tenant that did not receive content appears as a difference rather than as an absence somebody has to notice.
35
36## Sources
37
38- [Microsoft Defender multitenant management requirements](https://learn.microsoft.com/en-us/unified-secops/mto-requirements)
39- [Manage multitenant content distribution](https://learn.microsoft.com/en-us/unified-secops/mto-configure-content)
40- [Microsoft Defender multitenant management overview](https://learn.microsoft.com/en-us/unified-secops/mto-overview)
41
42Verified on the date shown. Microsoft describes the cross-cloud case as under review, so confirm current behaviour before designing around it.
43`;export{e as default};

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.