Nerdio Manager's Intune Cross-Tenant Management feature allows administrators to add and manage multiple additional Intune tenants within a single Nerdio Manager instance. This provides a simplified management experience when administering large or complex Intune environments, especially in multi-organizational scenarios - for example, following Merger and Acquisition (M&A) events, or where multiple child organizations are managed by a parent organization.
By configuring a Service Principal and Enterprise Application registration in the secondary tenants, you can perform Intune and Windows 365 management on the secondary tenants via the Nerdio Manager instance running in the primary tenant.
The vast majority of management functions that are available in single-tenant Nerdio Manager deployments are also available in multi-tenant scenarios, with complete feature parity planned for future releases.
This feature is in Public Preview.
The feature is available in the following Nerdio Manager plans:
|
AVD Core |
|
|
AVD Premium |
|
|
Windows 365 |
|
|
Unified Endpoint Management |
|
*The feature is fully functional in all subscriptions; however, initial setup makes use of AVD Premium Nerdio Manager features for Entra ID-based tenant linking. Subscribers to other plans will need to perform advanced configuration in the Azure CLI.
The Preview version of this feature contains the following limitations:
|
Issue/limitation |
Impact |
Mitigation/planned fix |
|---|---|---|
|
Automatic assignment of Nerdio Manager permissions in the secondary tenant is not supported. |
You need to create a Service Principal in the secondary tenant and manually assign the permissions for the required Intune functions. |
|
|
Intune User Operating Mode is not supported for secondary tenants. |
Nerdio Manager must be configured to operate in application context mode. |
Support for user context mode is planned for a future release. |
|
Policy propagation across tenants is not currently supported. |
You need to assign Intune policies to each tenant individually in Nerdio Manager. |
|
|
The Intune Insights feature is not supported for secondary tenants. |
The data dashboards and reports associated with Intune Insights are currently available for the primary managed tenant only. |
A number of reports can be viewed under Reports in the Intune portal, though the detailed visualizations associated with Nerdio Manager Insights are not currently available for secondary tenants. |
|
Intune Service Accounts can't be linked to secondary tenants. |
A small number of operations, such as the viewing of BitLocker keys, can't be performed on the secondary tenant within Nerdio Manager. |
Perform these operations directly via the Intune portal. |
|
Signing Intune scripts via Nerdio Manager is unavailable for secondary tenants. |
Self-signing of scripts in Nerdio Manager is available for primary tenants only. |
Use native PowerShell methods to sign scripts for the secondary tenants. |
|
AVD to Windows 365 migration is not supported for secondary tenants or cross-tenant scenarios. |
Migration of AVD hosts to Windows 365 Cloud PCs can currently be automated for the primary tenant only. |
Migration in the secondary tenants requires manual instantiation of a Windows 365 Cloud PC and migration of user accounts using the Microsoft Graph API. |
Following the Principle of Least Privilege (PoLP), you can define a custom role to enable and configure Intune Cross-Tenant Management in Nerdio Manager. Full Access in the Intune module is required.
The following procedure guides you through configuring and managing Intune Cross-Tenant Management:
Contact our Sales team for more information about this feature.
Comments (0 comments)