Managing external identities to enable secure access for partners, customers, and other non-employees
Yes. An Azure subscription can be used for Microsoft Entra External ID billing and feature access, but it must be visible to the correct tenant and the signed-in account must have the required permissions.
For an external tenant, the subscription must be owned by a Microsoft Entra workforce tenant. External tenants do not have subscription management capabilities, and subscription ownership cannot be changed to an external tenant.
If the subscription selector shows No available items, the documented causes are:
- Signed in to the wrong tenant
If currently signed in to the external tenant, switch to the workforce tenant in the Microsoft Entra admin center:
- Settings
- Directories + subscriptions
- Find the workforce tenant
- Select Switch
- Insufficient permissions on the subscription The required permission is at least the Contributor role on the subscription or on a resource group in that subscription. Being Owner already satisfies this requirement.
- The subscription is not associated with the current directory A subscription can exist but still not appear if it is not associated with the directory currently in use. In that case, associate the existing subscription with the tenant, then repeat the linking flow.
Also, Microsoft Entra External ID requires the tenant to be linked to an Azure subscription for billing and feature access.
Based on the documented requirements, Azure Subscription 1 is eligible only if all of the following are true:
- it is associated with the same workforce tenant currently selected in the Microsoft Entra admin center
- the signed-in account has at least Contributor on that subscription or one of its resource groups
- the subscription is being used from the workforce tenant context, not the external tenant context
The Tenant Creator role does not appear in the documented requirements for subscription visibility in the selector. The documented checks are tenant context, subscription association to the directory, and Azure RBAC permission.