We are developing a web application that needs to create new Microsoft Entra workforce tenants programmatically.
We are specifically interested in the Microsoft Entra Tenant Governance "Secure Add-on Tenant Creation" capability.
Microsoft documentation states that a new add-on tenant can be created using the Commerce API or the Microsoft Entra admin center.
We do NOT want to automate or reverse-engineer the Microsoft Entra admin center UI. We need to use an officially supported API.
Please confirm the following:
Whether this API is currently available to customers as a Public Preview capability.
The official API endpoint/base URL and API version.
The required OAuth 2.0 audience/resource and scopes.
The required Microsoft Entra application permissions and/or delegated permissions.
The required user roles, billing-account permissions, subscription permissions, and Tenant Creator requirements.
The official request body/schema for creating a new workforce tenant.
The official response schema, including the newly created Tenant ID and initial onmicrosoft.com domain.
The process for enabling or requesting access to this API.
Whether any preview enrollment, allow-listing, feature flag, or Microsoft approval is required.
The official API documentation, Swagger/OpenAPI specification, or Microsoft-provided integration documentation.
Our intended flow is:
User signs in with Microsoft Entra ID → Backend validates the signed-in user → Backend checks Tenant Creator permission → Backend checks Azure subscription/RBAC permission → Backend validates any required billing eligibility → Backend calls the officially supported Commerce API → New Microsoft Entra workforce tenant is created → Backend receives the new Tenant ID/domain → Application continues its onboarding process.
Our intended business architecture is to create separate Entra tenants for tenant groups within our SaaS application. For example, multiple application customers may belong to Tenant Group A and use Entra Tenant AA, while another group uses Entra Tenant BB.
We are specifically requesting the officially supported Commerce API contract, including the endpoint, API version, authentication requirements, permissions, request/response schemas, and the access/enablement procedure required to implement this scenario.
If this API is managed by a different Microsoft product team or requires a preview/allow-listing process, please route this request to the appropriate Microsoft Entra Tenant Governance / Commerce API team or provide the appropriate escalation/contact path.
Please do not provide a recommendation to automate the Microsoft Entra admin center UI. We are specifically looking for the officially supported programmatic API.