This large U.S. state government agency manages Microsoft 365 for roughly 100,000 users across around 100 agencies within a single enterprise tenant. With agency-level IT teams handling day-to-day administration, central IT needed a way to delegate access without giving operators inappropriate visibility or control across the wider environment.
Managing Microsoft 365 across roughly 100 agencies, the state government agency’s central IT team had been facing a difficult trade-off. Agency-level operators needed enough access to handle day-to-day administration for their own users, but broad tenant-wide permissions would give them visibility or control beyond their remit.
The alternative was to keep administration tightly centralized, forcing agency IT teams to escalate routine requests and increasing the burden on central IT. Neither model worked well at this scale.
The agency also lacked the reporting visibility it needed across a large and complex user environment. Native Microsoft 365 tools made it difficult to pull accurate, actionable data, leaving the team with only limited visibility into access levels, permission drift, and potential risk.
Microsoft 365’s native role model did not map cleanly to a multi-agency government environment. With admin roles in the Microsoft 365 admin center typically tenant-wide, it’s difficult to give an operator responsibility for one agency without extending their reach across others. Administrative units can provide some scoping, but they require significant setup and do not fully reflect complex organizational structures or every type of delegated task.
These limitations left the agency with no reliable way to limit each operator’s access to the users and resources they were responsible for managing. For an agency subject to regulatory and audit scrutiny, those blurred administrative boundaries created a clear governance risk.
The team needed a model that could enforce who was allowed to manage which users and resources, while giving central IT clearer visibility across the tenant.
To give local IT teams the access they needed within clearly defined boundaries, the agency deployed CoreView Virtual Tenants.
CoreView overlays a segmentation layer onto the existing Microsoft 365 tenant, allowing central IT to map administrative access to the agency’s organizational structure.
Agency-level operators can manage their own users, groups, and configurations without gaining visibility into other agencies’ data or accounts. Central IT retains oversight across the full tenant.
To improve visibility across the wider Microsoft 365 environment, the agency also used CoreView’s reporting capabilities to surface key data at scale.
The agency now has a more clearly defined governance model for Microsoft 365 administration, with access aligned more closely to each operator’s area of responsibility.
The core benefits include:
Together, these changes give the agency a robust foundation for governing Microsoft 365 at scale.
CoreView has enabled the agency to align Microsoft 365 administration with its real organizational structure inside a single tenant.
Rather than relying on broad native admin roles, complex workarounds, or operators simply staying within their intended remit, Virtual Tenants enforce clear administrative boundaries.
This has made delegated access more practical and auditable across the agency’s complex Microsoft 365 environment.
Next Steps: Extending Governance Across Configuration and Hybrid AD
To extend its governance model beyond users and groups into Microsoft 365 configuration settings, the agency is in the process of adding CoreView Configuration Manager. The software will allow central IT to define required configuration baselines and identify when settings drift from them.
The agency is also moving toward hybrid management in CoreView to simplify the management of users and groups connected to its hybrid Active Directory environment. Operators will be able to manage these objects directly through CoreView, reducing the need to work in Active Directory itself.
Together, these next steps will extend the agency’s governance model across more of its Microsoft 365 and hybrid infrastructure.