Students want simplicity. Lecturers want control of their courses. Administrators want records that auditors trust. IT wants one tenant it can actually govern. These demands pull in different directions — and yet, in my experience, a single well-governed tenant serves all of them better than the fragmented alternative.
The case against fragmentation
Separate tenants per faculty feel like autonomy, but they multiply every cost: duplicated licences, inconsistent security, mail that can’t find people, and collaboration that dies at faculty boundaries. A student taking courses across three faculties should not need three identities. Fragmentation taxes exactly the people with the least power to complain.
Governance is what makes “one” work
A single tenant without governance is just a bigger mess. What makes it work is structure agreed up front: a naming convention for Teams and groups, a clear identity lifecycle from admission to graduation, delegated administration so faculties manage their own spaces within guardrails, and security baselines — MFA, conditional access, retention — applied to everyone, including leadership.
- Design the Teams and SharePoint topology before assigning licences.
- Automate provisioning and deprovisioning around the academic calendar.
- Delegate administration with roles, not with global admin accounts.
- Train faculty champions — adoption follows people, not memos.
The honest trade-off
One tenant means shared change windows, shared policies and the occasional hard conversation about who gets to create what. That friction is real — but it is the friction of governance, and it is far cheaper than the chaos of five tenants drifting apart.
So yes: one tenant can serve everyone, provided someone does the unglamorous work of governing it. That work — structure, lifecycle, training, review — is the actual job. The licences are the easy part.
Taming a sprawling tenant?
Get governance, identity and rollout handled
by someone who has done it at scale.