How are you keeping Entra External ID config consistent across multiple tenants?

Posted by antivocal@reddit | sysadmin | View on Reddit | 14 comments

Managing a handful of entra external ID tenants for different clients and keeping them consistent is kind of a mess, every tenant has drifted from the "standard" config in some small way and there's no clean way to see what's different or push a change across all of them.

Currently got some graph API scripts and a folder of exported JSON i manually diff

is there anything better out there? not looking for full IaC, just something that can tell me "here's what's different between these two tenants right now"