A tenant nobody owns still has an administrator.
Most Microsoft 365 tenants were configured during a rushed setup, a migration, or by whoever was available at the time. Admin rights spread to a departed employee, a former partner, or a vendor account nobody remembers granting. Sharing defaults, license tiers, and Conditional Access exceptions accumulate the same way - each one reasonable on its own, none of them reviewed as a set.
The result is a tenant that runs, but that nobody can fully describe. Ask who can reset a global admin password, why a specific license tier was assigned, or what happens to guest access after a project ends, and the honest answer is often a shrug rather than a policy.
Tenant governance treats Microsoft 365 - or a comparable Google Workspace environment - as an ownership decision: name who is accountable for its configuration, set a standard, and put a cadence on reviewing it before an audit, an insurer, or an incident forces the question.