Hi,
You can deploy your ER circuit in a subscription and provision it. Once ER circuit is provisioned, you will need to create ER gateway to connect to the ER circuit.
- Based on your description you are planning to have one HUB where you will be deploying the ER Gateway and other Azure Tenants will be peering with the HUB to reach On-Premises.
There is another way to do it. You can deploy multiple ER gateways - 1 per tenant and connect them to the ER circuit.
If all Azure tenant VNETs are of same customer, you are good. If you don't want traffic from one VNET to transit to other VNET via ER Circuit, you will need to implement this via NSGs and other options. This is because when you connect VNETs to same ER circuits all the VNETs can communicate with each other by default.
Regards,
Karthik Srinivas