What each role can do
Managing the organization covers team members, billing, single sign-on, the audit log, and creating tenants. This follows the organization role, so giving someone Admin in one tenant lets them manage that tenant but not the organization.
Use Support analyst for a support agent who needs to investigate user activity and reset authenticators.
Tenant access
Under Tenant access, each tenant has its own control:- The organization role gives them whatever their organization role is, and follows it when you change it.
- A specific role overrides their organization role in that tenant.
- No access hides the tenant from them.
Add a team member
You need the Admin organization role to add or change team members.- Open Organization settings > Team.
- Click Add team member.
- Enter their Full name and Email.
- Choose an Organization role.
- Under Tenant access, set the role for each tenant they need. Leave the rest on No access.
- Click Add team member to send the invitation.
Change roles or tenant access
- Open Organization settings > Team and select the team member’s name.
- Under Access and roles, change their Organization role, change the role for any tenant, or set a tenant to No access to revoke it.
- Click Save changes.
Deactivate a team member
Deactivating is how you remove someone from the organization. It takes away their access to the organization and all of its tenants, and stops them signing in.- Open Organization settings > Team and select the team member’s name.
- Click Deactivate team member.

