If you hold an administrative role in a tenant, its area appears in the menu under Tenant. If you belong to several tenants, choose one with the tenant switcher at the top of that area.
What you can do
What you see depends on your roles in the tenant:
- Members: who belongs to the tenant and their roles; assigning roles explains separation-of-duties conflicts.
- Invitations: invite members and guests by email.
- Units and subgroups: the tenant's structure, and groups for projects whose member lists may be private.
- Settings: the tenant's own settings, such as who must use two-step sign-in, guest policy and session length.
- Domains and organisation sign-in: verify email domains and link your organisation's sign-in system.
- Audit, eDiscovery, erasure, offboarding, extensions, support approvals and closure, for the roles that need them.
Every role and what it allows is on .
Rules that always apply
- Some roles cannot be held together (separation of duties); for example a guest never holds an administrative role.
- A tenant always keeps at least one owner.
- Depending on your organisation's policy, sensitive changes may ask you to confirm with your second factor; where it is optional, a second factor is still recommended.
- Every change is recorded in the tenant's audit log.