Tenant administrator
Give people the access they need and protect recovery paths
Administration aligns people, permissions, settings, security, notifications, and data protection with the workspace’s real operating model. Start with roles and recovery, then enable modules and external channels.
Before you start
- Tenant administrator access.
- A role and recovery owner agreed.
- Verified mail before enforcing email-dependent security.
#Build roles from job responsibilities
- List who builds, publishes, approves, administers connectors, manages projects, handles leads, and views audit data.
- Start with the least capable suitable role.
- Add sensitive permissions only with an owner and reason.
- Test using a non-administrator account.
- Review system roles before editing custom roles.
#Configure settings in safe order
Set general identity, branding, security policy, OTP/TOTP, channels, sessions, and tools. Test mail before enforcing email verification or password-reset reliance. Keep maintenance tools and provider tests limited to trusted administrators.
#Treat MFA recovery as part of setup
Confirm TOTP with a current code, store recovery codes once in a secure location, and document an administrator-assisted recovery path. Platform MFA and tenant-user MFA are separate controls.
#Prove export and restore
Configure portable exports and database backups according to retention policy. A backup is not proven until a restore succeeds in an isolated environment. Keep tenant exports, private attachments, and secret-bearing settings out of public storage.
#Common mistakes
- Giving every manager administrator access.
- Enforcing email security before mail works.
- Saving recovery codes in the same browser or server.
- Calling an untested backup a recovery plan.
#Verify the result
- Roles were tested with non-admin users.
- Mail and recovery paths work.
- MFA recovery is documented.
- A restore has been proven in isolation.