Skip to main content
Version: 2026.09

Administrators

An installation with tenant management has two administrator roles:

RoleAdministersWho may grant or revoke it
Tenant AdministratorOne tenant: its people, agents and settingsA Platform Administrator, for any tenant; a Tenant Administrator, for their own tenant
Platform AdministratorThe whole installation: every tenant, every tenant's people, and who holds the Platform Administrator role, from the Platform Admin ConsoleA Platform Administrator

A Platform Administrator can manage any tenant without holding the Tenant Administrator role there. A person can also hold both roles. The Tenant Administrator role applies to the tenant the person belongs to.

Your IT administrator creates the first Platform Administrator when the platform is installed.

Grant an administrator role​

You can make someone a Tenant Administrator only if they belong to a tenant.

  1. Find the person:
    • To grant Tenant Administrator: Users in the Admin Panel, Users in the Platform Admin Console, or the Members section of a tenant's page in the Platform Admin Console.
    • To grant Platform Administrator: Users in the Platform Admin Console, or the Members section of a tenant's page there.
  2. Open the row's ⋮ menu and choose Make tenant admin or Make platform admin. On the person's details page, check the role's box in the Roles section instead.
  3. The confirmation says what the person will administer. Click Grant.

If you grant a role to yourself, your access usually updates at once. Otherwise a notification says "Your own roles update on your next sign-in."

The row menu items are always named Make tenant admin, Remove tenant admin, Make platform admin and Remove platform admin. Confirmations, the Admin column and the Roles section may show your installation's own names for the roles.

Revoke an administrator role​

You cannot revoke your own administrator role. Your own row's menu offers no Remove tenant admin or Remove platform admin, and your own boxes in Roles are disabled.

  1. Find the person, as for granting.
  2. Open the row's ⋮ menu and choose Remove tenant admin or Remove platform admin. On the details page, clear the role's box instead.
  3. The confirmation says what the person will no longer administer. Click Revoke.

A Platform Administrator may revoke any other Tenant Administrator, including a tenant's only one.

A role can come from your sign-in provider rather than from Istari. The confirmation then says: "This role was imported from the sign-in provider. Removing it here takes effect now, and it stays removed even if the provider still grants it."

Refusals​

Where the page can tell in advance that an action would be refused, the action is disabled:

  • In a row's ⋮ menu, the reason appears under the action's name.
  • In the Roles section, hover over the box to read the reason.

Otherwise the refusal appears in the dialog or as a notification.

SituationMessageWhat to do
Removing the last active Platform Administrator: revoking their role or their membership, suspending them, or suspending their tenant"The installation keeps at least one active platform administrator."Grant the role to someone else first
Granting a role to a suspended person"This user is suspended."Reactivate the person first
Granting Tenant Administrator in a suspended tenant, from the Platform Admin Console"This tenant is suspended."A Platform Administrator reactivates the tenant first
A Tenant Administrator removing Tenant Administrator from a Platform Administrator"Only a platform administrator can change a platform administrator."Ask a Platform Administrator

On installations without tenant management​

If Settings > Admin > Users has an Invited tab, your installation does not use tenant management. There, your IT administrator grants administrator access in your sign-in provider, not in Istari. The Admin column of the Users page only shows who holds it.