Home > User Management > Add Users
Export to PDFTo add users and grant user permissions to AvePoint Online Services and other services, click Add on the User management page. Refer to the information below to configure settings in the Add user pane:
Sign-in method – Select a sign-in method from the drop-down list.
Local user – The local system will check the user’s credentials.
Microsoft 365 user/group – Microsoft 365 users and groups will become AvePoint Online Services users. They can use their Microsoft 365 login IDs to log into AvePoint Online Services.
To allow added users and group users to sign in to AvePoint Online Services with their Microsoft 365 login IDs, AvePoint recommends that the Microsoft 365 Global Administrator check the Enterprise applications configuration in Microsoft Entra ID > Enterprise applications > Consent and permissions > User consent settings. If the Do not allow user consent option is selected, the Microsoft 365 Global Administrator or Privileged Role Administrator must consent to the AvePoint Online Services app first. For details on consenting to the app by the Administrator, refer to What If Your Tenant Does Not Allow Users to Consent to Apps?
Salesforce user – Salesforce users will become AvePoint Online Services users. They can use their Salesforce login IDs to log into AvePoint Online Services.
Google user/group – Google users and groups will become AvePoint Online Services users. They can use their Google login IDs to log into AvePoint Online Services.
Due to Google API limitations, users in the nested Google groups cannot use their Google login IDs to log into AvePoint Online Services.
The following options appear according to the sign-in method you’ve selected:
Microsoft 365 tenant – This option only appears if Microsoft 365 user/group is selected as the sign-in method. Select a tenant from the drop-down list.
Google tenant – This option appears if Google user/group is selected as the sign-in method. Select the tenant of the users you want to add from the drop-down list.
Salesforce tenant – This option only appears if Salesforce user is selected as the sign-in method. Select the tenant of the users you want to add from the drop-down list.
For organizations with a subscription to MyBiz, the Salesforce Sandbox tenant can be listed in the Salesforce tenant drop-down list. If you select a Salesforce Sandbox tenant, you can only add users with the Tenant user role for MyBiz. Salesforce Sandbox users added via this way can only access the MyBiz environment, but they cannot access the AvePoint Online Services environment.
The tenants in the Microsoft 365 tenant / Google tenant / Salesforce tenant drop-down list are retrieved from Tenant management. For details on connecting tenants, refer to Connect Your Tenants to AvePoint Online Services.
Add users – Specify the users that you are about to add to AvePoint Online Services.
For Local user, enter valid email addresses in the format of someone@example.com.
For Microsoft 365 user/group, you can enter the following:
The usernames / email addresses of Microsoft 365 users in the format of someone@example.com.
The aliases of Microsoft 365 users.
The names / email addresses of Microsoft 365 Groups, mail-enabled security groups, distribution groups, and security groups.
If the Microsoft 365 username, alias, or group name begins with a special character, you cannot add them to AvePoint Online Services.
For Google user/group, you can enter the following:
The usernames of Google users in the format of someone@example.com.
The display names or email addresses of Google groups.
For Salesforce user, enter usernames of Salesforce users in the format of someone@example.com.
Note the following:
If you select Microsoft 365 user/group as the sign-in method, you can specify Everyone. Everyone refers to all available users (excluding external users) in your Microsoft 365 tenant’s Microsoft Entra ID. If you add Everyone as AvePoint Online Services users, all available users can sign in to AvePoint Online Services and perform the corresponding actions according to the assigned role and available products.
When you add a security group, distribution group, or mail-enabled security group to AvePoint Online Services, the following users cannot sign in to AvePoint Online Services:
The owner of the distribution group or mail-enabled security group.
If the security group has nested groups and the owner of a nested group is not a member of any other groups that have been added to AvePoint Online Services, the nested group owner cannot sign in to AvePoint Online Services.
Guest users cannot log in to AvePoint Online Services.
ReCenter (for Microsoft 365): This service is only supported for Microsoft 365 accounts. If you want to grant permissions to many users, it is recommended to grant permissions to Microsoft 365 Groups instead of Microsoft 365 users.
Cloud Backup for IaaS + PaaS: This service is only supported for Microsoft 365 accounts and local accounts.
ReCenter (for Google Workspace): This service is only supported for Google users.
Confide: This service is only supported for Microsoft 365 accounts and local accounts.
EnPower: This service is only supported for Microsoft 365 accounts.
tyGraph: This service is only supported for Microsoft 365 accounts.
AvePoint Portal Manager: This service is only supported for Microsoft 365 accounts and local accounts.
Document Management System Online: This service is only supported for Microsoft 365 accounts.
MyHub: This service is only supported for Microsoft 365 accounts.
Role – Select the Tenant user, Service administrator, or Customized administrator role.
For more details about the user roles, refer to AvePoint Online Services User Roles.
Assign permissions to users (for Customized administrator) – If you select the Customized administrator role, turn on the toggle of the permission that you want to assign to the users. In AvePoint Online Services, you can assign Management, Auto discovery, and Administration permissions to customized administrators, and they can only access the functions for which they have been assigned permissions. When customized administrators go to each cloud service, their permissions are the same as the service administrators.
Assign services and permissions to users (for Tenant user) – If you select the Tenant user role, turn on the toggle of the service that the users can access, and then select the permissions for the users. The services available for selection depend on your subscription. If your subscription for a specific service has expired, the service is unavailable for selection.
| Service | Permission |
|---|---|
| Cloud Management services (includes Cloud Management, Cloud Archiving, and Classic DocAve Backup services) | Standard user: A standard user can be delegated access to SharePoint Online site collections and Cloud Management tools. For details on how power users can delegate access for standard users, see AvePoint Cloud Management User Types. |
| Cloud Management services (includes Cloud Management, Cloud Archiving, and Classic DocAve Backup services) | Application administrator: The application administrator fulfills the role of a Power User. Power Users have full control of Cloud Management tools as well as profile and plan settings. |
| Cloud Governance | Application administrator: The application administrator fulfills the role of the IT Administrator. The IT Administrator can create or modify service request definitions and manage AvePoint Cloud Governance settings. |
| Cloud Backup for Microsoft 365 | Standard user: Standard users must be manually added to Cloud Backup for Microsoft 365 account management. The standard users who are added to the security groups can configure restore settings, perform restores, and view activity reports. Additionally, the standard users who are added to the Administrators group can also configure backup settings and perform backups. |
| Cloud Backup for Microsoft 365 | Application administrator: The application administrator can configure backup and restore settings, perform backup and restore, view activity reports, etc. |
| ReCenter (for Microsoft 365) | Standard user: Standard users can access the ReCenter portal, run jobs to recover Microsoft 365 data, and view job reports. |
| ReCenter (for Microsoft 365) | Application administrator: Application administrators can use all the functionalities in ReCenter and manage access to ReCenter for Standard users. |
| Cloud Backup for IaaS + PaaS | Application administrator: In Cloud Backup for IaaS + PaaS, application administrators can manage backup and restore settings, perform backup/restore jobs, and view or download job reports. |
| Cloud Backup for IaaS + PaaS | Standard user: Standard users must be manually added to Cloud Backup for IaaS + PaaS account management. The standard users who are added to a security group will have the same permissions as this group has been granted. The standard user can also be added to the Administrators group to have the full control to the application. |
| Cloud Backup for Dynamics 365 | Application administrator: The application administrator can configure backup and restore settings, perform backup and restore, view activity reports, etc. |
| Cloud Backup for Dynamics 365 | Standard user: In Cloud Backup for Dynamics 365, administrators must add standard users to specific security groups to access certain features. |
| Cloud Backup for Google Workspace | Application administrator: In Cloud Backup for Google Workspace, application administrators can configure backup and restore settings, perform backup and restore, view activity reports, etc. Apart from these, in AvePoint Online Services, application administrators can add Tenant Users and assign Cloud Backup for Google Workspace to them. |
| Cloud Backup for Google Workspace | Standard user: Standard users must be manually added to Cloud Backup for Google Workspace account management. The standard users who are added to the security groups can access the Cloud Backup for Google Workspace portal to restore/export backup data and view job reports based on their permissions. |
| ReCenter (for Google Workspace) | Standard user: Standard users can access the ReCenter portal, run jobs to recover Google Workspace data, and view job reports. |
| ReCenter (for Google Workspace) | Application administrator: Application administrators can use all the functionalities in ReCenter and manage access to ReCenter for Tenant Users. |
| Cloud Backup for Salesforce® | Standard user: A standard user must be added into a user group in AvePoint Cloud Backup for Salesforce® by Administrators for using the specific features according to the permissions granted to the user group. |
| Cloud Backup for Salesforce® | Application administrator: The application administrator fulfils the role of an Administrator. The Administrator can perform backup/restore jobs, export backup data to CSV, download reports, and manage AvePoint Cloud Backup for Salesforce® settings. |
| Cloud Backup for SaaS Applications | Application administrator: In Cloud Backup for SaaS Applications, application administrators can configure backup, restore/export settings, perform jobs, and view the activity report, etc. |
| Cloud Insights | Standard user: A standard user can only view statistics about the site collections for which they have the role of primary administrator or site owner. |
| Cloud Insights | Application administrator: The application administrator can view statistics about all site collections in your SharePoint Online environment. |
| Opus | Standard userIn AvePoint Opus, standard users do not have access to any content sources. Standard users must be added to a security group so that they can manage the content within the content source. |
| Opus | Application administrator: In AvePoint Opus, application administrators have access to all content sources. They can create security groups and set permissions for users and groups in AvePoint Opus. |
| Office Connect Online Manager | Application administrator: The application administrator, who must be a Microsoft 365 Global Administrator, can access the Office Connect Online Manager Configuration page from AvePoint Online Services. |
| Cloud Index | Standard user: A standard user can view file lists and perform actions on files in the connections configured by application administrators. |
| Cloud Index | Application administrator: The application administrators can configure connections between the data sources and Microsoft 365. |
| Policies for Microsoft 365 | Application administrator: The application administrators can create policies and assign policies to Microsoft 365 content to monitor user activities and changes within Microsoft 365. After that, application administrators can generate reports for identified violations. |
| Insights | Standard user: In Insights, standard users can view risk analysis and exposure reports and view data in the dashboard based on the permissions of the groups to which they belong. Standard users that have been added to the Administrators group can also configure risk definitions, scope and binding, administration settings, as well as additional actions for external user management. |
| Insights | Application administrator: The application administrators can configure sensitivity and exposure definitions, configure scope and admin settings, view risk analysis and exposure reports, view data in the dashboard, etc. |
| Cense | Standard user: Standard users can monitor Microsoft 365 user license consumption with charts and reports and manage user licenses based on their permissions for Cense. |
| Cense | Application administrator: Application administrators have full control permission and can use all functionalities in Cense. Apart from this, in AvePoint Online Services, application administrators can add tenant users, assign Cense to them, and then add them to groups to assign Microsoft 365 users for license management. |
| Confide. | Standard user: In Confide, standard users can be added with the Audit viewer role in the Confide admin portal to view the user activity report. |
| Confide | Application administrator: In Confide, application administrators can appoint Business Owners, and manage license and watermark settings. |
| Fly | Standard user: Standard users must be manually added to Fly user management. Standard users added to security groups can access different migration workloads or migration tenant projects. |
| Fly | Application administrator: In Fly, application administrators have full control permission and can use all functionalities. Apart from this, in AvePoint Online Services, application administrators can add Tenant Users and assign Fly to them. |
| EnPower | Standard user: In EnPower, Tenant User maps to the standard user role. |
| EnPower | Application administrator: In EnPower, application administrators can use all the functions. |
| tyGraph | Standard user: Standard users can view certain reports according to their roles assigned by the administrator. |
| tyGraph | Application administrator: Application administrators can manage overall report settings, manage pages configurations, and grant permissions to other users to view certain reports. |
| AvePoint Portal Manager | Standard user: In AvePoint Portal Manager, standard users can create templates and manage the templates created by themselves. However, they cannot publish, deploy or update templates. |
| AvePoint Portal Manager | Application administrator: In AvePoint Portal Manager, application administrators can perform all the operations, including creating templates, managing all templates, deploying templates, and managing all settings. |
| rakumo for Microsoft 365 | Application administrator: Application administrators can perform Microsoft 365 synchronization to retrieve data for management. Besides, application administrators can also configure settings of each service and manage some system settings. |
| Document Management System Online | Standard user: In Document Management System Online, standard users can search and manage documents in your SharePoint Online environment. |
| Document Management System Online | Application administrator: In Document Management System Online, application administrators can search and manage documents in your SharePoint Online environment. Apart from these, application administrators can also manage permissions of standard users in Document Management System Online. |
| MyHub | Standard user: Standard users in MyHub focus on tasks assigned to them via various integrated products. They interact with their personalized portal to efficiently manage and complete these tasks. |
| MyHub | Application administrator: Application admins in MyHub can configure general settings and manage system-wide preferences through a centralized configuration portal. These settings are applied across all end-user portals, ensuring a consistent and streamlined experience. |
| MyBiz | Standard user: A standard user can use specific features according to the roles granted by administrators. |
| MyBiz | Application administrator: Application administrators can use all features in MyBiz Admin center and specific features in MyBiz End user portal according to the granted roles. |
| Confidence Platform for Google | Standard user: Standard users will be automatically synchronized to the Confidence Platform for Google for user management. In the Confidence Platform for Google, standard users can be assigned delegated roles with full control or limited permissions over specific data scopes. |
| Confidence Platform for Google | Application administrator: Application administrators have full control permission and can use all functionalities. |
Note the following options for specific services:
Available geo location – If your tenant has Multi-Geo Capabilities in Cloud Backup for Microsoft 365 service, the Available geo location option will appear when you assign the Cloud Backup for Microsoft 365 to users. To maintain segregation among geo locations, select one or more geo locations that will be available to the users.
Available reports – If you assign the Cloud Insights service to users, the Available reports option appears. Select one or more reports that will be available to the users.
Send email notifications to the newly added users and groups (for Microsoft 365 user/group, Google user/group, or Salesforce user) – If you want to send email notifications to newly added users and groups, select this option.
Click Save to save your configurations. Users with the sign-in method of Local user will receive invitation emails. They must activate the user IDs first by clicking the link provided in the emails, and then use the user ID and password in the invitation emails to sign in to AvePoint Online Services.