Manage Tenants

    If a tenant is already registered in AvePoint Online Services, the associated customer account will be automatically mapped to the tenant, and this customer-to-tenant mapping cannot be modified. For an unregistered tenant, you must manually onboard a customer and map it to the tenant.

    Before onboarding customers or adding services, you must first push an admin app to each target tenant. Select the desired tenant, click Authorize, and then click Push and closeto initiate the authorization process.

    To manually onboard and map a customer to a tenant, select the tenant and click Onboard and map customers. Complete the customer information and click Invite and close. Once onboarded, the customer account will appear in the customers list. Search for the customer by organization name and select the target customer account. Click Apply changes to apply the updates. Once applied, the customer-to-tenant mapping cannot be modified.

    To add the baseline management service to a tenant, select the tenant and click Add services. Enable the toggle of the service and click Continue. Complete the subscription information for this service, and click Save and continue.

    - **Subscription** **type** – Select the subscription type for this service: **Trial** or **Subscription**. > ***Note**: For **Trial**, you can assign up to 5 customers, and the subscription expiration date is fixed. This number is calculated among all premium services. - **Source** – Select a value to indicate the source of your subscription. - **Payment type** – Select the payment type. - **Tenants** – Select the number of tenants you want to assign the subscription. - **Subscription expiration date** – By default, **Same as pooled** **subscription** is selected to keep the same expiration date as the pooled subscription. You can select **Expire now** or select **Specify a time** to set an expiration date for the customer’s subscription. - **Contract end date** – Click the calendar button and select the contract end date.

    *Note: Certain configurations in the baseline management service are not supported for tenants managed through Microsoft CSP integration. Refer to the following table for the detailed configurations.

    SourceConfigurationProperty
    Microsoft 365DeviceConditionalAccessPolicyComment
    Microsoft 365DeviceConditionalAccessPolicyEnabled
    Microsoft 365DeviceConditionalAccessPolicyName
    Microsoft 365 AdminOrgSettings > MicrosoftPlanner‎PlannerAllowCalendarSharing
    Microsoft 365 AdminOrgSettings > ReportsAdminCenterReportDisplayConcealedNames
    Microsoft Entra IDAuthenticationFlowsPolicySelfServiceSignUpEnabled
    Microsoft Entra IDB2BManagementPolicyInvitationsAllowedAndBlockedDomainsPolicy
    Microsoft Entra IDActivityBasedTimeoutPoliciesDisplayName (Key)
    Microsoft Entra IDActivityBasedTimeoutPoliciesId
    Microsoft Entra IDActivityBasedTimeoutPoliciesAzurePortalTimeOut
    Microsoft Entra IDActivityBasedTimeoutPoliciesDefaultTimeOut
    Microsoft Entra IDDirectorysettingsDisplayName
    Microsoft Entra IDDirectorysettingsId
    Microsoft Entra IDDirectorysettingsSettings
    Microsoft Entra IDDirectorysettingsTemplateId

    On the Integrations > Microsoft CSP > Tenants page, you can find the following information:

    - **Display name** – The display name of the Microsoft 365 tenant. - **Primary domain name** – The primary domain associated with the Microsoft 365 tenant. - **Microsoft ID** – The unique Microsoft-generated identifier for the Microsoft 365 tenant. - **Tenant** **status** **in Microsoft** **CSP** – The current tenant status within Microsoft CSP. - **Customer** – The customer account to which Microsoft 365 tenant belongs. - **Admin app consent** – The current authorization status of the admin app.

    To ensure regular updates, Elements automatically syncs tenants from Microsoft CSP partner accounts every day. If immediate synchronization is required, you can manually initiate the process by clicking Sync tenants.

    The following table lists the permissions required by the admin app pushed to the tenant.

    APIPermissionType
    Microsoft GraphApplication.ReadWrite.All(Read and write all applications)Delegated
    Microsoft GraphDeviceManagementApps.ReadWrite.All(Read and write Microsoft Intune apps)Delegated
    Microsoft GraphDeviceManagementManagedDevices.ReadWrite.All(Read and write Microsoft Intune devices)Delegated
    Microsoft GraphDeviceManagementRBAC.ReadWrite.All(Read and write Microsoft Intune RBAC settings)Delegated
    Microsoft GraphDirectory.ReadWrite.All(Read and write directory data)Delegated
    Microsoft GraphGroupMember.ReadWrite.All(Read and write group memberships)Delegated
    Microsoft GraphIdentityRiskEvent.ReadWrite.All(Read and write risk event information)Delegated
    Microsoft GraphIdentityRiskyServicePrincipal.ReadWrite.All(Read and write all identity risky service principal information)Delegated
    Microsoft GraphIdentityRiskyUser.ReadWrite.All(Read and write risky user information)Delegated
    Microsoft GraphOrganization.ReadWrite.All(Read and write organization information)Delegated
    Microsoft GraphOrganizationalBranding.ReadWrite.All(Read and write organizational branding information)Delegated
    Microsoft GraphPolicy.Read.All(Read your organization's policies)Delegated
    Microsoft GraphPolicy.ReadWrite.AccessReview(Read and write your organization's directory access review default policy)Delegated
    Microsoft GraphPolicy.ReadWrite.ApplicationConfiguration(Read and write your organization's application configuration policies)Delegated
    Microsoft GraphPolicy.ReadWrite.AuthenticationFlows(Read and write authentication flow policies)Delegated
    Microsoft GraphPolicy.ReadWrite.AuthenticationMethod(Read and write authentication method policies)Delegated
    Microsoft GraphPolicy.ReadWrite.Authorization(Read and write your organization's authorization policy)Delegated
    Microsoft GraphPolicy.ReadWrite.ConditionalAccess(Read and write your organization's conditional access policies)Delegated
    Microsoft GraphRoleManagement.ReadWrite.Directory(Read and write directory RBAC settings)Delegated
    Microsoft GraphUser.ReadWrite.All(Read and write all users' full profiles)Delegated
    Microsoft GraphPolicy.ReadWrite.DeviceConfiguration(Read and write your organization's device configuration policies)Delegated
    Microsoft GraphDeviceManagementServiceConfig.ReadWrite.All(Read and write Microsoft Intune configuration)Delegated
    Microsoft GraphDeviceManagementConfiguration.ReadWrite.All(Read and write Microsoft Intune Device Configuration and Policies)Delegated
    Microsoft GraphIdentityProvider.ReadWrite.All(Read and write identity providers)Delegated
    Microsoft GraphPolicy.ReadWrite.ExternalIdentities(Read and write your organization's external identities policy)Delegated
    Microsoft GraphRoleManagementPolicy.ReadWrite.Directory(Read, update, and delete all policies for privileged role assignments of your company's directory)Delegated
    Microsoft GraphPolicy.ReadWrite.CrossTenantAccess(Read and write your organization's cross tenant access policies)Delegated
    Microsoft GraphSharePointTenantSettings.ReadWrite.All(Read and change SharePoint and OneDrive tenant settings)Delegated
    Microsoft GraphOrgSettings-Forms.ReadWrite.All(Read and write organization-wide Microsoft Forms settings)Delegated
    Microsoft GraphOrgSettings-AppsAndServices.ReadWrite.All(Read and write organization-wide apps and services settings)Delegated
    Microsoft GraphOrgSettings-Todo.ReadWrite.All(Read and write organization-wide Microsoft To Do settings)Delegated
    Microsoft GraphReportSettings.ReadWrite.All(Read and write admin report settings)Delegated
    Microsoft GraphOrgSettings-Microsoft365Install.ReadWrite.All(Read and write organization-wide Microsoft 365 apps installation settings)Delegated
    Microsoft GraphOrgSettings-DynamicsVoice.ReadWrite.All(Read and write organization-wide Dynamics customer voice settings)Delegated
    Microsoft GraphPolicy.ReadWrite.MobilityManagement(Read and write your organization's mobility management policies)Delegated
    Microsoft GraphDirectory.AccessAsUser.All(Access directory as the signed in user)Delegated
    Microsoft GraphGroup.ReadWrite.All(Read and write all groups)Delegated
    Microsoft GraphAgreement.ReadWrite.All(Read and write all terms of use agreements)Delegated
    Microsoft GraphCustomSecAttributeDefinition.ReadWrite.All(Read and write custom security attribute definitions)Delegated
    Microsoft GraphSecurityEvents.Read.All(Read your organization’s security events)Delegated
    Office 365 Exchange OnlineExchange.Manage(Manage Exchange configuration)Delegated
    Office 365 SharePoint OnlineAllSites.FullControl(Have full control of all site collections)Delegated
    PowerApps ServiceUser(Access the PowerApps Service API)Delegated
    ProjectWorkManagementOrgSettings-Planner.ReadWrite.All(Read and write organization-wide Microsoft Planner settings)Delegated
    Skype and Teams Tenant Admin APIuser_impersonation(Access Microsoft Teams and Skype for Business data as the signed in user)Delegated