Configure business units and tenant scoping
Business units are the primary data isolation boundary within an account. Use them to limit the scope of access and operations.
Assign users to the narrowest set of business units required for their duties.
Prefer business unit scoped roles over account-scoped roles wherever the user's work is confined to one unit.
Scope certificate profiles, seats, and enrollments to specific business units so that operations can’t cross tenant boundaries.
Review business unit assignments whenever a user changes teams, and remove assignments promptly on role change.
Restrict the
Business unitspermission to users who require it. This permission can widen another user's effective access.