Skip to main content

Configure business units and tenant scoping

Business units are the primary data isolation boundary within an account. Use them to limit the scope of access and operations.

  • Assign users to the narrowest set of business units required for their duties.

  • Prefer business unit scoped roles over account-scoped roles wherever the user's work is confined to one unit.

  • Scope certificate profiles, seats, and enrollments to specific business units so that operations can’t cross tenant boundaries.

  • Review business unit assignments whenever a user changes teams, and remove assignments promptly on role change.

  • Restrict the Business units permission to users who require it. This permission can widen another user's effective access.