The Enterprise Portal has a handful of behaviors that are limitations on what local vs enterprise level admins can do. Many 'symptoms' occur because resources or configurations are associated to either the Enterprise or Organization level by design.
Likely Cause: Users and devices are org-bound by design. They cannot exist at the Enterprise Level.
Resolution: Switch to an Organization context via the Global Selector, then create the user or device within the appropriate organization.
Likely Cause: Enterprise Groups are automatically shared with all organizations. This is default behavior and cannot be restricted.
Resolution: Expected Behavior. If the group should only exist in specific orgs, create it as a Local Group at the org level instead.
Likely Cause: Enterprise Configuration scope grants access to all organizations automatically, with no exceptions.
Resolution: Expected Behavior. If an admin should not have visibility into certain orgs, do not grant them the Enterprise Configuration scope. Use org-level admin roles instead.
Likely Cause: Enterprise Resources are read-only at the org level.
Resolution: Expected Behavior. Local admins can associate groups to Enterprise Resources but cannot modify the resource configuration. Changes must be made by an Enterprise admin in the Enterprise level.
Likely Cause: Dynamic group rules and exception lists are managed exclusively at the Enterprise Level.
Resolution: Expected Behavior. The local admin must request changes through the Enterprise administrator. For local flexibility, consider creating a supplementary Local Group.
Likely Cause: These resources are only available in the Enterprise level.
Resolution: Switch to the Enterprise context via the Global Selector to manage Custom Roles and Service Accounts.
Likely Cause: The Enterprise Portal replaces the MTP entirely for enterprise tenants. There is no separate MTP login.
Resolution: Expected Behavior. All administration is done through the Enterprise Portal. Use the Global Selector to navigate between the Enterprise Level and individual organizations.
Likely Cause: The association was made in the Enterprise context between two Enterprise Resources.
Resolution: Expected Behavior. Enterprise-to-Enterprise associations can only be managed by Enterprise admins in the Enterprise configuration. The local admin can add additional group associations but cannot remove ones created at the Enterprise level.