Troubleshoot: Enterprise Portal (Preview)

The Enterprise Portal has a handful of behaviors that are limitations on what local vs enterprise level admins can do. Many 'symptoms' occur because resources or configurations are associated to either the Enterprise or Organization level by design.

Admin cannot create users or devices in the Enterprise Portal

Likely Cause: Users and devices are org-bound by design. They cannot exist at the Enterprise Level.

Resolution: Switch to an Organization context via the Global Selector, then create the user or device within the appropriate organization.

Enterprise Group appears in all organizations, even those that shouldn’t have it

Likely Cause: Enterprise Groups are automatically shared with all organizations. This is default behavior and cannot be restricted.

Resolution: Expected Behavior. If the group should only exist in specific orgs, create it as a Local Group at the org level instead.

Admin with Enterprise Configuration scope can see all organizations, including restricted ones

Likely Cause: Enterprise Configuration scope grants access to all organizations automatically, with no exceptions.

Resolution: Expected Behavior. If an admin should not have visibility into certain orgs, do not grant them the Enterprise Configuration scope. Use org-level admin roles instead.

Local admin cannot edit an Enterprise Resource (SSO app, group config, policy)

Likely Cause: Enterprise Resources are read-only at the org level.

Resolution: Expected Behavior. Local admins can associate groups to Enterprise Resources but cannot modify the resource configuration. Changes must be made by an Enterprise admin in the Enterprise level.

Local admin cannot modify dynamic group exception lists for an Enterprise Group

Likely Cause: Dynamic group rules and exception lists are managed exclusively at the Enterprise Level.

Resolution: Expected Behavior. The local admin must request changes through the Enterprise administrator. For local flexibility, consider creating a supplementary Local Group.

Custom Roles or Service Accounts not visible in organization context

Likely Cause: These resources are only available in the Enterprise level.

Resolution: Switch to the Enterprise context via the Global Selector to manage Custom Roles and Service Accounts.

Admin tries to access Multi-Tenant Portal but is redirected to Enterprise Portal

Likely Cause: The Enterprise Portal replaces the MTP entirely for enterprise tenants. There is no separate MTP login.

Resolution: Expected Behavior. All administration is done through the Enterprise Portal. Use the Global Selector to navigate between the Enterprise Level and individual organizations.

Local admin cannot remove an Enterprise Group association from an Enterprise SSO application

Likely Cause: The association was made in the Enterprise context between two Enterprise Resources.

Resolution: Expected Behavior. Enterprise-to-Enterprise associations can only be managed by Enterprise admins in the Enterprise configuration. The local admin can add additional group associations but cannot remove ones created at the Enterprise level.

Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case