Access On Behalf Of Feature on Tenant Environment
the on behalf of feature enables the management of tenants via sso when a tenant is created in a multi tenant environment without this feature, the tenant admin has to create some users on the tenant environment, or integrate with ldapor microsoft entra id, to give those users some rights for management purposes using the on behalf of feature, the tenant can easily be managed with the administrative accounts assigned by the host's admin users the access on behalf of users are used on both the tenant and the host environments and are able to switch between different tenants (tenant to tenant, tenant to host or host to tenant) to manage them when defining the necessary rights on the tenant sides to enable this feature navigate to administration > tenant manager click the tenant's logo at the bottom of the pop up, slide the toggle to the right to enable access on behalf of the tenant after enabling this feature for the tenant, the host's admin user who manages the tenant needs the necessary rights on the tenant system please refer to user management docid\ wvmzfudyxl1sslw4d7xo1 for details on how the host's admin users assign tenant's admin user right to select “access on behalf users”, ldapdatacollectorjob should be triggered on the tenant environment (either manually or in the predefined time) this job selects access on behalf of users for the tenant from ldap or microsoft entra id integration defined in the host environment, if the tenant creation screen has blank group and user search phrases from the tenant creation screen, if the tenant creation screen has non empty group and user search phrases aioc hide on behalf of tenant switch system config parameter is used in both tenant and host environmentsfor hiding the tenant to switch feature if the parameter is set as true the default value of this parameter is false , which means that until this parameter is set as true, the access on behalf feature is used as in the usual scenario this parameter also affects the desktop client for the tenant switch feature