Microsoft Entra ID allows you to create several types of users in your tenant, which provides greater flexibility in how you manage your organization's users.
This article explains how to create a new user, invite an external guest, and delete a user in your workforce tenant. It also includes information about creating users in an external tenant for Microsoft Entra External ID scenarios.
Types of usersBefore you create or invite a new user, take some time to review the types of users, their authentication methods, and their access within your Microsoft Entra workforce tenant. For example, do you need to create an internal guest, an internal user, or an external guest? Does your new user need guest or member privileges?
Users in workforce tenantsA Microsoft Entra workforce tenant has the following user types:
For more information about the differences between internal and external guests and members, see B2B collaboration properties.
Authentication methods vary based on the type of user you create. Internal guests and members have credentials in your Microsoft Entra tenant that can be managed by administrators. These users can also reset their own password. External members authenticate to their home Microsoft Entra tenant and your Microsoft Entra tenant authenticates the user through a federated sign-in with the external member's Microsoft Entra tenant. If external members forget their password, the administrator in their Microsoft Entra tenant can reset their password. External guests set up their own password using the link they receive in email when their account is created.
Reviewing the default user permissions may also help you determine the type of user you need to create. For more information, see Set default user permissions.
Users in external tenantsA Microsoft Entra tenant in an external configuration is used exclusively for Microsoft Entra External ID scenarios. An external tenant can include the following user types:
For more information, see Default user permissions for external tenants.
PrerequisitesThe required role of least privilege varies based on the type of user you're adding and if you need to assign Microsoft Entra roles at the same time. Whenever possible you should use the least privileged role.
Task Role Create a new user User Administrator Invite an external guest Guest Inviter Assign Microsoft Entra roles Privileged Role Administrator Create a new userFollow these steps:
Sign in to the Microsoft Entra admin center as at least a User Administrator.
Browse to Entra ID > Users.
Select New user > Create new user.
Complete the remaining tabs in the New user page.
BasicsThe Basics tab contains the core fields required to create a new user. Before you begin, review the guidance on user name properties.
Either select the Review + create button to create the new user or Next: Properties to complete the next section.
Either select the Review + create button to create the new user or Next: Properties to complete the next section.
PropertiesThere are six categories of user properties you can provide. These properties can be added or updated after the user is created. To manage these details, go to Entra ID > Users and select a user to update.
Either select the Review + create button to create the new user or Next: Assignments to complete the next section.
AssignmentsYou can assign the user to an administrative unit, group, or Microsoft Entra role when the account is created. You can assign the user to up to 20 groups or roles. You can only assign the user to one administrative unit. Assignments can be added after the user is created.
To assign a group to the new user:
To assign a role to the new user:
To add an administrative unit to the new user:
The final tab captures several key details from the user creation process. Review the details and select the Create button if everything looks good.
Sign in to the Microsoft Entra admin center as at least a User Administrator.
Make sure you're signed in to your external tenant. Use the Settings icon in the top menu to switch to your external tenant from the Directories + subscriptions menu.
Browse to Entra ID > Users.
Select New user > Create new external user.
On the Create new user page, complete the Basics tab as described earlier in this article, but with these variations:
(Optional) Select Next: Properties. Complete the Properties tab as described earlier in this article, but note these variations:
(Optional) Select Next: Assignments. Complete the Assignments tab as described earlier in this article, but note that the Add administrative unit and Add role options are unavailable for external users.
Select the Review + create button to create the new user.
The overall process for inviting an external guest user is similar, except for a few details on the Basics tab and the email invitation process. You can't assign external users to administrative units.
Note
This feature applies to both workforce and external tenants, but is currently in preview for external tenants.
Sign in to the Microsoft Entra admin center as at least a User Administrator.
Browse to Entra ID > Users.
Select New user > Invite external user.
Complete the remaining tabs in the New user page (as shown below).
Basics for external usersIn this section, you're inviting the guest to your tenant using their email address. If you need to create a guest user with a domain account, use the create new user process but change the User type to Guest.
Guest user invitations
When you invite an external guest user by sending an email invitation, you can check the status of the invitation from the user's details.
Add other users
There might be scenarios in which you want to manually create consumer accounts in your Azure Active Directory B2C (Azure AD B2C) directory. For more information about creating consumer accounts, see Create and delete consumer users in Azure AD B2C.
If you have an environment with both Microsoft Entra ID (cloud) and Windows Server Active Directory (on-premises), you can add new users by syncing the existing user account data. For more information about hybrid environments and users, see Integrate your on-premises directories with Microsoft Entra ID.
You can delete an existing user using the Microsoft Entra admin center.
You must have at least the User Administrator role assignment to delete users in your organization.
Those with the Privileged Authentication Administrator role can delete any users including other administrators.
User Administrators can delete any non-admin users, Helpdesk Administrators, and other User Administrators.
For more information, see Administrator role permissions in Microsoft Entra ID.
To delete a user, follow these steps:
The user is deleted and no longer appears on the All users page. The user can be seen on the Deleted users page for the next 30 days and can be restored during that time. For more information about restoring a user, see Restore or remove a recently deleted user using Microsoft Entra ID.
When a user is deleted, any licenses consumed by the user are made available for other users.
Note
To update the identity, contact information, or job information for users whose source of authority is Windows Server Active Directory, you must use Windows Server Active Directory. After you complete the update, you must wait for the next synchronization cycle to complete before you'll see the changes.
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4