Configure organization, domain, and federation settings
Prepare high-impact organization and identity-domain changes with ownership, verification, rollback, and tested sign-in paths.
Audience, roles, and scope
Admin organization, domain, and federation surfaces; DNS, identity-provider, and emergency-access configuration require their owning procedures.
Who this is for
- Tenant identity administrators
- Security owners
Roles
- Tenant administrator
- Identity administrator
Before you begin
- Approved change record
- Verified domain ownership
- Identity-provider metadata and tested rollback
- A protected emergency administrator path
Article tags
- organization
- domain
- federation
- identity
- sso
Procedures
Follow the sequence and stop when identity, authorization, target, or result differs from the article.
Prepare a domain or federation change
Test identity changes before broad enforcement.
- 1Plan and authorize
Document affected domains and users, owners, validation method, maintenance window, communications, rollback, and emergency access.
- 2Configure and test narrowly
Enter verified metadata, protect signing material, and test with designated non-critical accounts before enforcing broadly.
- 3Verify and monitor
Confirm sign-in, claims, logout, and recovery for intended users; monitor failures and execute rollback if thresholds are exceeded.
The organization or identity setting is validated without locking out administrators or misrouting tenant identities.
Security and data handling
- Use only the identity, tenant, role, and data scope approved for the task.
- Verify targets and expected effects before saving, sending, publishing, exporting, deleting, or approving.
- Keep secrets and regulated data out of screenshots, URLs, free-text diagnostics, and ordinary support messages.
- Handle federation certificates, secrets, and metadata through approved secret-management channels.
Known limitations
- The Admin interface cannot prove DNS propagation, external identity-provider correctness, or every application’s claim handling.
- Exact federation protocols and enforcement options depend on tenant configuration.
Troubleshooting
You cannot open Vianordis Admin
Likely cause: The session expired, the account is not entitled, or the required tenant or role claim is missing.
- Open the service through the approved Vianordis entry point and sign in again.
- Confirm the intended organization, tenant, and account are in use.
- If access remains denied, record the time and request an entitlement check; do not attempt direct-URL bypasses.
A documented control or navigation item is not visible
Likely cause: The current role, subscription, tenant configuration, release status, or feature flag does not expose it.
- Confirm the audience, role, prerequisites, and limitations in this article.
- Refresh after a new sign-in and verify the correct tenant context.
- Ask the responsible administrator whether the capability is enabled before reporting a defect.
A saved change or background result is not visible
Likely cause: Validation failed, processing is incomplete, the view is stale, or the feature is locally simulated rather than persisted.
- Review inline validation, status indicators, filters, and the selected tenant or workspace.
- Refresh once and search by a stable identifier before repeating the action.
- Do not repeat irreversible or externally visible actions until the first operation's state is known.
Source verification
Organization, domain, and federation navigation and forms were reviewed in the pinned source.
Reviewed paths at 8f3a86e
src/app/(base)/settings/organisation/OrganisationView.tsxsrc/app/(base)/settings/domain/page.tsxsrc/app/(base)/settings/federation/FederationView.tsxsrc/database/federation.ts
Contact support
Contact support when
- A repeatable Vianordis Admin error blocks an approved task
- Expected access, tenant scope, data, or status appears incorrect
- A security, privacy, financial, compliance, or data-loss concern is suspected
Include
- The page, action, expected result, and exact error text
- The time of occurrence with time zone and whether it is reproducible
- Your tenant, role, browser, and sanitized record or correlation identifier
- The troubleshooting steps already completed
Never include
- Passwords, access tokens, API keys, recovery codes, session cookies, or private keys
- Unredacted personal, financial, health, student, employee, or other regulated data
- Confidential documents or message bodies unless support provides an approved secure channel