Skip to main content
Tenant Settings controls organization-wide configuration including company details, custom domains, branding, and security options. Access depends on your tenant-settings permissions; individual actions can require additional management access.

Accessing Tenant Settings

  1. Click Settings in the sidebar
  2. Select Tenant from the settings navigation
Tenant Settings is organized into three tabs: Details, AI, and Branding.

Save behavior

Use the header Save Settings for the main form, including Details, AI and custom-domain login-method choices. Wait for the saved result before leaving. Header Reset restores the form’s saved baseline; it is not a saved undo of earlier changes. Logo uploads, Save color, location changes, custom-domain actions and Save sign-in page are separate persisted operations. Inspect the result of the action you used; the header cannot discard an upload or domain change that already succeeded.

Tenant Details

Basic organization information:

Locations and preferences

Review Locations on Details. Create or edit a location in its own dialog, save it there and check the resulting record. Setting a primary location and deleting a location use their own actions; check the target location and any confirmation. These changes are separate from the header form save. Review the timezone, language/locale and currency preferences offered in Details. Save form changes with Save Settings. The data-residency card reports stored-data and application-serving regions; it does not move the tenant’s data or offer a region-change control.

Tenant Security Settings

Restrict to Assigned Companies

When enabled:
  • Users only see data for companies they’re explicitly assigned to
  • Improves data isolation between teams
  • Requires company assignments in user management
Roles with Bypass Company Restrictions enabled will still have access to all companies.

AI Settings

The AI tab controls AI-powered features for your organization. Two independent switches let you decide who gets AI: everyone, only your internal team, or no one.

AI Features (Master Switch)

The Enable all AI-powered features switch turns AI on or off for your entire organization. When disabled, users cannot generate new AI content. Review the affected AI controls and workflows after saving. This switch is not a record-deletion operation or evidence that every already-running background task has stopped.

Client-facing AI

The Enable AI features for client users switch controls whether your client (company) users get AI-powered features. When disabled, client users see a non-AI experience while your internal team can continue using AI.
Both switches are enabled by default. The client-facing switch is only available while the master switch is on: turning off the master switch disables AI for everyone, including client users.
After changing either switch, click Save Settings to apply. The General section also contains the AI-Powered Home Page global toggle. The Context section lets you provide business context and contact information the AI assistant can use.

Customize the AI Home welcome screen

Use Settings > Tenant > AI > Home page to set the background, greeting, and quick-action blocks shown on AI Home. You need permission to manage Tenant Settings to edit these controls. To see the result on Home, AI features and AI-Powered Home Page must be enabled for the viewer. For a company user, AI Home must also be enabled for that company.
1

Open Home page settings

Go to Settings > Tenant, select AI, then select Home page inside the AI card. The right-hand preview shows sample welcome text and blocks as you edit.
2

Upload a background image

Under Background image, click Upload image and choose a JPG (or JPEG), PNG, or WebP file no larger than 3 MB. Wait for the upload confirmation and check the image preview. A large landscape image, such as 1920 × 1080 pixels, is a useful starting point; that size is a recommendation, not an upload requirement. The image fills the welcome area and crops around the center on narrower screens. A light or dark overlay keeps the greeting readable, so choose a simple image without important text near its edges.
3

Personalize the welcome text

In Phrasing, edit Greeting label, Headline, Subheadline, and Text entry placeholder. You can include {greeting}, {name}, {tenantName}, or {portalName}. For example, use {greeting} for the label, {name} for the headline, and How can we help today? for the subheadline. Empty fields use the standard welcome text.
4

Set the shortcut blocks

Under Blocks under the text entry, click Add block. Give each block a Label, choose an Icon, and optionally add a Description. Enter the Prompt sent to AI that should start when someone selects the block. For example, label a block Open a support ticket and set its prompt to I want to open a support request. You can add up to four blocks; custom blocks replace the default quick actions.
5

Save and check Home

Review the sample preview, then click Save Settings in the page header. The Save button on a block also saves the tenant settings form. Open Home with an account for which AI Home is enabled, and check the background and text on both desktop and phone widths. The sample preview is illustrative; the live greeting uses the viewer’s name and time of day.
AI Home settings showing an uploaded background image, personalized welcome phrasing, shortcut blocks, and sample preview.

Example AI Home settings with a background, personalized welcome, and shortcut blocks.

To remove the image, click Remove image, then Save Settings. To restore the standard phrasing and quick actions, click Reset to default, then Save Settings. Check the live Home page after saving; the preview uses example content and only shows two blocks at once.

Custom Domains

Configure custom domains to access MSPortal with your own branding. Custom domains are managed in the Domains card on the Branding tab.

Adding a Custom Domain

1

Enter Domain

Type your custom domain (e.g., portal.yourcompany.com)
2

Copy CNAME Target

Copy the provided CNAME target value
3

Update DNS

Add a CNAME record with your DNS provider pointing to the target
4

Verify Domain

Click Re-check to verify DNS propagation
5

Set Primary

Optionally mark as primary domain
Domain creation and Set Primary save independently of the header form. Re-check retrieves and can update verification status. Inspect the returned state before sharing the domain; waiting or returning to the page is not proof that DNS is active.

Domain Status

Sign-In Methods for Custom Domains

Choose which sign-in options appear on the sign-in page of your custom domains. The Custom domain login methods section sits below the domain list in the Domains card, with a checkbox for each method:
  • Sign in with Microsoft
  • Sign in with Google
  • Send Magic Link (email sign-in link)
Uncheck a method to remove it from the sign-in page of your custom domains, so the page shows only the options your organization actually uses. Click Save Settings at the top of the page to apply your changes.
At least one sign-in method must remain enabled, so the last enabled method cannot be turned off. These choices only affect your custom domains: MSPortal domains keep all sign-in methods available.

Enhanced Branding

Customize your organization’s branding:
Tenant branding color controls and light/dark sample previews.

Current Tenant Branding controls with separate Save color and built-in light/dark previews.

Brand Color

Set your primary brand color, used for buttons, links, sidebar highlights, and other branded UI across the app.
1

Open the Colors Section

In the Branding card, open the Colors section.
2

Pick Your Color

Use the color picker or type a hex code into the input. Short hex values such as #0e9 and full six-digit hex such as #7c3aed are both accepted.
3

Preview in Light and Dark Mode

Preview cards show how buttons, sidebar items, badges, and links will look in both light and dark themes. The dark-mode variant is generated automatically from your chosen color.
4

Save

Click Save color and wait for confirmation. Review the resulting light and dark previews and reload a portal page to check the saved brand.
The Reset button restores the default MSPortal teal color. You will be prompted to confirm before reverting.
Where the brand color appears:
  • Primary buttons and call-to-action buttons
  • Links and link hover states
  • Sidebar active item highlights
  • Focus rings and selection highlights
  • Chart primary color
  • Status badges that use the brand scale

Client Onboarding Portal Branding

Your brand color automatically applies to the public client onboarding portal as well. When a client opens their onboarding link, the portal uses your tenant’s colors and logo so it feels like part of your brand, not a generic page. No separate configuration is needed.

Logo Options

Custom Sign-In Page

Use the Sign-In Page section to customize the first page clients see when they visit one of your custom domains. These settings do not change the sign-in page on MSPortal-owned domains.

Prerequisites

  • An active custom domain
  • Access to manage Tenant Settings or Launch Center settings
  • A primary light logo uploaded under Branding > Light if you want your logo on the sign-in card
1

Open Sign-In Page settings

Go to Settings > Tenant > Branding, then select Sign-In Page in the Branding card.
2

Set the logo size

Move the Logo size slider until the logo fits the sign-in card. The preview updates as you make changes.
3

Choose a background

Select Default, Solid color, Gradient, or Image.For an image, upload a PNG, JPG, or WEBP file up to 3 MB. See Background image requirements below for recommended dimensions and tips for choosing an image. Use Photo darkening to keep the sign-in card readable over a bright image.
4

Choose the card style

Enable Frosted glass card to make the card slightly transparent with a blur effect. The glass effect appears when you use a custom color, gradient, or image background.
5

Write the welcome message

Enter a Welcome title and Welcome subtitle. Leave either field blank to use the standard MSPortal sign-in copy. Review any help instructions as public-facing text; do not include private support details or credentials.
6

Preview and save

Uploading a background prepares a draft asset; use Save sign-in page to apply the draft configuration. Review the preview, then click Save sign-in page. Open the custom domain in a signed-out or private browser window to verify the complete sign-in experience.
The custom-domain sign-in page also uses your primary logo, favicon, tenant color palette, and the sign-in methods selected under Branding > Domains.
To remove the custom background, card style, logo size, and welcome copy, click Reset to default and confirm. Your uploaded tenant logo, favicon, brand colors, and custom domain remain unchanged.

Background image requirements

When adding your own sign-in background, use these specifications: The dimensions are a recommendation, not a minimum upload requirement. If your image is larger than 3 MB, compress it or export a smaller copy before uploading. Your image fills the page behind the centered sign-in card. It stays centered and crops at the edges to fit the screen, so phones may show much less of the image’s sides than a desktop does.
  • Choose an image with a simple background so the sign-in card is easy to read.
  • Avoid text or important details in the image: the card covers the center, and the edges may be cropped. Use your separately uploaded tenant logo for branding on the card.
  • Adjust Photo darkening if the background is too bright.
  • After clicking Save sign-in page, check your custom domain in a signed-out or private browser window on both a desktop and a phone.

Sign-In Page Troubleshooting

Upload and crop

Use the format and size limits shown by the selected upload control. For logos, confirm the crop and wait for the upload result; closing the cropper is not a save. Favicon and reporting-logo uploads have their own behavior. Review light and dark variants separately.

Best Practices

  • Complete all branding - Upload all logo variants for consistent appearance
  • Test custom domains - Verify domains work before sharing with users
  • Document settings - Record configuration for disaster recovery
  • Review periodically - Update branding when company details change

FAQs

No. Header Reset restores the main form baseline; dedicated uploads and domain actions persist separately.
No. The upload prepares a draft asset; apply the configuration with Save sign-in page.
No. The card is informational and has no data-region change control.
Use the header Save Settings, keeping at least one sign-in method enabled.
No. The color control confirms and saves a return to the default palette; header Reset concerns the main form.