Browse documentation

Administration

Users, seats, and external guests

Know which identities consume active named-user capacity.

For
Administrators
Updated
August 11, 2026

Seat-counting rules

IdentityConsumes a seat?
Active human login accountYes
Administrator, operator, viewer, or regular userYes, when active
Login account flagged externalYes, when active
Disabled human accountNo
Service principal or API clientNo
Token-only package recipient or shared-inbox guestNo

Create, registration, directory provisioning, bulk import, and reactivation paths use the same active-seat check. Deactivating or deleting an active human account releases capacity.

When usage exceeds the limit

Existing users remain visible and active if an administrator lowers the configured limit below current usage. The system reports an over-limit state and blocks new active accounts and reactivation until usage is within capacity. It does not select users to deactivate automatically.