Administration
Users, seats, and external guests
Know which identities consume active named-user capacity.
- For
- Administrators
- Updated
- August 11, 2026
Seat-counting rules
| Identity | Consumes a seat? |
|---|---|
| Active human login account | Yes |
| Administrator, operator, viewer, or regular user | Yes, when active |
| Login account flagged external | Yes, when active |
| Disabled human account | No |
| Service principal or API client | No |
| Token-only package recipient or shared-inbox guest | No |
Create, registration, directory provisioning, bulk import, and reactivation paths use the same active-seat check. Deactivating or deleting an active human account releases capacity.
When usage exceeds the limit
Existing users remain visible and active if an administrator lowers the configured limit below current usage. The system reports an over-limit state and blocks new active accounts and reactivation until usage is within capacity. It does not select users to deactivate automatically.
