Organization
The active tenant's Microsoft 365 organization profile: name, tenant ID, address, and business phones. These fields are read-only — Microsoft Graph's organization endpoint does not accept changes to identity or address, so a button, Edit organization profile in Microsoft 365, opens the admin center page where that is actually done rather than pretending a save here would work.
Two things on this page are editable, because Graph does support writing them:
- Notification contacts — the technical, marketing and security notification email addresses, and security notification phone numbers, one value per line.
- Privacy profile — a contact email address and a statement URL.
Saving needs Organization.ReadWrite.All, which is in the baseline permission set
— see Sign-in & permissions. Only the fields you actually
changed are sent, and the whole profile is re-read afterwards in case another administrator
changed something else in the meantime. A refusal here is a permission problem, not data — the
app tells you which.
Domains
Every domain Microsoft 365 has verified for the tenant: the domain name, whether it is the
Default domain, whether it is the tenant's original Initial
.onmicrosoft.com domain, its authentication Type (Managed or
Federated), and which Services are enabled on it (for example, Email).
This list is entirely read-only — there is no row action and nothing to double-click. Adding or verifying a domain is a Microsoft 365 admin center task, and this page exists to state the facts, not to edit them. It is read once per tenant and kept; a Refresh button re-reads it, and it clears on a tenant switch or sign-out.
Licenses
The licence SKUs your tenant holds, with the totals. Edit drills into the users holding that licence, annotated with how each one holds it — Direct, Group, or Direct + group, since a user can hold the same SKU both ways at once. That column is the quickest way to find out why removing a licence from someone did not take effect.
Editing a user from here jumps to their card on the Users page, with a way back.
Roles
The catalogue of directory (admin) roles, with a member count against each, and a filter for assigned versus not assigned — which answers "who has admin rights here?" in one screen. Edit opens a role's members, where you can add and remove them.
The list covers the whole catalogue, not only roles somebody already holds. Assigning a role nobody in the tenant holds yet also activates it, which is a one-way, tenant-wide change, so the confirmation says so.
Only direct, active assignments are counted and shown. A PIM-eligible assignment is not a membership, and a role held through a role-assignable group belongs to the group — so neither appears here. If a count looks lower than you expect, that is usually why.
A member the current token cannot fully read is still listed, by whatever identifier is available: an administrator you cannot name still holds the role, and dropping the row would be worse than showing a partial one. Where a count could not be established the cell is left blank rather than zero — "could not ask" and "nobody" are different answers.
Removing your own role is allowed but warns you first, since any other Privileged Role Administrator can undo it. Two removals Microsoft refuses outright, whatever you hold: the last Global Administrator, and an assignment that is not a direct membership.
Your access
The admin roles you — the signed-in account — personally hold in the active tenant. This is deliberately not called "Roles": Tenant ▸ Roles is the tenant's whole role catalogue and who holds each one, a different page about different objects. Two entries named Roles would read as the same page twice.
What the list means changes with where you are signed in. At home, it is simply the account's own role assignments. Inside a delegated customer tenant, it is what that GDAP relationship delegates to your partner group — see Delegated administration. A line above the list states which one you're looking at, since nothing about the rows themselves would otherwise say so.
Only active, direct assignments are shown — the same rule Tenant ▸ Roles follows. A PIM-eligible assignment is not a membership, and a role held through a role-assignable group belongs to the group, so neither appears here. This page has no row action either: changing who holds a role is done on Tenant ▸ Roles, while assigning a partner security group to an approved customer role is done on Partner ▸ Relationships (GDAP).