Request directory access

Last updated on Aug 3, 2026

Learn how to request access to shared directories, monitor request status, and manage trustee relationships in Admin Console.

Directory trust lets multiple organizations share user authentication for a single domain. When one organization claims a domain, other organizations can request trustee access to the directory containing it. System Administrators in both organizations manage these access relationships through the Admin Console.

Requesting organizations (trustees) can request access to directories they need, check the status of pending requests, or withdraw from established trust relationships. Owning organizations can approve or reject incoming requests and revoke access from existing trustees.

Prerequisites

You need:

  • System administrator role for the Admin Console
  • Exported user list from the Admin Console that preserves data, profiles, and roles for rollback

Request directory access (requesting organization)

When you add an existing domain to your Admin Console, you're prompted to request access to the directory that owns the domain.

Go to Settings > Identity in the Admin Console.

Add the domain you need to access.

Review the notification that shows which information will be shared: your name, email, and organization name.

Select the option to request access to the directory.

Access request confirmation
Select Request Access.

Your access request is sent to the owning organization's System Administrators. You don't need to configure the domain. When they approve your request, the owner's existing identity setup applies.

Check request status (requesting organization)

Sign in to the Admin Console and go to Settings > Identity.

Select the Access Requests tab.

Review the status displayed for each directory access request in the list.

Select a request from the list to view its details and access options to resend or cancel it.

When the owning organization approves your request, you receive an email notification. The approved request moves from the Access Requests tab to your Directories list with an Active trusted status. Go ahead and add users and user groups and assign them to product profiles.

Withdraw trustee status (requesting organization)

Sign in to the Admin Console and go to Settings > Identity.

Select the Directories tab.

Select the shared directory from which you want to withdraw access.

In the directory details drawer, select Withdraw.

Confirm the withdrawal action.

Alert

Withdrawing access removes all users associated with domains in that directory from your organization. Users retain access to their assigned apps, services, and storage. To revoke software access, select Users > Remove users, then reclaim their assets through asset reclamation.