Change a client user's portal role
How to move a client's portal user between Primary Contact, IT Admin, and Billing from the client record itself, and how to confirm the change actually took.
What you will have
- See every person with elevated access on a client's portal, plus the client's own owner.
- Move one person between Primary Contact, IT Admin, and Billing.
- Confirm the new role stuck, on a fresh page load and in the audit trail.
Why it works this way
Portal roles live on the User record itself, not on a Microsoft 365 group. Microsoft 365 groups are no longer used for permission assignment, so a role change here takes effect immediately and does not wait on any directory sync.
This list only shows people with elevated access, plus the client's owner. Everyone else who signs in on this client's domain still gets basic read access by default; they never need a role from this screen to see their own tickets and documents.
Steps
Open the client record and go to Users > Portal Access.
Portal Access sits under Users, next to Contacts. Contacts are manual records for billing, tickets, and meetings; nobody signs in on the strength of being listed there. Portal Access is the one screen that actually grants a sign-in role.
Open the client record and go to Users > Portal Access. Find the person's row and read their current role.
The Portal Users panel lists the client's owner first, badged Owner and Full Access, then every other elevated user with their role in a dropdown. Here, KB walk - safe to delete is elevated to Billing.
Find the person's row and read their current role. Open the dropdown and pick the new role.
The dropdown offers exactly three roles: Primary Contact, IT Admin, and Billing (plus any custom client-scoped permission group your instance has configured; this client has none). Picking one saves right away, with no separate Save button.
Note: Owner is not one of the choices here. It belongs only to whoever is named under Edit > Primary Contact on the client record, and that person's row shows a fixed Owner and Full Access badge instead of this dropdown.Open the dropdown and pick the new role. Reload the page and check the role again.
The row still reads IT Admin after a full page reload, confirming the change is stored on the person's account and was not just a screen that reset itself.
Reload the page and check the role again. Open Logs > Audit to see the change on record.
The newest entry names the action USER_ROLE_CHANGED, the person, who made the change and when, and expands to show the exact before-and-after value, role BILLING to IT_ADMIN here, plus the organization the change happened on.
Open Logs > Audit to see the change on record.
If it did not work
- If the person isn't listed here yet, they have no elevated role. Use Add User above the list to search their contact or email and grant one; this also creates the audit record in one step.
- If you need to change who the client's owner is, that's Edit > Primary Contact on the client record itself, not a role on this list.
Questions this page answers
How are portal user roles managed?
Portal user roles (Primary Contact, IT Admin, Billing, and User) are managed by admins on each client's Users tab, under Portal Access. M365 groups are no longer used for permission assignment. Admins set each user's role directly, and the role determines the access tier for every section.
Was this helpful?