# Configuring access for accounts

> As an administrator, you can configure fine-grained tenant or folder permissions for objects that already exist at the organization level (i.e. groups, users, robot accounts, external apps), via Orchestrator, by assigning them to tenants or folders in Orchestrator. An object gets the permissions required to perform particular operations in a tenant or folder through one or more roles.

As an administrator, you can configure fine-grained tenant or folder permissions for objects that already exist at the organization level (i.e. groups, users, robot accounts, external apps), via Orchestrator, by assigning them to tenants or folders in Orchestrator. An object gets the permissions required to perform particular operations in a tenant or folder through one or more roles.

You can use groups to simplify access control, as groups allow you to manage objects with similar needs together.

## Overview

As an administrator, you can configure fine-grained tenant or folder permissions for accounts that already exist at the organization level, via Orchestrator, by assigning them to folders or tenants in Orchestrator. An account gets the permissions required to perform particular operations in a folder or tenant through one or more roles.

You can use groups to simplify account management, as groups allow you to manage accounts with similar needs together.

## Adding Accounts to a Tenant

To give tenant access to accounts or groups, follow these steps:

1. Go to **Tenant** &gt; **Manage Access**. The **Manage Access** page is displayed.
2. Click **Assign roles** &gt; **User**/**Robot Account**/**Group** to add a new account in the tenant. The **Assign roles** window is displayed.
3. In the **Search for user/robot account/group** drop-down, search for the object you want to add.
4. Under **Roles**, select the role(s) for this object.
5. Click **Assign**. The selected object can access tenant resources according to its role.

## Adding Accounts to a Folder

To give folder access to accounts or groups, follow these steps:

1. Go to **Tenant** &gt; **Folders**. The **Folders** page is displayed.
2. From the **Folders** page, in the **Manage Folders** pane, click the folder you want to manage. The folder and its contents are displayed on the right-hand dashboard.
3. Click **Assign Accounts/Group** to add a new account or group in the folder. The **Assign Account/Group** window is displayed.
4. In the **Account, group, or external app** drop-down, search for the object you want to add.
5. Under **The Roles for the account/group selected above**, select the role(s) for this object.
6. Click **Assign**. The selected object is now in the folder and can access it according to its role.

## Removing Account Assignments

### Unassigning Accounts From a Tenant

To remove tenant access for accounts or groups, follow these steps:

1. Go to **Tenant** &gt; **Manage Access**. The **Manage Access** page is displayed.
2. Click **More Actions** &gt; **Unassign** for the account you want to remove from the tenant. A confirmation window is displayed.
3. Click **Yes** to confirm. The removed account or group is removed and loses access to the tenant.## Removing folder access

### Unassigning Accounts From a Folder

To remove folder access for accounts or groups, follow these steps:

1. Go to **Tenant** &gt; **Folders**. The **Folders** page is displayed.
2. From the **Folders** page, in the **Manage Folders** pane, click the folder you want to manage. The folder and its accounts are displayed on the right-hand dashboard.
3. Click **More Actions** &gt; **Unassign** for the account or group you want to remove from the folder. A confirmation window is displayed.
4. Click **Yes** to confirm. The removed account or group is removed and loses access to the folder.

   :::important
   Accounts part of [account-machine mappings](configuring-account-machine-mappings.md) that are employed in triggers cannot be deleted or unassigned from the folder in which the trigger resides. Make sure the account is not set as an execution target in a trigger to be able to delete it.
   :::
