Delegated Administration for Partners Field Guide
Best practices and instructions for Zoom partners who use Delegated Account Access to manage their customers' Zoom accounts.
Overview
Zoom's Delegated Account Access feature allows partners to access and administer their customers' Zoom accounts without requiring shared credentials or a master/sub-account relationship. Partners and their customers operate as independent accounts, with the partner receiving controlled, permission-scoped access to each customer's environment.
This guide covers the recommended end-to-end setup process, ongoing account management, and current feature limitations that partners should understand before getting started.
Partner-Initiated Access Requests
Previously, delegated access could only be initiated by the customer — their account admin would navigate to Roles and invite an external (partner) user to their account. This workflow required customers to define roles and permissions themselves. See the Delegated Administration Field Guide for details about that process.
A new partner-initiated flow allows partners to send the access request directly to the customer, who then reviews and approves it.
Heads Up
If you have questions or issues accessing the partner-initiated flows, contact Partner Help through the Partner Portal.
Both flows (customer-initiated and partner-initiated) remain supported.
Before You Begin
Before configuring Delegated Account Access, confirm that your Zoom account has the feature enabled.
To verify, do the following:
Sign in to the Zoom web portal. In the left navigation, scroll to the Admin section and click User Management, Roles.

In the Role Name column, select the role used by the Administrators who will create customer relationships. For example, Admin or a custom role.
On the role screen that appears, go to the Account Management section. Make sure the External accounts field is selected. Note: By default, this role is disabled for everyone except the Owner role or unmodified, default Admin role.

Determine the appropriate action:
If the permission is not visible, contact your Zoom channel account manager to request this feature.
If the permission is visible and enabled, click Admin, Account Management, External Accounts. The Add an account button will be available.

You'll also need the following before you begin:
A licensed Zoom account for the user who will manage all customer relationships.
Which team members (MS, PSO, Support) will need access to each customer account.
The appropriate permission scopes for each customer engagement type. See Send an Access Request to Each Customer below.
Setup: Partner Side
Designate a Delegated Account Access Lead
Designate a single user—or a dedicated alias account, if permitted by your organization—to serve as your organization's Delegated Account Access Lead. This user will initiate and own all customer access relationships from the Account Management, External Accounts page.
This is important because only the user who initiates a customer relationship (the "creator") has full visibility into that specific relationship. A second creator can't see relationships created by the first creator unless they're explicitly added. Centralizing relationship creation in one account ensures your organization maintains a complete view of all supported customers.
To configure this user's permissions:
Sign in to the Zoom web portal as an account owner or admin.
Navigate to User Administration, Roles and create a new role. Name it something like Zoom Delegated Account Access Lead.

Under Account Management, enable Edit access for External Accounts.
Assign this role to your designated lead user.
Note
Managed Services, PSO, and Support team members do not require any admin permissions in your Zoom tenant. Only the lead initiating and managing customer relationships needs this role.
Create a Delegate Group for Each Customer
Create the user group(s) that will represent your team members for each engagement.
Navigate to User Management, Groups and create a new group. Name it to reflect the customer and/or service type (for example, Acme Corp – Managed Services Team).
Optional: Enable multi-factor authentication (MFA) to streamline customer account access.
See the following articles for more information.
Add the relevant MS, PSO, or Support team members to the group.
Current limitations to be aware of:
Only one group per customer relationship is supported. If you provide multiple service types (for example, both Managed Services and break-fix Support) to a single customer, create a single group that includes all relevant team members and apply the broadest necessary permission set.
Group membership in Zoom can be synced dynamically via SAML/SCIM. Groups assigned as managed delegates to customer relationships sync automatically to update delegate membership when group members change (additions or removals). For additional information about SAML, see:
We recommend leveraging Groups to manage delegates across customer relationships in order to more easily make centralized member adjustments.
Send an Access Request to Each Customer
The Delegated Account Access Lead performs this step for each customer.
Navigate to Account Management, External Accounts and click Add an account.

Enter the customer's account information and configure the following options:
Account contact: If possible, use the account owner email to ensure they receive the request. If your contact is not the owner, ensure their admin role already has the edit permission for Role Management enabled, otherwise they will not receive the request.
Expiration date: Set an end date if the engagement has a known term. Leave unchecked for ongoing support relationships.
Allow me to add delegates to manage the account: Enable this to allow your team members to be added under this relationship.
I will act as the point of contact and keep my delegates undisclosed: Enable this if you do not want your individual team members' names to appear in the customer's Roles, External Accounts view.
Allow delegates to open support tickets on behalf of this account: Enable this if you want to open Technical Support Tickets with Zoom Support for this account. If accepted, you will become their exclusive contact to Zoom Support and the customer will not be able to directly open Technical Support Tickets with Zoom Support.

Define the permission scope for this customer relationship. Only one role per partner-customer relationship is currently supported, so configure the superset of permissions your team will need across all service types for this customer. There are more than 230 granular options, with separate View and Edit controls. Recommended starting points:
Engagement TypeSuggested ApproachSupport / read-only troubleshooting
View access only for relevant areas
Full admin / managed services
Edit access across required areas
Product-specific (for example, Zoom Phone only)
Limit scope to that product area
Best practice: Avoid granting access to sensitive user content areas (for example, chat history, recordings, billing) unless explicitly required for the engagement.

Click Send add account request. Notify the customer to expect an approval email or direct them to Admin, User Management, Roles to approve from the banner notification in the web portal.


Add Delegates After Customer Approval
After the customer approves the request, the account will appear in the Approved tab of your External Accounts page.
Click the Delegates column of the customer's row, click the delegate number to add delegates.
Add individual users by name or email, and/or select the group created in the Create a Delegate Group for Each Customer section above.
All newly added delegates will have immediate access to manage the customer account. They will receive an email confirmation.
Managing Ongoing Changes
In the situation where a customer relationship ends, you have two options:
On the External Accounts page, click the … menu on the customer's row and select Remove access.
Ask the customer to delete the customer relationship from Admin, User Management, Roles.
Setup: Customer Side (Reference)
Customers don't need to initiate anything when the partner-initiated flow is used. After approving the partner's access request (via email or the banner in Admin, User Management, Roles), the relationship is active.
Customers can review active delegated relationships at any time under Admin, User Management, Roles (with external users).
Delegate Onboarding: Team Member Actions
Each team member added as a delegate must complete the following steps independently.
Sign in to zoom.us. In the left navigation, scroll to the Admin section, then click Account Management, External Accounts.
The page will list one row for each customer. Click Manage account in the Action column for the desired customer.
On the Verify to Continue prompt (optional, shown if MFA is not enabled for these users):
Click Send to receive a one-time verification code by email.
Enter the code and click Verify. Check spam if the email does not arrive promptly.
Upon successful verification, you will enter the customer's account in delegated admin mode, with the permissions configured by your organization's lead.
Last updated
Was this helpful?

