An account area your members can manage
A member opens your app's account settings with a small job in mind: replace an old email address. While they're there, they want to check how they sign in and whether their recovery options are ready.
For organization-owned tenant members, that is a useful place to bring account controls together, separate from consumer account settings. M7's documented browser-direct tenant operations give app builders the pieces for that screen: profile details, email addresses, passwords, linked providers and security settings. The controls available depend on the member's sign-in methods, your app's registered scopes and the organization's policy. Confirm those capabilities in your integration before offering them to members.
Start with the ordinary changes
Imagine Maya using a project app for her organization. Her account screen brings together profile and email controls: display name, avatar and email addresses, with verification and primary-address labels.
She can edit the display name and avatar when the app has the profile scope. Her system login name stays the same. For her replacement email, the app needs the email scope and a clear sequence: add the address, explicitly request a verification code, verify it, then choose the verified active address as primary. Adding it alone neither sends the message nor proves ownership.
Once the replacement is primary, Maya can remove the old address if the account's safeguards permit it. The final verified address is protected. These self-service profile and email edits keep her sessions, so she can return to her project without another sign-in.
Show the sign-in choices that fit
The same screen should explain where Maya's password is managed. A native tenant password can be changed using the current password. An eligible member who signs in through a linked provider and has no consumer link can set a first local password after fresh provider sign-in. A consumer-linked member manages their password through the consumer account instead.
Build the controls from the returned password options. This gives each member an action that applies to their account, with an explanation when it is unavailable.
If Maya prefers provider sign-in and wants to remove her local password, she must first sign in through a verified, currently permitted provider that will remain linked, within five minutes. An email sign-in alone is insufficient. She also confirms the specific local password identity being removed. Once retirement completes, that credential cannot be restored; a later eligible setup creates a new one.
Linked providers deserve equally clear labels. A link belongs to the member within the organization, so its effect extends beyond this one app. Linking requires provider proof and explicit confirmation; matching email addresses do not merge accounts. Unlinking requires fresh proof through a different usable method that will remain, with eligibility checked against current policy.
Make security and recovery understandable
Where the organization permits tenant two-factor authentication, Maya can enroll an authenticator and keep the ten backup codes shown once after successful enrollment. Tenant factors are separate from consumer-account factors, including for consumer-linked members.
Explain when that factor applies. Password sign-in follows the organization's allowance and the member's enrollment. Email sign-in also depends on the email allowance and saved preference. Fresh provider sign-in does not require the local tenant factor; that does not establish whether the provider performed its own second check. Refreshing or switching an existing session adds no fresh local-factor prompt.
Sensitive settings ask for fresh sign-in or factor proof. If Maya loses both authenticator access and all backup codes, she needs an authorized manager reset.
Tell members what actually finished
Label device controls with their scope: the browser-direct device list covers this member's sessions in this app. Password changes, password removal and provider unlinking have different session effects; none justifies a blanket “signed out everywhere” message.
Remote cleanup can remain pending, and uncertain responses need reconciliation before the screen reports success. Clear scope and honest status let Maya finish her small account task knowing what changed—and what she can do next.