diff --git a/docs/img/access-controls/saml-idp/access-app.png b/docs/img/access-controls/saml-idp/access-app.png
index 28a66b3efa9..33d34b24395 100644
Binary files a/docs/img/access-controls/saml-idp/access-app.png and b/docs/img/access-controls/saml-idp/access-app.png differ
diff --git a/docs/img/access-controls/saml-idp/enroll-saml-app.png b/docs/img/access-controls/saml-idp/enroll-saml-app.png
deleted file mode 100644
index f6ddb26df16..00000000000
Binary files a/docs/img/access-controls/saml-idp/enroll-saml-app.png and /dev/null differ
diff --git a/docs/img/access-controls/saml-idp/gcp-workforce/gcp-workforce-tile.png b/docs/img/access-controls/saml-idp/gcp-workforce/gcp-workforce-tile.png
index b0a0b4ac385..b793180c0e9 100644
Binary files a/docs/img/access-controls/saml-idp/gcp-workforce/gcp-workforce-tile.png and b/docs/img/access-controls/saml-idp/gcp-workforce/gcp-workforce-tile.png differ
diff --git a/docs/img/access-controls/saml-idp/saml-add-auth.png b/docs/img/access-controls/saml-idp/saml-add-auth.png
new file mode 100644
index 00000000000..332160a0e2f
Binary files /dev/null and b/docs/img/access-controls/saml-idp/saml-add-auth.png differ
diff --git a/docs/img/access-controls/saml-idp/saml-idp.png b/docs/img/access-controls/saml-idp/saml-idp.png
new file mode 100644
index 00000000000..88bb3c9ef1f
Binary files /dev/null and b/docs/img/access-controls/saml-idp/saml-idp.png differ
diff --git a/docs/img/access-graph/graph-explorer-ui.png b/docs/img/access-graph/graph-explorer-ui.png
new file mode 100644
index 00000000000..2df44cb08f5
Binary files /dev/null and b/docs/img/access-graph/graph-explorer-ui.png differ
diff --git a/docs/img/enterprise/plugins/datadog/review-access-request.png b/docs/img/enterprise/plugins/datadog/review-access-request.png
index 05a2ab77bd6..7e3ea385ce3 100644
Binary files a/docs/img/enterprise/plugins/datadog/review-access-request.png and b/docs/img/enterprise/plugins/datadog/review-access-request.png differ
diff --git a/docs/img/enterprise/plugins/datadog/teleport-users.png b/docs/img/enterprise/plugins/datadog/teleport-users.png
index 0d99c7289d2..7f93820b7f7 100644
Binary files a/docs/img/enterprise/plugins/datadog/teleport-users.png and b/docs/img/enterprise/plugins/datadog/teleport-users.png differ
diff --git a/docs/img/enterprise/plugins/enroll.png b/docs/img/enterprise/plugins/enroll.png
index 958c14122ab..4e9cfae257a 100644
Binary files a/docs/img/enterprise/plugins/enroll.png and b/docs/img/enterprise/plugins/enroll.png differ
diff --git a/docs/pages/admin-guides/access-controls/idps/saml-gcp-workforce-identity-federation.mdx b/docs/pages/admin-guides/access-controls/idps/saml-gcp-workforce-identity-federation.mdx
index 3c8e11d7a83..5c80b5f6442 100644
--- a/docs/pages/admin-guides/access-controls/idps/saml-gcp-workforce-identity-federation.mdx
+++ b/docs/pages/admin-guides/access-controls/idps/saml-gcp-workforce-identity-federation.mdx
@@ -20,7 +20,6 @@ process.
This guide details how to integrate GCP workforce Identity Federation service with Teleport
SAML IdP, so users can sign in into GCP web console by authenticating with Teleport.
-
## Prerequisites
(!docs/pages/includes/edition-prereqs-tabs.mdx edition="Teleport Enterprise"!)
@@ -42,7 +41,7 @@ pool provider to help you quickly get started with the integration.
## Guided configuration flow
Create a workforce pool and pool provider with the script generated by Teleport.
-In the Web UI, under **Access Management**, click **Enroll New Resource** menu.
+In the Web UI, under **Add New** in the left pane, click **Resource** menu.
In the search box, enter “workforce”, which will show the Workforce Identity Federation
integration tile. Click the tile.

diff --git a/docs/pages/admin-guides/access-controls/idps/saml-guide.mdx b/docs/pages/admin-guides/access-controls/idps/saml-guide.mdx
index 82f4747963e..a918ec5d332 100644
--- a/docs/pages/admin-guides/access-controls/idps/saml-guide.mdx
+++ b/docs/pages/admin-guides/access-controls/idps/saml-guide.mdx
@@ -34,15 +34,10 @@ of the service provider.
Below we'll show both of the configuration options.
-First, in the Web UI, under **Access Management**, click **Enroll New Resource** menu.
-In the search box, enter "saml", which will show the SAML application
-integration tile. Click the tile.
+First, in the Web UI, under **Zero Trust Access**, click **Auth Connectors** in the menu.
+Choose the appropriate SAML application integration tile. Click the tile and follow the resulting steps.
-
-
-The first configuration step, **Configure Service Provider with Teleport's Identity Provider Metadata**
-shows Teleport SAML IdP metadata values. For this guide, you can move to next step by clicking **Next** button
-which takes to **Add Service Provider To Teleport** step.
+
### Option 1: Configure with Entity ID and ACS URL
@@ -177,7 +172,7 @@ already available to access under resources page.
## Step 3/3. Verify access to iamshowcase protected page
-To verify everything works, navigate to **Resources** page in Teleport Web UI.
+To verify everything works, navigate to **Resources** page in Teleport Web UI and look for the app.

diff --git a/docs/pages/admin-guides/management/guides/awsoidc-integration.mdx b/docs/pages/admin-guides/management/guides/awsoidc-integration.mdx
index 567d535cb57..afad0a7c684 100644
--- a/docs/pages/admin-guides/management/guides/awsoidc-integration.mdx
+++ b/docs/pages/admin-guides/management/guides/awsoidc-integration.mdx
@@ -17,7 +17,7 @@ The following features use an AWS OIDC integration to interact with AWS:
It targets users who would prefer a more manual approach or to manage the integration with Infrastructure as Code tools.
-As an alternative to this guide, you can use the Teleport Web UI (Access Management / Enroll New Integration).
+As an alternative to this guide, you can use the Teleport Web UI. In the left-hand pane, click **Add New** -> **Integration**.
## How it works
Teleport is added as an [OpenID Connect identity provider](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_create_oidc.html) to establish trust with your AWS account and assume a configured IAM role in order to access AWS resources.
diff --git a/docs/pages/connect-your-client/tsh.mdx b/docs/pages/connect-your-client/tsh.mdx
index 6e5f2820b20..f93ef668bd9 100644
--- a/docs/pages/connect-your-client/tsh.mdx
+++ b/docs/pages/connect-your-client/tsh.mdx
@@ -885,9 +885,7 @@ You can use `tsh` to examine sessions that users have completed in resources
protected by Teleport. This section explains how to list and play Teleport
session recordings with `tsh`.
-Note that you can also play session recordings in the Teleport Web UI. To do so,
-navigate to the **Access Management** tab on the top sidebar and view the
-**Session Recordings** tab on the left sidebar.
+To view the recording, select **Audit** in the Teleport Web UI, then click **Session Recordings** in the menu.
### Listing recordings
diff --git a/docs/pages/identity-governance/access-request-plugins/datadog-hosted.mdx b/docs/pages/identity-governance/access-request-plugins/datadog-hosted.mdx
index dc909145f0e..943d240c062 100644
--- a/docs/pages/identity-governance/access-request-plugins/datadog-hosted.mdx
+++ b/docs/pages/identity-governance/access-request-plugins/datadog-hosted.mdx
@@ -63,7 +63,7 @@ For the purpose of this guide, we will define an `editor-requester` role, which
can request the built-in `editor` role, and an `editor-reviewer` role that can
review requests for the `editor` role.
-In the Teleport WebUI navigate to **Access -> Roles**. Then select **Create New
+In the Teleport Web UI navigate to **Zero Trust Access -> Roles**. Then select **Create New
Role** and create the desired roles.
@@ -94,12 +94,12 @@ spec:
First, assign yourself the `editor-reviewer` role. This will allow your user to
review Access Requests for the `editor` role. To edit your user roles navigate to
-**Management -> Access -> Users**, then for your user select **Options -> Edit**
+**Zero Trust Access -> Users**, then for your user select **Options -> Edit**
and add the `editor-reviewer` role.
Next, create a user called `myuser@example.com` who has the `editor-requester` role.
Later in this guide, you will create an Access Request as this user to test the
-Datadog plugin. To this user, navigate to **Management -> Access -> Users**. Then
+Datadog plugin. To this user, navigate to **Zero Trust Access -> Users**. Then
select **Enroll Users** and create a user with the `editor-requester` role.
You should end up with two users that look like this:
@@ -141,9 +141,8 @@ to create a new Application key. Copy the Application key to paste in a later st
## Step 4/6. Enroll the Datadog Incident Management plugin
At this point, you're now ready to enroll the Datadog Incident Management plugin.
-Navigate to **Access Management -> Enroll New Integration -> Datadog**.
-
+(!docs/pages/includes/plugins/enroll.mdx name="the Datadog Incident Management"!)
Provide the API and Application keys generated above. Select the desired API endpoint.
Then provide the Datadog team handle, that you created earlier, as the fallback recipient.
@@ -154,8 +153,6 @@ can be a Datadog user email, or a Datadog team handle. You can configure more cu
notification routing rules afterwards using
[Access Monitoring Rules](./notification-routing-rules.mdx).
-
-
If the recipient is a Datadog team, the team name will be added to the Datadog incident
teams attribute.
diff --git a/docs/pages/identity-governance/access-request-plugins/opsgenie.mdx b/docs/pages/identity-governance/access-request-plugins/opsgenie.mdx
index 4671b42374f..48725efca78 100644
--- a/docs/pages/identity-governance/access-request-plugins/opsgenie.mdx
+++ b/docs/pages/identity-governance/access-request-plugins/opsgenie.mdx
@@ -77,13 +77,7 @@ Create a user called `myuser` who has the `requester` role. Later in this
guide, you will create an Access Request as this user to test the Opsgenie
plugin:
-To create a user first navigate to Management -> Access -> Users
-
-
-
-Then select 'Create New User' and create a user with the requester role.
-
-
+To create a user, first navigate to Zero Trust Access -> Users.
## Step 3/5. Set up an Opsgenie API key
@@ -97,10 +91,9 @@ See https://support.atlassian.com/opsgenie/docs/create-a-default-api-integration
## Step 4/5. Configure the Opsgenie plugin
At this point, you have generated credentials that the Opsgenie plugin will use
-to connect to the Opsgenie API. To configure the plugin to use this API key navigate
-to Management -> Integrations -> Enroll New Integration.
-
-
+to connect to the Opsgenie API. To configure the plugin to use this API key,
+navigate to **Add New** in the Web UI; in the left pane, click **Integration**.
+Click the Opsgenie tile.
## Step 5/5. Test the Opsgenie plugin
diff --git a/docs/pages/identity-security/access-graph/self-hosted-helm.mdx b/docs/pages/identity-security/access-graph/self-hosted-helm.mdx
index 6e131ba2ccd..74cd3224fc7 100644
--- a/docs/pages/identity-security/access-graph/self-hosted-helm.mdx
+++ b/docs/pages/identity-security/access-graph/self-hosted-helm.mdx
@@ -208,10 +208,10 @@ $ kubectl -n rollout restart deploymen
$ kubectl -n rollout status deployment/teleport-proxy # Wait for the deployment to succeed
```
-## Step 4/4. View the Access Graph in the Web UI
+## Step 4/4. View Access Graph data in the Graph Explorer
-You can find the Access Graph in the "Access Management" tab in the Web UI.
-
+In order to visualize the data from the Access Graph service, use the Graph Explorer in the Web UI.
+Click **Identity Security** --> **Graph Explorer** and then select a resource to view in the Graph Explorer.
To access the interface, your user must have a role that allows `list` and `read` verbs on the `access_graph` resource, e.g.:
diff --git a/docs/pages/identity-security/access-graph/self-hosted.mdx b/docs/pages/identity-security/access-graph/self-hosted.mdx
index 39628066224..90d511084fb 100644
--- a/docs/pages/identity-security/access-graph/self-hosted.mdx
+++ b/docs/pages/identity-security/access-graph/self-hosted.mdx
@@ -124,10 +124,10 @@ access_graph:
Then, restart Auth Service instances, followed by Proxy Service instances.
-## Step 3/3. View the Access Graph in the Web UI
+## Step 3/3. View Access Graph data in the Graph Explorer
-You can find Access Graph in the "Access Management" tab in the Web UI.
-
+In order to visualize the data from the Access Graph service, use the Graph Explorer in the Web UI.
+Click **Identity Security** --> **Graph Explorer** and then select a resource to view in the Graph Explorer.
To access the interface, your user must have a role that allows `list` and `read` verbs on the `access_graph` resource, e.g.:
diff --git a/docs/pages/includes/plugins/enroll.mdx b/docs/pages/includes/plugins/enroll.mdx
index 0a4e8e15b9e..87619e05e50 100644
--- a/docs/pages/includes/plugins/enroll.mdx
+++ b/docs/pages/includes/plugins/enroll.mdx
@@ -2,13 +2,11 @@
In Teleport Enterprise Cloud, Teleport manages {{ name }} for you, and you can
enroll {{ name }} from the Teleport Web UI.
-Visit the Teleport Web UI and on the left sidebar, click **Access** followed
-by **Integrations**. Then click **Enroll New Integration** to visit the
-"Enroll New Integration" page:
+Visit the Teleport Web UI and on the left sidebar, click **Add New** followed
+by **Integration**:

On the "Select Integration Type" menu, click the tile for your integration. You
will see a page with instructions to set up the integration, as well as a form
that you can use to configure the integration.
-