> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/onboard-cortex-multi-tenant.md).

# Onboard Cortex multi-tenant

This section describes how to get up and running with Cortex XDR multi-tenant, including how to activate parent and child tenants, and manage child tenants.

### **Onboarding checklist for multi-tenant central licensing deployments**

We recommend that you review the following steps to successfully deploy and onboard Cortex XDR with central licensing management. For MSSP multi-tenant environments with customer-owned licenses, see the onboarding checklist for multi-tenant customer-owned license deployments below.

This checklist enables you to set up a multi-tenant deployment. After onboarding, you should configure Cortex XDR to suit your needs. For more information, see [Configure and deploy Cortex XDR](/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr.md).

| Step                               | Details                                                                                                                            | See More                                                                                                         |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- |
| Step 1. Activate the parent tenant | <ul><li>Activate Cortex XDR in Cortex Gateway for the parent tenant</li><li>Enable access to Palo Alto Network resources</li></ul> | See below.                                                                                                       |
| Step 2. Create a child tenant      | Create and activate a child tenant in Cortex Gateway.                                                                              | See below.                                                                                                       |
| Step 3. Set up users and roles     | Set up users, roles, user groups, and user authentication.                                                                         | [Set up users, groups, and roles](/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles.md) |

#### **Step 1. Activate Cortex XDR (main account)**

To set up Cortex XDR multi-tenant, you need to activate the main account in Cortex Gateway. Cortex Gateway is a centralized portal for activating and managing tenants, users, roles, and user groups. After activating the tenant you can then access the tenant. You will need to repeat this task for each tenant if you have multiple tenants. The activation process includes accessing Cortex Gateway, activating the tenant, and then accessing the tenant.

{% hint style="warning" %}

### Prerequisite

Before you begin, make sure you have the following:

* Cortex XDR activation email.
* Customer Support Portal Super User role is assigned to your account.

  Before activating your Cortex XDR tenant, you need to set up your Customer Support Portal account. See [How to Create Your Customer Support Portal User Account](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNVCA0). When you create a Customer Support Portal account you can set up two-factor authentication (2FA) to log into the Customer Support Portal, by using one of the following:

  * Email
  * Okta Verify
  * Google Authenticator (non-FedRAMP accounts)

  Users who create the Customer Support Portal account are granted the Super User role. If you are the first user to access Cortex Gateway with the Customer Support Portal Super User role, you are automatically granted Account Admin permissions for the gateway.

  You can activate Cortex XDR new tenants, access existing tenants, and create and manage role-based access control (RBAC) for all of your tenants.
  {% endhint %}

How to activate Cortex XDR

1. Enable and verify access to Cortex XDR communication servers, storage buckets, and various resources in your firewall configuration. For more information, see [Enable access to required PANW resources](/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources.md).
2. Go to [Cortex Gateway](https://cortex-gateway.paloaltonetworks.com/signin/) .

   You can also access the link from the activation email.
3. Enter your username and password or multi-factor authentication (if set up) by using your Customer Support Portal account credentials to sign in.

   Once signed in, you can view the following:

   * Tenants that are allocated to your Customer Support Portal account and ready for activation. After activation, you cannot move your tenant to a different Customer Support Portal account.
   * Tenant details such as license type, number of endpoints, and purchase date.
   * Tenants that were activated and are now available. If you have more than one Customer Support Portal account, the tenants are displayed according to the Customer Support Portal account name.
4. In the **Available for Activation** section, use the serial number to locate the tenant that needs activation, and then click **Activate**.
5. On the **Tenant Activation** page, define the following:
   * **Tenant Name:** Enter a name for the tenant. Use a name that is unique across your company account and up to 59 characters long.
   * **Region:** Geographic location where your tenant will be hosted. For more information, see [Cortex XDR supported regions](/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/cortex-xdr-supported-regions.md).
   * **Tenant Subdomain:** DNS record associated with your tenant. Enter a name that will be used to access the tenant directly using the full URL:

     `https://<xdr-tenant>.xdr.<region>.paloaltonetworks.com`
6. Select **I agree to the terms and conditions of the Privacy policy**.
7. Click **Activate**.

   The activation process can take about an hour and does not require that you remain on the activation page. Cortex XDR sends a notification to your email when the process is complete.
8. After activation, from Cortex Gateway, in the **Available Tenants** when hovering over the activated tenant, do the following:
   * Ensure that you can successfully access the tenant by clicking the Cortex XDR tenant name (when the tenant is active).
   * In the dialog box, view the tenant status, region, serial number, and license details.

#### **Step 2. Create a child tenant**

After setting up the main account, you can create child tenants in Cortex Gateway. You can create as many child tenants as you require, subject to your license.

{% hint style="info" %}

### Note

* The main account is labeled in Cortex Gateway, but child tenants are not labeled.
* Cortex enables parent-child pairing between tenants located in different geographical regions. To enable this capability, contact your support team.
* To create a child tenant, ensure that you have Account Admin permissions.
  {% endhint %}

In Cortex Gateway, you can view all the available tenants. If you want to create more child tenants than your license permits, contact Customer Support.

1. In the Cortex Gateway, hover over the main account you activated previously until the three-dot menu appears and click **Add Child Tenant**.
2. Add the following details:

   | Parameter              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
   | ---------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Child Tenant Name      | <p>Give the Cortex XDR tenant an easily recognizable name.</p><p>Choose a name that is 59 or fewer characters and is unique across your company account.</p>                                                                                                                                                                                                                                                                                                                                                         |
   | Region                 | View the region for the child tenant.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
   | Child Tenant Subdomain | <p>Give your Cortex XDR instance an easy-to-recognize name that is used to access the tenant directly using the full URL.</p><p>https\://\<subdomain>.crtx.\<region>.paloaltonetworks.com</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>This is a public FQDN, so be careful with sensitive information such as the company name.</p><p>After activating a child tenant, you can only change the child tenant subdomain once.</p></div>       |
   | Child Units Allocation | <p>Assign the number of Gigabytes you want to allocate to this child tenant. The amount used and the total amount available to this multi-tenant environment are displayed.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Ensure that you meet the <a href="#UUID-f8450665-a710-7ec2-d40a-7f15349ac119_section-idm234529819989674">minimum requirements</a> for child tenant allocation.</p></div>                                            |
   | Child Endpoints        | <p>Assign the number of endpoints and/or cloud endpoints you want to allocate to this child tenant. The number of used endpoints and the total number of endpoints available to this multi-tenant setup are displayed.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Ensure that you meet the <a href="#UUID-f8450665-a710-7ec2-d40a-7f15349ac119_section-idm234529819989674">minimum requirements</a> for child tenant allocation.</p></div> |
   | Add Ons                | If any license add-ons were purchased with your multi-tenant license, they are listed here. If you acquired compute units (CU) or forensics, you can allocate how many units to allocate to this child tenant.                                                                                                                                                                                                                                                                                                       |
3. Confirm approval of the terms and conditions of the privacy policy and click **Activate**.

   Activation can take up to an hour. You should receive notification by email that the child tenant has completed the activation process.
4. (Optional) Add another child tenant by repeating steps 1 and 2 or access your newly created tenant.

   In an enterprise multi-tenant environment, in the Cortex Gateway' under your main account, you can see the total number of tenants you are licensed for and how many you have created.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If you reach your limit for child tenants, depending on your license, you may be able to create more tenants. You may be charged for additional tenants. Contact Customer Support if you are approaching your authorized limit.</p></div>

**Child tenant minimum allocations**

The following are the minimum number of endpoints and Gigabytes needed in a child tenant. You will not be able to create a child tenant with less than these minimum allocations, nor will you be able to edit your child tenant allocations to have less than these minimum allocations.

| Multi-tenant environment | Child tenant minimum allocation                                                                        |
| ------------------------ | ------------------------------------------------------------------------------------------------------ |
| MSSP multi-tenant        | 200 endpoints OR 100 Gigabytes. The endpoint total can be made up of endpoints and/or cloud endpoints. |
| Enterprise multi-tenant  | 50 endpoints OR 100 Gigabytes. The endpoint total can be made up of endpoints and/or cloud endpoints.  |

### **Onboarding checklist for multi-tenant customer-owned license deployments**

We recommend that you review the following steps to successfully deploy and onboard Cortex XDR with customer-owned licenses. For MSSP multi-tenant environments with central licensing management, see the onboarding checklist for multi-tenant central licensing deployments above.

This checklist enables you to set up a multi-tenant deployment. After onboarding, you should configure Cortex XDR to suit your needs. For more information, see [Configure and deploy Cortex XDR](/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr.md).

| Step                                                      | Details                                                                                                                    | See More   |
| --------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | ---------- |
| Step 1. Activate Cortex XDR parent and child tenants      | Activate parent and child tenants in Cortex Gateway.                                                                       | See below. |
| Step 2. Define access configurations and role permissions | Ensure the users have the appropriate role permissions in the CSP and the correct access configurations in Cortex Gateway. | See below. |
| Step 3. Pair parent tenant with child tenant              | Use Cortex XDR Tenant Management in the parent tenant to pair the child tenant.                                            | See below. |

#### **Step 1. Activate Cortex Cortex XDR (parent and child tenants)**

To set up Cortex XDR multi-tenant in a customer-owned license deployment, you need to activate the parent and child tenants in Cortex Gateway. Cortex Gateway is a centralized portal for activating and managing tenants, users, roles, and user groups. After activating the tenants you can then access the tenant. You will need to repeat this task for each tenant if you have multiple tenants. The activation process includes accessing Cortex Gateway, activating the tenant, and then accessing the tenant.

{% hint style="warning" %}

### Prerequisite

Before you begin, make sure you have the following:

* Cortex XDR activation email.
* Customer Support Portal Super User role is assigned to your account.

  Before activating your Cortex XDR tenant, you need to set up your Customer Support Portal account. See [How to Create Your Customer Support Portal User Account](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNVCA0). When you create a Customer Support Portal account you can set up two-factor authentication (2FA) to log into the Customer Support Portal, by using one of the following:

  * Email
  * Okta Verify
  * Google Authenticator (non-FedRAMP accounts)

  Users who create the Customer Support Portal account are granted the Super User role. If you are the first user to access Cortex Gateway with the Customer Support Portal Super User role, you are automatically granted Account Admin permissions for the gateway.

  You can activate Cortex XDR new tenants, access existing tenants, and create and manage role-based access control (RBAC) for all of your tenants.
  {% endhint %}

How to activate Cortex XDR

1. Enable and verify access to Cortex XDR communication servers, storage buckets, and various resources in your firewall configuration. For more information, see [Enable access to required PANW resources](/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources.md).
2. Go to [Cortex Gateway](https://cortex-gateway.paloaltonetworks.com/signin/) .

   You can also access the link from the activation email.
3. Enter your username and password or multi-factor authentication (if set up) by using your Customer Support Portal account credentials to sign in.

   Once signed in, you can view the following:

   * Tenants that are allocated to your Customer Support Portal account and ready for activation. After activation, you cannot move your tenant to a different Customer Support Portal account.
   * Tenant details such as license type, number of endpoints, and purchase date.
   * Tenants that were activated and are now available. If you have more than one Customer Support Portal account, the tenants are displayed according to the Customer Support Portal account name.
4. In the **Available for Activation** section, use the serial number to locate the tenant that needs activation, and then click **Activate**.
5. On the **Tenant Activation** page, define the following:
   * **Tenant Name:** Enter a name for the tenant. Use a name that is unique across your company account and up to 59 characters long.
   * **Region:** Geographic location where your tenant will be hosted. For more information, see [Cortex XDR supported regions](/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/cortex-xdr-supported-regions.md).
   * **Tenant Subdomain:** DNS record associated with your tenant. Enter a name that will be used to access the tenant directly using the full URL:

     `https://<xdr-tenant>.xdr.<region>.paloaltonetworks.com`
6. Select **I agree to the terms and conditions of the Privacy policy**.
7. Click **Activate**.

   The activation process can take about an hour and does not require that you remain on the activation page. Cortex XDR sends a notification to your email when the process is complete.
8. After activation, from Cortex Gateway, in the **Available Tenants** when hovering over the activated tenant, do the following:
   * Ensure that you can successfully access the tenant by clicking the Cortex XDR tenant name (when the tenant is active).
   * In the dialog box, view the tenant status, region, serial number, and license details.

#### **Step 2. Define access configurations and role permissions**

To set up manual pairing in a customer-owned license multi-tenant deployment, after the parent and child Cortex XDR tenants are activated, you must define correct access configuration in the Customer Support Portal (CSP) and role permissions in Cortex Gateway.

The following table describes the access configurations and role permissions needed:

| Tenant         | Application                                                                                                                | Action                                                                                                                                        |
| -------------- | -------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| Parent         | Customer Support Portal (CSP) Account                                                                                      | Ensure the parent user name has Super User role permissions.                                                                                  |
| Cortex Gateway | Ensure the user name added to the child tenant’s CSP account has Admin role permissions on the parent Cortex XDR instance. |                                                                                                                                               |
| Child          | Customer Support Portal (CSP) Account                                                                                      | Add the user name from the parent tenant who is initiating the parent-child pairing and ensure the user name has Super User role permissions. |
| Gateway        | Provide the user name added in CSP with Admin role permissions to access the child Cortex XDR instance.                    |                                                                                                                                               |

#### **Step 3. Pair a parent tenant with child tenant**

After you set up the correct access configurations and role permissions, you should pair the parent tenant to the child tenants.

Cortex enables parent-child pairing between tenants located in different geographical regions. To enable this capability, contact your support team.

**Pairing a Parent and Child Tenant**

1. Log in to the Cortex XDR tenant that has been assigned as the parent tenant and select Settings → Configurations → **Tenant Management**.

   The Tenant Management table displays:

   * **Tenant Name**: Name of the child tenant.
   * **Pairing Status**: State of a pairing request: **Paired**, **Pending**, **Failed**, **Rejected**.
   * **Account Name**: CSP account to which the child tenant is associated.
   * **Last Sync**: Timestamp of when the parent tenant last made contact with child tenant.
   * **Managed Security Actions**: A column for each security action with a status: **Configuration name** or **Unmanaged**. **Unmanaged** status means that a configuration for the security action has not yet been selected.
   * **Region**: Shows the region of the child tenant.

     <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>This field is not enabled by default. To enable this, contact your support team.</p></div>
2. Click **+ Pair Tenant**.

   You can pair tenants across different regions.
3. In the **Pair Tenant** window, select the child tenant you want to pair.

   Child tenants are grouped according to:

   * **Unpaired**: Children that have not yet been paired and are available. If another parent has requested to pair with the child but the child has not yet agreed, the tenant will appear.
   * **Paired**: Children that have already been paired to this parent.
   * **Paired with others**: Children that have been paired with other parents.
   * **Pending**: Children with a pending pairing request.
4. **Pair the tenant.**

   Cortex XDR then sends a **Request for Pairing** to the specified child tenant.
5. In the child tenant Cortex XDR console, a child tenant user with Admin role permissions needs to approve the pairing by navigating to **Notifications** ![notification-icon.png](/files/r6WiEnM84vwe8jm2Hcy1), locate the **Request for Pairing** notification and select **Approve**.
6. Verify the parent-child pairing.

   After pairing has been approved, in the child tenant’s Cortex XDR app, when navigating to a page managed by a parent configuration, the child user is notified by a flag who is managing their security.

   In the child tenant’s, pages that you manage, appear with a read-only banner. Child tenant users cannot perform any actions from these pages, but can view the configurations you create on their behalf.

   ![](/files/IADaO057WF51YMi2wWOh)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/onboard-cortex-multi-tenant.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
