> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/configure-security-settings-for-multi-tenant-deployments.md).

# Configure Security Settings for Multi-Tenant Deployments

These recommended security configurations are intended for deployments in which the main account and tenant accounts do not reside in the same DMZ.

| Key                               | Value       | Description                                                                                                                                                                                                                                                                                                                                     |
| --------------------------------- | ----------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **`security.tenant.use.secret`**  | **`false`** | <p>Generates a unique cookie session for the tenant account and main account.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If you implement this key in a Multi-tenant high availability architecture, you must restart main host and all of the other hosts.</p></div> |
| **`Tenant.AcceptAnyCertificate`** | **`false`** | Validates the host certificate. Set to false if using a CA (certificate authority) signed certificate. Must be set to true if using a self signed certificate, or the main server cannot send requests to hosts.                                                                                                                                |
| **`host.insecure`**               | **`true`**  | Trusts any certificate (when host accounts exist).                                                                                                                                                                                                                                                                                              |

1. In the main account, navigate to Settings → ABOUT → **Troubleshooting**.
2. Create a separate server configuration for each of the recommended configurations.
   1. Scroll to the bottom of the **Server Configuration** section.
   2. Click **Add Server Configuration**.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/configure-security-settings-for-multi-tenant-deployments.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
