> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar.md).

# Step 1: Activate Cortex XSOAR

To activate a Cortex XSOAR tenant, you need to log into Cortex Gateway, which is a centralized portal for activating and managing tenants, users, roles, and user groups. After activating the tenant you can then access the tenant. You must repeat this task for each tenant if you have multiple tenants. The activation process includes accessing the Cortex Gateway, activating the tenant, and then accessing the tenant.

Before you begin, ensure that you have the following:

* The Cortex XSOAR activation email.
* A Customer Support Portal (CSP) account.

  You need to set up your CSP account. For more information, see [How to Create Your CSP User Account](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNVCA0).

  When you create a CSP account, you can set up two-factor authentication (2FA) to log into the CSP by using an Email, Okta Verify, or Google Authenticator (non-FedRAMP accounts). For more information, see [How to Enable a Third Party IdP](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sZ8mCAE).
* You have one of the following roles assigned:

  | Role        | Description                                                                                                                                                                                                                                                                                                                                                                                                                               |
  | ----------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | CSP role    | The Super User role is assigned to your CSP account. The user who creates the CSP account is granted the Super User role.                                                                                                                                                                                                                                                                                                                 |
  | Cortex role | <p>You must have the Account Admin role.</p><p>If you are the first user to access Cortex Gateway with the CSP Super User role, you are automatically granted Account Admin permissions for the Cortex Gateway. You can also add Account Admin users as required.</p><p>In the Cortex Gateway, you can activate new tenants, access existing tenants, and create and manage role-based access control (RBAC) for all of your tenants.</p> |

How to activate Cortex XSOAR

1. Log in to Cortex Gateway.

   You can also access the link from the activation email.
2. Enter your username and password or multi-factor authentication (if set up) by using your CSP account credentials to sign in.

   After you are signed in, you can view the following:

   * If you are a CSP Account Admin, you can see tenants allocated to your CSP account and ready for activation. After activation, you cannot move your tenant to a different CSP account.
   * Tenant details such as license type, status, and serial number.
   * Tenants that were activated and are now available. If you have more than one CSP account, the tenants are displayed according to the CSP account name.
3. In the **Available for Activation** section, use the serial number to locate the tenant that needs activation, and then click **Activate as SAAS**.

   If you want to install On-prem instead, download the install package. For more information, see [Cortex XSOAR installation](/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation.md).

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>When you activate, a production tenant is first activated. After activation, you can set up a development tenant (subject to your license).</p></div>
4. In the **Activate XSOAR 8** dialog box, select **Start Fresh**.

   If you are migrating from Cortex XSOAR 6, select **Migrate your tenant**. When activated, this option starts the migration process. For more information, see [Migrate from Cortex XSOAR 6 to 8 using the migration wizard](/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard.md).
5. On the **Tenant Activation** page, define the following:

   | Parameter        | Description                                                                                                                                                                                                                                          |
   | ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Tenant Name      | Enter the name of the tenant. Use a unique name across your company account up to 59 characters long.                                                                                                                                                |
   | Region           | Geographic location where your tenant will be hosted. For more information about supported regions, see [Supported host regions](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/supported-host-regions.md). |
   | Tenant Subdomain | DNS record associated with your tenant. Enter a name that will be used to access the tenant directly using the full URL: `https://<subdomain>crtx.<region>.paloaltonetworks.com`                                                                     |
6. Review and **agree to the terms and conditions of the Privacy policy, Terms of Use, and EULA** , and then **Activate** your tenant.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Activation can take about an hour and does not require you to remain on the activation page. Cortex XSOAR sends a notification to your email when the process is complete.</p></div>
7. When the tenant is active, ensure you can access the tenant by clicking the Cortex XSOAR tenant name.

   When hovering over the activated tenant, you can see the tenant's status, region, serial number, and license details.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>If you want to change your tenant's name, the subdomain, or activate a development tenant (subject to license), click the ellipsis on the right.</p><p>You can only change the subdomain once. This cannot be undone.</p><p>After deleting a subdomain, you can reuse it after 7 days.</p></div>
8. Subject to your license, activate your development tenant.
   1. Hover over the activated tenant, and on the right-hand side, click the ellipsis and then click **Activate Dev Tenant**.

      ![dev-activation.png](/files/yKY2XiYn4XfBnKZhpL0x)
   2. Define the development tenant name, region, and subdomain.

      After the development tenant is activated, you can set up a remote repository. For more information, see [Set up a remote repository](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-3.-set-up-a-remote-repository.md).
   3. Enable access to Palo Alto Networks resources in your firewall. See [Enable access to Palo Alto Networks resources](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
