> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/gateway-guide/user-management.md).

# User management

You can manage users in Cortex Gateway or the Cortex tenant. At the **Users** tab in the **Permissions** page (**Cortex Gateway** → **Permission Management**+**Permissions**) or the **Users** page (**Settings & Info** → **Settings** → **Access Management** → **Users**) in the tenant, you can see user information, including:

| Name            | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User Type       | <p>Indicates whether the user was defined in Cortex using the <strong>CSP</strong>, <strong>SSO</strong> using your organization’s IdP, or both <strong>CSP/SSO</strong>.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If you have migrated local users from Cortex XSOAR 6 to Cortex XSOAR 8 and these users are in the Customer Support Portal, these users are designated the <strong>PANW IDP</strong> user type. For more information, see <a href="/spaces/nPfgrPjdRQBvgLTOrM8C/pages/nHeekfDTgRC14AseBzix">Migrating users and roles</a>.</p></div>                                                                                                              |
| Direct Role     | <p>Displays the name of the role assigned specifically to the user not inherited from somewhere else, such as a user group.</p><p>In Cortex Gateway, select the arrow next to the name of the user to see the user roles and the tenants the user has access to.</p><p>In the Cortex tenant, the direct role is the role assigned to the user in the tenant.</p><p>When the user has no access permissions assigned specifically to them, the field displays <strong>No-Role</strong>.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If a user does not have a direct role or user group assigned, the user is revoked and is not saved in the Cortex Gateway.</p></div> |
| Groups          | <p>Lists the user groups to which the user belongs.</p><p>If a user is assigned to multiple user groups, which are mapped to different roles, or if the user is assigned to nested user groups, the user inherits the permissions of parent user groups and has the highest level of privileges based on the combination of roles.</p><p>Any group imported from Active Directory has the letters <strong>AD</strong> added beside the group name.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If a user does not have a direct role or user group assigned, the user is revoked and is not saved in the Cortex Gateway.</p></div>                                     |
| Group Roles     | Lists the different group roles based on the groups the user belongs to. When you hover over the group role, the group associated with this role is displayed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Last Login Time | Last date and time the user accessed the Cortex tenant.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Status          | Displays whether the user is **Active** or **Inactive**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Phone number    | <p>Relevant only in the Cortex tenant.</p><p>Displays the user's phone number. Including the user's phone number enables playbooks and scripts to trigger direct analyst communication by phone.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

#### Considerations for managing users in Cortex Gateway or tenant

| Option                     | Cortex Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | Cortex tenant                                                                                                                                                                                                                                                                                                                                 |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SSO                        | Limited to viewing SSO users. You cannot edit SSO users in Cortex Gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Full management of SSO users                                                                                                                                                                                                                                                                                                                  |
| Update user details option | N/a                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | View the user's details and add the user's telephone number.                                                                                                                                                                                                                                                                                  |
| User Permissions           | <p>Global user role management including assigning the Account Admin role, or limiting the user role to the relevant Cortex product/tenant, and adding/removing roles in the Tenant/Gateway.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>You must have an Account Admin role to manage users in Cortex Gateway.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | <p>Management of predefined and custom user roles on the tenant.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>You must have an Account Admin or Instance Administrator role.</p></div>                                                                                |
| Hide users                 | <p>Users are hidden from the list of users in Cortex Gateway, but can still be viewed in the tenants.</p><p>By default, the <strong>Show User Subset</strong> field is selected, which displays the users not designated as Hidden users. This is useful when you have users not related to your Cortex tenant and who will not be designated with a Cortex tenant role, such as Customer Support Portal Super Users, and you want to hide them from the list.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Users without an assigned role or user group are not saved in the Cortex Gateway. However, there is an exception for users who did not have an assigned role or user group and who were hidden before the following product releases:</p><ul><li>Cortex XSIAM 2.7 (legacy)</li><li>Cortex XSIAM 3.2 (platform)</li><li>Cortex XSOAR 8.11</li><li>Cortex XDR 3.15 (legacy)</li><li>Cortex XDR 4.2 (platform)</li></ul><p>Users who were hidden before the release remain saved in the Cortex Gateway and are not revoked, even if they do not have an assigned role or user group.</p></div> | <p>The user is hidden in the list of users in the tenant, but can still be viewed in other tenants and Cortex Gateway.</p><p>In the Cortex tenant under the <strong>Actions</strong> button, select <strong>Hide Hidden Users</strong>.</p><p>When you hide users in the tenant, they are hidden in the tenant and not in Cortex Gateway.</p> |
| Deactivate/activate users  | Deactivate the user for one or more tenants.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Deactivate the user for the tenant only.                                                                                                                                                                                                                                                                                                      |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/gateway-guide/user-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
