> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/gateway-guide/user-management/manage-users-in-cortex-gateway.md).

# Manage users in Cortex Gateway

In Cortex Gateway, on the **Permissions** page (**Cortex Gateway** → **Permission Management**), you can manage users that have been added to your Customer Support Portal account or view users that have been created in the tenant using SSO (you cannot edit SSO users in Cortex Gateway). All users must have at least one role or belong to at least one user group to be saved in the Cortex Gateway.

{% hint style="info" %}

### Note

To remove users added to your CSP account, you must do so in the CSP, not in Cortex Gateway.
{% endhint %}

The Permission page is split into the following:

* **Users** tab: View user information according to your Customer Support Portal account, including groups, roles, user types, and tenants assigned. When right-clicking a user, you can perform actions such as editing roles, deactivating users, and removing or adding roles.
* **Tenants** tab: View tenants according to the Cortex product and manage users who have access to each tenant.

<details>

<summary>Add/update user roles</summary>

Update a user's role if the user was added to the CSP. You can add the following roles:

* **Pre-defined roles**: Instance Administrator and Account Admin.
* **Custom roles**: Includes out-of-the-box roles and roles created in Cortex Gateway or the tenant.

You can add/update roles by either selecting the users in the **Users** tab or by tenants in the **Tenants** tab.

{% hint style="info" %}

### Note

* To update the permissions associated with each role, you need to change them in the tenant or the Roles tab in Cortex Gateway.
* The **Cortex User** role in the CSP controls both user visibility in the tenant and the ability to authenticate via the CSP.
  * If you do not want a user to appear in the tenant's **Users** list or be able to log in via the CSP, do not assign them the **Cortex User** role in the CSP.&#x20;
  * To allow a user to appear in the tenant but restrict them to SSO login only, you must assign them the **Cortex User** role in the CSP but ensure you do not assign them a direct role or a default role in the Gateway or tenant.&#x20;
* If no role is assigned to a user, either directly or through a user group, in the Cortex Gateway or the tenant, the user cannot access the tenant. In this case, the user is subsequently revoked in the Cortex Gateway, and their information is no longer saved.&#x20;
  {% endhint %}

[Update user roles according to each user](#UUID-a1c4e54d-7a22-5940-9eab-0b82b4ba4080_section-idm4621377715758434158467935798_body)

You can update user roles for one or multiple users.

1. From the **Permissions** page, in the **Users** tab, do one of the following:
   * If editing one user, right-click the user's name and select **Update Permissions** or **Add Permissions** (if no role).
   * If editing multiple users, select multiple users, and in the right-hand corner, outside the table, click the edit button.
2. In the **Update user role** window, if you want the user to have superuser permission across all tenants, select **Apply the Account Admin role**.

   We do not recommend creating additional Account Admins as the user has full access to all tenants across all Cortex products. Account Admin is a special role, automatically assigned to the Customer Support Portal Super User.
3. If you have multiple Cortex products, select the product for which you want to change permissions.
4. In the **AVAILABLE TENANTS** field, select the tenant where you want to add the user's role.
5. In the **Role** field, select one of the following:
   * Predefined role
   * Custom role
6. Save the user role.

{% hint style="info" %}

### Note

To make users visible in the **Users** list in the Cortex tenant, an admin needs to assign them the **Cortex User** role on the **Edit User** screen in the **Manage User Console** of Customer Support Portal (CSP).
{% endhint %}

[Update user roles according to each tenant](#UUID-a1c4e54d-7a22-5940-9eab-0b82b4ba4080_section-idm4618346285452834158466029107_body)

You can update user roles according to each Cortex tenant or multiple tenants.

{% hint style="info" %}

### Note

If you are updating multiple tenants at one time, you can only add predefined roles or roles created in Cortex Gateway (not custom roles created in the tenant).
{% endhint %}

1. In the **Permissions** page, select the **Tenants** tab.
2. If updating a single tenant, right-click the tenant and select **Update Permissions**.
3. If updating multiple tenants, select the multiple tenants, and in the right-hand corner, outside the table, click the edit button.
4. Select the role you want to add.

   If selecting multiple tenants, you can only add predefined and custom roles created in Cortex Gateway. If you want to add custom roles created in a tenant, you need to select only one tenant.
5. Select the users.
6. Save the role.

</details>

<details>

<summary>Remove permissions</summary>

If a user has a role in the tenant, you can remove their user permission to access each tenant. If no direct or user group role has been assigned, the user role displays **No Role**, and has no permission to view or edit the Cortex tenant.

1. From the **Permissions** page, in the **Users** tab, right-click the user's name and select **Remote Permissions**.
2. Do one of the following:
   * Remove permissions for all tenants, by clicking **Select All Tenants**.
   * To remove permissions for specific tenants, click the name field to select the tenants you want the user to be deactivated from.
3. Click **Remove**.

</details>

<details>

<summary>Deactivate users</summary>

Deactivate users for all or one or more tenants if they no longer need access, but may need it again at a later date. All user information is maintained for deactivated users. Users should be permanently removed if they no longer have access to the system through the CSP. The deactivated user appears grayed out. To reactivate, follow the same steps in this procedure.

{% hint style="info" %}

### Note

You cannot deactivate a user who has an Account Admin role or who is not assigned access to a tenant. If you want to deactivate an Account Admin user role, right-click the user and select **Remove User Permissions**. You can then deactivate the user.
{% endhint %}

If the user is assigned to incidents or tasks or is the owner of a dashboard, these assignments do not automatically change when the user is removed or deactivated. We recommend changing incident and task assignments manually before removing or deactivating users.

Any reports the user has created remain available. Reports are not owned by specific users and can be edited or deleted by other users.

* Reassign open incidents to another user.

  Go to the **Incidents** page and search for **`-status:closed owner:`*****`user_name`*** to find any incidents the user is assigned and reassign.
* Reassign tasks to another user.

  Go to the **Incidents** page and search for **`-status:closed investigation.users:`*****`user_name`*** and reassign.

  When a user is assigned a task in an incident, the user is added to the incident. This search finds all incidents where the user is a participant.

How to deactivate users

1. From the **Permissions** page, in the **Users** tab, right-click the user's name and select **Deactivate User**.
2. Click **Select All Tenants**.
3. To select specific tenants, click the name field to select the tenants you want the user to be deactivated from.
4. Click **Deactivate**.

</details>

<details>

<summary>Hide users</summary>

Hides users from the user list in Cortex Gateway. This is useful when you have users who are not related to the Cortex tenant and will not be designated with a role, such as CSP Super Users, and you want to hide them from the list. When a user is designated as hidden, the user is no longer displayed when the table is configured to **Show User Subset** (default configuration).

You cannot view the user or search for the user when hidden. To show hidden users, deselect **Show User Subset**. To remove the hidden user tag, right-click the user and select unhide the user.

{% hint style="info" %}

### Note

Users without an assigned role or user group are not saved in the Cortex Gateway. However, there is an exception for users who did not have an assigned role or user group and who were hidden before the following product releases:

* Cortex XSIAM 2.7 (legacy)
* Cortex XSIAM 3.2 (platform)
* Cortex XSOAR 8.11
* Cortex XDR 3.15 (legacy)
* Cortex XDR 4.2 (platform)

Users who were hidden before the release remain saved in the Cortex Gateway and are not revoked, even if they do not have an assigned role or user group.
{% endhint %}

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/gateway-guide/user-management/manage-users-in-cortex-gateway.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
