> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-self-service.md).

# Migrate from Cortex XSOAR 6 Multi-Tenant to Cortex XSOAR 8 SaaS Multi-Tenant (Self-Service)

Use this procedure to migrate manually from Cortex XSOAR 6 to Cortex XSOAR 8 Multi-Tenant SaaS (not using the wizard).

{% hint style="info" %}

### Important

This procedure does not migrate incident and indicator data and is recommended for content-only platform migrations. Some Cortex XSOAR integrations and API endpoints support syncing data between Cortex XSOAR deployments. For more information, contact Customer Success or the Professional Services team.

The Cortex XSOAR 8 tenant is available for activation in Cortex Gateway. A CSP Super User is needed to see the tenant available for activation and to activate it.
{% endhint %}

![mt-migration-self-service-workflow.png](/files/0SSzbrQdggnZ8FmM3yDR)

<details>

<summary>Task 1. Activate your tenants</summary>

Ensure that you have the required licenses to activate your tenants. You need to activate the tenants in the order they appear below.

**1. Activate the main tenant**

You must have a multi-tenant/MSSP license, such as PAN-DEMISTO-MSSP, to set up your multi-tenant deployment.

1. From Cortex Gateway, in the **Available for Activation** section, use the serial number to locate the tenant that needs activation, and click **Activate as SAAS**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Only a CSP Account Admin will see the option to activate.</p></div>
2. In the **Activate XSOAR 8** dialog box, select **Start Fresh**.

   Activation can take about an hour and does not require that you remain on the activation page. Cortex XSOAR sends a notification to your email when the process is complete.

   After activation, the first tenant activated is labeled the **Main Account**.
3. Enable access for your Cortex XSOAR 8 tenant. For more information, see [Enable access to Palo Alto Network resources](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).
4. Set up initial user access in the Customer Support Portal (CSP) for administrators who will set up Cortex XSOAR 8.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Account admins have access to all tenants in the CSP account, including any existing Account admins who were set up before the migration. For example, if you had a Cortex XDR Account Admin user in your CSP account, the same user has access to Cortex XSOAR.</p></div>

   * Verify the user is in the CSP portal.
   * Grant the Instance Administrator role to the users who will manage the initial setup. For more information, see [Manage roles in Cortex Gateway](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-cortex-gateway.md).

**2. Activate the development tenant (if using a remote repository)**

You must have a development license.

1. In Cortex Gateway, hover over your activated tenant and click **Activate Dev Tenant**.
2. Define the development tenant name, region, and subdomain.

   Activation can take about an hour and does not require that you remain on the activation page. Cortex XSOAR sends a notification to your email when the process is complete.
3. Enable access for your Cortex XSOAR 8 tenant. For more information, see [Enable access to Palo Alto Network resources](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).
4. Set up initial user access in the Customer Support Portal (CSP) for administrators who will set up Cortex XSOAR 8.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Account admins have access to all tenants in the CSP account, including any existing Account admins who were set up before the migration. For example, if you had a Cortex XDR Account Admin user in your CSP account, that user would have access to Cortex XSOAR.</p></div>

   * Verify the user is in the CSP portal.
   * Grant the Instance Administrator role to the users who will manage the initial setup. For more information, see [Manage roles in Cortex Gateway](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-cortex-gateway.md).
5. After activation, set up the content repository. For more information, see [Set up a remote repository](/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/set-up-a-remote-repository.md).

**3. Activate the child tenant**

1. In Cortex Gateway, hover over the **Main Account** you activated in Step 1 and click **Add Child Tenant**.
2. Define the child tenant name, region, and subdomain.
3. Activate the child tenant and confirm approval.

   Activation can take about an hour and does not require that you remain on the activation page. Cortex XSOAR sends a notification to your email when the process is complete.
4. Enable access for your Cortex XSOAR 8 tenant. For more information, see [Enable access to Palo Alto Network resources](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).
5. Set up initial user access in the Customer Support Portal (CSP) for administrators who will set up Cortex XSOAR 8.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Account admins have access to all tenants in the CSP account, including any existing Account admins who were set up before the migration. For example, if you had a Cortex XDR Account Admin user in your CSP account, that user would also have access to Cortex XSOAR.</p></div>

   * Verify the user is in the CSP portal.
   * Grant the Instance Administrator role to the users who will manage the initial setup. For more information, see [Manage roles in Cortex Gateway](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-cortex-gateway.md).
6. Repeat these steps if you want additional child tenants (subject to your license). For more information about creating child tenants, see [Create a child tenant](/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-2.-create-a-child-tenant.md).

</details>

<details>

<summary>Task 2. Configure content</summary>

We recommend configuring content in the following order:

1. Development tenant (if activated)
2. Main tenant
3. Child tenant

If using a development tenant, we recommend configuring this tenant first, as you install and configure content on the development tenant.

As configuration and content propagate from the main tenant to the child tenant, you should configure the main tenant before the child tenant. If you initially sync a child tenant, it will not contain any data, as you have not yet synced the main tenant.

1. On the development tenant, do the following:
   1. Familiarize yourself with user management in Cortex XSOAR 8, as it is different from Cortex XSOAR 6.

      * Identify the roles you have defined in Cortex XSOAR 6.
      * Recreate the roles in Cortex XSOAR 8 with the same permissions you have for each role on Cortex XSOAR 6 (if the role is not already present in Cortex XSOAR 8).
      * If you have nested roles in Cortex XSOAR 6, create user groups in Cortex XSOAR 8 to replicate the nested roles in Cortex XSOAR 6. The nested direction is reversed in Cortex XSOAR 8. For more information about user groups, see [User group management](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/user-group-management.md).

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>You can't sync roles between dev and prod tenants and between the Main tenant and child tenants. You need to create roles on each tenant. If you want to create roles for all tenants, you can create them in Cortex Gateway.</p></div>
   2. Install and configure Marketplace content.
      * In Cortex XSOAR 8, install the content packs used in Cortex XSOAR 6. After installation, configure each Cortex XSOAR 8 integration instance. Verify mappers and classifiers are set correctly for each instance.

        <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Some integrations are configured differently for Cortex XSOAR 8. For further information about the integration configuration changes, see <a href="/spaces/nPfgrPjdRQBvgLTOrM8C/pages/c5JAEJeIN1BfobnndsBs">Reconfigure integrations</a>.</p></div>
      * If you have integration instances in Cortex XSOAR 6 that connect to internal resources, and those resources cannot be reached by Cortex XSOAR 8 due to firewalls or other limitations, deploy engines to act as connectors between your internal endpoint accessed by the integration and Cortex XSOAR 8. For more information about engines, see [Set up an engine](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-2.-set-up-an-engine.md).
      * Verify all integrations work in Cortex XSOAR 8.
      * If you have been using RBAC in Cortex XSOAR 6 for integrations/integration commands, configure the same RBAC settings for Cortex XSOAR 8. For more information, see [Configure integration permissions](/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md).
   3. Move custom content from Cortex XSOAR 6 to Cortex XSOAR 8.
      * In Cortex XSOAR 6, export your custom content.

        Go to **Settings** → **About** → **Troubleshooting**, scroll down until you see the **Custom Content** section, and click **Export**.
      * In Cortex XSOAR 8, upload your custom content.

        Go to **Settings & Info** → **Settings** → **System** → **Server Settings**. In the **Custom Content** section, drag and drop the exported file.
   4. Create API keys in Cortex XSOAR 8 and update third-party services. For more information, see [API Keys in Cortex XSOAR 8 - Multi-Tenant](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/api-keys-in-cortex-xsoar-8-multi-tenant.md).
   5. Configure jobs in Cortex XSOAR 8 to match how they are set up in Cortex XSOAR 6.
2. On the main tenant, repeat step 1.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>In a dev/prod environment, you can't install and configure Marketplace content on a production machine.</p></div>
3. On the child tenant, repeat step 1.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>At this stage, do NOT enable fetching for integration instances in Cortex XSOAR 8.</p></div>

</details>

<details>

<summary>Task 3. Perform validation testing</summary>

Perform validation testing on each tenant. It doesn't matter in which order you do this.

1. If using a dev/prod environment, ensure you can push and pull content between tenants. For more information, see [Push content from a development tenant](/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md).
2. Check that you can sync content from the Main Tenant to the child tenant.

   Before syncing, ensure that you have the required propagation labels. For more information, see [Sync content to child tenants](/cortex-xsoar-8-saas/multi-tenant/child-tenant-management/content-management-in-multi-tenant/sync-content-to-child-tenants.md).
3. On the child tenant:
   1. Check that the content has been synced from the Main Tenant.
   2. Temporarily enable incident fetching in your Cortex XSOAR 8 integration instances.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If your Cortex XSOAR 6 production server is also fetching on Cortex XSOAR 8, this will fetch the same incidents into both platforms.</p></div>
   3. After incidents are fetched into Cortex XSOAR 8, verify that all playbooks execute correctly, that they run through to completion, and that all automations work.
   4. After testing, disable incident fetching in your Cortex XSOAR 8 integration instances.
   5. If using External Dynamic Lists, confirm you have configured the Generic Export Indicators integration. In Cortex XSOAR 8, the Generic Export Indicators integration requires a username and password. For more information about the Generic Export Indicators integration, see [Export Indicators](/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md).
   6. Confirm that API triggers work if you use the API to ingest incidents.
4. On all tenants, verify that all playbooks, scripts, and jobs (not the main tenant) run correctly.

</details>

<details>

<summary>Task 4. Set up access to Cortex XSOAR 8 for additional users</summary>

You can authenticate users by doing one or both of the following options:

* Authenticate users through the Customer Support Portal (CSP)
* SAML Single Sign-On (SSO)

If you do not want a user to have access to all tenants, the user should be added using SSO in each tenant. For example, for an MSSP with co-managed tenants (a tenant where management is shared between the MSSP and the end customer), the MSSP’s analysts and the end customer’s analysts need access to the child tenant. If the MSSP’s analysts need access to every child tenant (for multiple end customers), you can add them in the CSP or through SSO, by configuring SSO for the main tenant and each child tenant.

To restrict users' access to only one tenant, the end customer’s analysts must have SSO access configured directly on the child tenant. End customer users should not be created as users in the CSP. If you require users to be automatically propagated to all tenants, you must use the CSP. SSO does not propagate from the main tenant to the child tenants.

* If you are not using SSO, add all users to the CSP portal to grant users access to the Cortex XSOAR 8 tenant.
* If you are using SSO, configure SSO in your Cortex XSOAR 8 tenants and your identity provider. For more information, see [Authenticate users using SSO](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md).
* After user access has been set up, verify that users can log into Cortex XSOAR 8.
* Verify RBAC functionality works correctly.

</details>

<details>

<summary>Task 5. Post-migration steps</summary>

Perform the post-migration steps on each tenant. It doesn't matter in which order you do this.

1. Enable fetching in all of your integration instances.
2. In a dev/prod environment, push, pull, and install content on the prod machine. For more information, see [Install Content on a Production Tenant](/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md).
3. If you have not done so already, sync content between the child tenant and the main tenant.
4. Disable activity on Cortex XSOAR 6:

   * Disable all jobs
   * In your integration instances, disable fetching incidents.
   * Wait for all playbooks to finish and for all open incidents to complete.
   * Disable all enabled integration instances.

   Cortex XSOAR 8 can now be used as your working environment.

{% hint style="info" %}

### Note

Any third-party services that need to access Cortex XSOAR 8 must be updated with the new API and EDL information.
{% endhint %}

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-self-service.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
