> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-1.-activate-cortex-xsoar-8-saas-multi-tenant.md).

# Step 1. Activate Cortex XSOAR 8 SaaS Multi-Tenant

## Step 1. Activate Cortex XSOAR 8 SaaS Multi-Tenant

You need to activate the Cortex XSOAR 8 tenants in Cortex Gateway.

If you have a Cortex XSOAR 6 multi-tenant/MSSP license, in Cortex XSOAR 8, you can activate a main tenant and one child tenant. If you want to activate more child tenants, you need an additional license. For more information, contact Customer Support.

**Before you begin**

* The Cortex XSOAR activation email.
* A Customer Support Portal (CSP) account.

  You need to set up your CSP account. For more information, see [How to Create Your CSP User Account](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNVCA0).

  When you create a CSP account you can set up two-factor authentication (2FA) to log into the CSP, by using an Email, Okta Verfiy, or Google Authenticator (non-FedRAMP accounts). For more information, see [How to Enable a Third Party IdP](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sZ8mCAE).

In Cortex Gateway, you can view the following:

* Tenant details such as license type, number of users, and purchase date.
* Tenants that were activated and are now available. If you have more than one CSP account, the tenants are displayed according to the CSP account name.
* If you are a CSP Account Admin, you can see tenants allocated to your CSP account and ready for activation. After activation, you cannot move your tenant to a different CSP account.

{% hint style="info" %}

### Note

After you create your CSP account, the Super User role is assigned to your CSP account. The user who creates the CSP account is granted the Super User role. If you are the first user to access Cortex Gateway with the CSP Super User role, you are automatically granted Account Admin permissions for Cortex Gateway.

To log into Cortex Gateway, enter your username and password or multi-factor authentication (if set up) by using your CSP account credentials to sign in.
{% endhint %}

You need to activate each tenant separately. When you activate, the first activated tenant is both a production and main tenant, but is labeled **Main Account**. After activation, you can set up a development tenant (subject to your license) and a child tenant. It doesn't matter if you activate a child tenant before a development tenant. If you have many child tenants, you can choose whether to use the wizard or start fresh without using the wizard.

<details>

<summary>Task 1. Activate the main tenant</summary>

1. From Cortex Gateway, in the **Available for Activation** section, use the serial number to locate the tenant that needs activation, and then click **Activate as SAAS**.
2. In the **ACTIVATE XSOAR 8 MAIN TENANT** dialog box, select **Migrate your tenant**.

   If you don't want to use the migration wizard, select **Start Fresh**. For more information about migrating your data without using the wizard, see [Migrate from Cortex XSOAR 6 Multi-Tenant to Cortex XSOAR 8 SaaS Multi-Tenant (Self-Service)](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-self-service.md).

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If you select <strong>Start Fresh</strong>, you can't use the migration wizard for any development or child tenants.</p></div>
3. On the **Tenant Activation** page, define the following:

   | Parameter        | Description                                                                                                                                                                                                                                                                                                         |
   | ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Tenant Name      | <p>Enter the name of the tenant. Use a unique name across your company account up to 59 characters long.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Important</strong></p><p>The main tenant must have the same main tenant name in Cortex XSOAR 6.</p></div> |
   | Region           | Geographic location where your tenant will be hosted. For more information about supported regions, see [Supported host regions](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/supported-host-regions.md).                                                                |
   | Tenant Subdomain | <p>DNS record associated with your tenant. Enter a name that will be used to access the tenant directly using the full URL:</p><p><code>https\://\<subdomain>crtx.\<region>.paloaltonetworks.com</code></p>                                                                                                         |
4. Review and **agree to the terms and conditions of the Privacy policy, Terms of Use, EULA** , and then **Activate** your tenant.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Activation can take about an hour and does not require you to remain on the activation page. Cortex XSOAR sends a notification to your email when the process is complete.</p></div>
5. Enable access to Palo Alto Networks resources in your firewall. See [Enable access to Palo Alto Networks resources](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).
6. Set up initial user access in the Customer Support Portal (CSP) for administrators who will set up Cortex XSOAR 8.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Account admins have access to all tenants in the CSP account, including any existing Account admins who were set up before the migration. For example, if you had a Cortex XDR Account Admin user in your CSP account, that user would also have access to Cortex XSOAR.</p></div>

   * Verify the user is in the CSP portal.
   * Grant the Instance Administrator role to the users who will manage the initial setup. For more information, see [Manage roles in Cortex Gateway](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-cortex-gateway.md).

</details>

<details>

<summary>Task 2. Activate the development tenant</summary>

If you don't have a development license, you can skip this task.

1. In Cortex Gateway, hover over the **Main Account** you activated in Task 1, on the right-hand side, click the ellipsis, and click **Migrate Dev Tenant.**

   ![migrate-dev-tenant.png](/files/RCGiMMv2Gu1cXJkl8mQS)
2. In the **ACTIVATE XSOAR 8** dialog box, select **Migrate Dev Tenant.**
3. Define the following fields:

   | Parameter            | Description                                                                                                                                                                                                                                          |
   | -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Dev Tenant Name      | Give the Cortex XSOAR development tenant an easily recognizable name. Choose a name that is 59 or fewer characters and is unique across your company account.                                                                                        |
   | Region               | Geographic location where your tenant will be hosted. For more information about supported regions, see [Supported host regions](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/supported-host-regions.md). |
   | Dev Tenant Subdomain | <p>Enter a name that will be used to access the tenant directly using the full URL:</p><p><code>https\://\<subdomain>crtx.\<region>.paloaltonetworks.com</code></p>                                                                                  |
4. Activate the development tenant.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>After activation, you can change your tenant name and domain name, including any dev/prod tenant.</p></div>

   Activation can take about an hour and does not require you to remain on the activation page. Cortex XSOAR sends a notification to your email when the process is complete.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>In the pre-migration wizard, you can set up the built-in or private content repository.</p></div>
5. Enable access to Palo Alto Networks resources in your firewall. See [Enable access to Palo Alto Networks resources](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).
6. Set up initial user access in the Customer Support Portal (CSP) for administrators who will set up Cortex XSOAR 8.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Account admins have access to all tenants in the CSP account, including any existing Account admins who were set up before the migration. For example, if you had a Cortex XDR Account Admin user in your CSP account, that user would also have access to Cortex XSOAR.</p></div>

   * Verify the user is in the CSP portal.
   * Grant the Instance Administrator role to the users who will manage the initial setup. For more information, see [Manage roles in Cortex Gateway](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-cortex-gateway.md).

</details>

<details>

<summary>Task 3. Activate the child tenant</summary>

1. In Cortex Gateway, hover over to the **Main Account** you activated in Task 1, on the right-hand side, click the ellipsis, and then click **Add Child Tenant**.

   ![child-activation.png](/files/nRSSW4Hi0CQNvE3qdTlD)
2. In the **ACTIVATE XSOAR 8 CHILD TENANT** dialog box, select one of the following:

   * **Migrate your tenant**: Starts the migration wizard process in the child tenant.
   * **Start Fresh**: A new child tenant is created without the wizard.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>You can have a mixture of both wizard and non-wizard migration tenants.</p></div>
3. Add the following details:

   | Parameter              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
   | ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Child Tenant Name      | <p>Give the Cortex XSOAR tenant an easily recognizable name.</p><p>Choose a name that is 59 or fewer characters and is unique across your company account.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Important</strong></p><p>The child tenant must have the same account name in Cortex XSOAR 6.</p></div>                                                                                                                                               |
   | Region                 | View the region for the child tenant. This can't be changed.                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | Child Tenant Subdomain | <p>Give your Cortex XSOAR instance an easy-to-recognize name that is used to access the tenant directly using the full URL.</p><p>https\://\<subdomain>.crtx.<<em>region</em>>.paloaltonetworks.com</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>This is a public FQDN, so be careful with sensitive information such as the company name.</p><p>After activating a child tenant, you can't change the child tenant Subdomain.</p></div> |
4. Confirm that you will proceed with the data transfer in the selected region and activate the child tenant.

   Activation can take up to an hour. You should receive a notification by email that the child tenant has completed the activation process.
5. Enable access to Palo Alto Networks resources in your firewall. See [Enable access to Palo Alto Networks resources](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).
6. Set up initial user access in the Customer Support Portal (CSP) for administrators who will set up Cortex XSOAR 8.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Account admins have access to all tenants in the CSP account, including any existing Account admins who were set up before the migration. For example, if you had a Cortex XDR Account Admin user in your CSP account, the same user has access to Cortex XSOAR.</p></div>

   * Verify the user is in the CSP portal.
   * Grant the Instance Administrator role to the users who will manage the initial setup. For more information, see [Manage roles in Cortex Gateway](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-cortex-gateway.md).

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-1.-activate-cortex-xsoar-8-saas-multi-tenant.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
