: Manage Bulk Configurations Through the Strata Multitenant Cloud Manager
Focus
Focus

Manage Bulk Configurations Through the Strata Multitenant Cloud Manager

Table of Contents

Manage Bulk Configurations Through the Strata Multitenant Cloud Manager

Learn how to manage bulk configurations through the Strata Multitenant Cloud Manager
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Prisma Access license
  • Enterprise Data Loss Prevention (E-DLP) license
  • Identity & Access role: Multitenant Superuser or Superuser
The Strata Multitenant Cloud Manager enables Managed Security Service Providers (MSSP) or distributed enterprise customers of Prisma Access to define and enforce global security policies through Prisma Access and data protection configurations through Enterprise DLP in all or some of their child tenants. You would use this to create repeatable common configurations that can be applied to many tenants, while allowing for granular customization of configurations at the individual tenants for local tenant admins. Bulk configuration management is only supported for Cloud managed tenants. Panorama managed tenants are not be supported as part of this feature.
If you activate a Prisma Access license or Enterprise DLP license at the parent-level of your tenant hierarchy, you can access ManageBulk Configuration to manage bulk configurations for Prisma Access and Enterprise DLP.

Prisma Access Bulk Configuration

You can manage Prisma Access security policies across child tenants through the following capabilities:

Enterprise DLP Bulk Configuration

You can synchronize Enterprise DLP configuration objects from the parent tenant to child tenants to maintain a consistent data protection baseline across all managed environments. The following DLP configuration objects can be synchronized:
  • DLP rules and their required referenced objects
  • Detection methods (data patterns, data dictionaries, and Optical Character Recognition)
  • DLP settings (sensitive data and data transfer configurations)
Any configuration objects you synchronize from the parent tenant remain read-only on the child tenant. You must manage these shared objects exclusively from the root-level parent.