Add Child Tenants for MSP
Focus
Focus
Prisma Browser

Add Child Tenants for MSP

Table of Contents

Add Child Tenants for MSP

Add child tenants for Prisma Browser MSP
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Prisma Browser Standalone License
  • Strata Cloud Manager Pro License
  • Cloud Identity Engine is included and spun up during activation.
  • Identity & Access role: Multitenant Superuser or Superuser
The Prisma Browser MSP allows you to add additional child tenants beneath the root level. This means that you need one standalone license that will be activated on the root tenant, which is shared across multiple child tenants. This article describes the detailed step-by-step instructions needed to add and onboard the child tenants.
Before You begin
Before you configure the CIE, decide on the Identity Provider type that best meets your requirements:
  • MSP IdP: Required when an MSP customer does not have their own IDP. In that case, MSP need to setup users and groups within their IDP and integrate this IdP with our CIE at the root tenant which can authenticate users in their tenant.
    Tenant-Specific IdP: Uses an MSP customer’s own IdP connected to a tenant-level CIE.
    If you plan to use the tenant-specific IdP type, ensure that the customer’s IdP is ready and can interface with the tenant-specific CIE.
To add child tenants to the MSSP root tenant, perform the following:
  1. Select the tenant where you have activated the Prisma Browser Standalone license and want to add the child tenants.
  2. Select Summary > Prisma Browser.
  3. Click Add Tenant to create and onboard child tenants on the root tenant where you activated the Prisma Browser license. You can add and onboard the tenants using the step-by-step guided wizard.
    1. Step 1 - Tenant Configuration
      1. Specify a Name for the child tenant.
      2. Select the Region, the SLS location where you want to deploy this tenant.
      3. Subscription is auto-populated based on the activated license.
      4. the User Quantity, the number of Prisma Browser Standalone licenses to allocate to this child tenant.
    2. Step 2 - Identity Provider Configuration You can configure two types of Identity Providers(IdP):
      • Tenant Specific IDP
        Select the type as Tenant Specific IdP and ensure that the customer's IdP is ready and can interface with the tenant-specific CIE.
      • MSP IdP
        Ensure that the CIE is configured at the root tenant. Select the appropriate Root Directory, Authentication Profile, and User Groups configured in the root tenant.
    3. Review the summary and click Create Tenant.
You can repeat the Add Tenant procedure to add the required number of tenants. You can view the list of tenants added and also the status of the tenant onboarding at Summary > Prisma Summary.