Add Child Tenants for MSP
Focus
Focus
Prisma Browser

Add Child Tenants for MSP

Table of Contents

Add Child Tenants for MSP

Add child tenants to your MSP root tenant using term subscription or Pay-As-You-Go billing.
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Prisma Browser Standalone license or PayGo SKU activated on the root tenant
  • Strata Cloud Manager Pro license
  • Cloud Identity Engine (included, spun up during activation)
  • Identity & Access role: Multitenant Superuser or Superuser
The Prisma Browser MSP allows you to add child tenants beneath the root tenant to deliver browser-based security to multiple customers. Each child tenant operates as a fully isolated environment with dedicated users, policies, and security telemetry. You create and manage child tenants from the root tenant where your license is activated.
You can onboard child tenants using one of two billing models:
  • Term Subscription—You activate a Prisma Browser Standalone license on the root tenant and allocate seats to child tenants from a shared license pool. Licensing is prepaid and capacity-based.
  • Pay-As-You-Go (PayGo)—You activate a PayGo SKU on the root tenant and create child tenants with monthly postpaid billing. You are billed based on the packages activated each day during the billing cycle, allowing you to scale as your customer base grows.
Before you configure Cloud Identity Engine, decide on the Identity Provider type that best meets your requirements:
  • MSP IdP—Required when an MSP customer doesn't have their own IdP. You set up users and groups within your IdP and integrate this IdP with CIE at the root tenant, which can authenticate users in the child tenant.
  • Tenant-Specific IdP—Uses an MSP customer's own IdP connected to a tenant-level CIE. If you plan to use the tenant-specific IdP type, ensure that the customer's IdP is ready and can interface with the tenant-specific CIE.
Select the billing model that matches your deployment to continue:

Pay-As-You-Go (PayGo)

Onboard a child tenant for Prisma Browser using the PayGo monthly postpaid billing model.
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Multitenant Superuser or Multitenant Manage User role
  • PayGo activated on your root tenant
  • Available credits in your PayGo credit pool
After activating the PayGo SKU on the absolute root tenant, you can create child tenants and activate Prisma Browser on them. The PayGo activation enables PayGo workflows in the MSP Portal, allowing you to onboard multiple tenants and configure different packages and quantities for each tenant.
Prisma Browser provides browser-based security for users accessing SaaS and web applications. It is suitable for tenants that require secure web access without the full network security capabilities of Prisma Access SASE. Use this workflow to onboard customers who require browser-level protection or to offer a lightweight security solution as part of your managed service portfolio. The minimum user allocation is 1 mobile user.
You perform this from the root tenant where the PayGo SKU is activated. The onboarding workflow creates a new child Tenant Service Group (TSG) in the tenant hierarchy and provisions Prisma Browser, Cloud Identity Engine, and Partner Premium Support for the new tenant.
Packages activated on the child tenant are included in the monthly postpaid billing based on the packages activated each day during the billing cycle.
To onboard a child tenant with PayGo billing:
  1. Select ConfigurationWorkflowsTenant OnboardingActivate New Tenant with PayGo Postpaid Billing Model and click Start Onboarding.
  2. Choose Prisma Browser Core from the available packages and click Next.
  3. Step 1 - Set up the tenant.
    1. In Tenant Name, enter a unique name for the child tenant.
    2. For Tenant Industry Vertical, choose the industry segment for this tenant.
    3. In Domain, enter the tenant's primary email domain.
    4. For Region, choose the SLS location where you want to deploy this tenant. This must match the CIE region of the root tenant if you choose to use MSP IdP.
    5. In User Quantity, enter the number of mobile users (minimum 1).
    6. (Optional) Enable Private App Access to provide access to private applications.
  4. Step 2 - Configure the Identity Provider.
    1. Select the Identity Provider type:
      • MSP IdP—The tenant uses the MSP's shared identity provider. The MSP sets up users and groups within their IdP and integrates the IdP with CIE at the root tenant, which authenticates users in the child tenant. Cloud Identity Engine resolves the MSP directory, domains, and user groups for this tenant.
      • Tenant Specific IdP—The tenant uses its own identity provider. Enter the IdP configuration details (SAML or OIDC settings), including metadata URL, domain, and user group mappings
    2. Entity ID and ACS URL are auto-populated.
    3. For Vendor, choose the Identity Provider, such as Entra, Okta, PingOne, CyberArk, Google, or PingFederate, and set up the identity provider.
    4. Identity Provider Metadata URL: enter the metadata URL you generated at the Identity Provider and verify the URL. The Identity Provider ID and SSO URL fields are populated using the URL you provided. If you see any issues with the information in these fields, correct it on the IdP vendor site and upload the metadata again.
  5. Review the onboarding summary and click Onboard to provision the tenant.
    Tenant provisioning is asynchronous and takes a few minutes. During this time, the system creates the child TSG, provisions Prisma Browser, configures CIE with your IdP settings, and applies a best-practice security policy. Once complete, the tenant status changes to Onboarding Complete in the Business dashboard. If provisioning fails, the Business dashboard displays the error in the tenant status column.
  6. After provisioning completes, verify the tenant activity details and activity logs.
    1. Select the newly created tenant from the tenant hierarchy.
    2. Review the Activity Details panel to confirm the onboarding status, allocated package, and mobile user quantity.
    3. Select Activity Log to view the chronological record of all actions performed on this tenant, including the onboarding event with timestamp, user, and description.

Add Child Tenants for MSP

Add child tenants for Prisma Browser MSP
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Prisma Browser Standalone License
  • Strata Cloud Manager Pro License
  • Cloud Identity Engine is included and spun up during activation.
  • Identity & Access role: Multitenant Superuser or Superuser
The Prisma Browser MSP allows you to add additional child tenants beneath the root level. This means that you need one standalone license that will be activated on the root tenant, which is shared across multiple child tenants. This article describes the detailed step-by-step instructions needed to add and onboard the child tenants.
Before You begin
Before you configure the CIE, decide on the Identity Provider type that best meets your requirements:
  • MSP IdP: Required when an MSP customer does not have their own IDP. In that case, MSP need to setup users and groups within their IDP and integrate this IdP with our CIE at the root tenant which can authenticate users in their tenant.
    Tenant-Specific IdP: Uses an MSP customer’s own IdP connected to a tenant-level CIE.
    If you plan to use the tenant-specific IdP type, ensure that the customer’s IdP is ready and can interface with the tenant-specific CIE.
To add child tenants to the MSSP root tenant, perform the following:
  1. Select the tenant where you have activated the Prisma Browser Standalone license and want to add the child tenants.
  2. Select Summary > Prisma Browser.
  3. Click Add Tenant to create and onboard child tenants on the root tenant where you activated the Prisma Browser license. You can add and onboard the tenants using the step-by-step guided wizard.
    1. Step 1 - Tenant Configuration
      1. Specify a Name for the child tenant.
      2. Select the Region, the SLS location where you want to deploy this tenant.
      3. Subscription is auto-populated based on the activated license.
      4. the User Quantity, the number of Prisma Browser Standalone licenses to allocate to this child tenant.
    2. Step 2 - Identity Provider Configuration You can configure two types of Identity Providers(IdP):
      • Tenant Specific IDP
        Select the type as Tenant Specific IdP and ensure that the customer's IdP is ready and can interface with the tenant-specific CIE.
      • MSP IdP
        Ensure that the CIE is configured at the root tenant. Select the appropriate Root Directory, Authentication Profile, and User Groups configured in the root tenant.
    3. Review the summary and click Create Tenant.
You can repeat the Add Tenant procedure to add the required number of tenants. You can view the list of tenants added and also the status of the tenant onboarding at Summary > Prisma Summary.