Add User Access Through the
Prisma SASE Multitenant Cloud Management Platform

Learn how to add user access through the
Prisma SASE Multitenant Cloud Management Platform
.
The
Prisma™ SASE Multitenant Cloud Management Platform
enables you to add user access to the platform as well as to the Prisma Access tenants you created.
A Palo Alto Networks Customer Support Account is only necessary for users who need to perform onboarding tasks. Other users can be invited to use Palo Alto Networks single sign on without Customer Support Accounts. However, If you integrate with a third party IDP for your enterprise, you do not have to add user accounts explicitly in the platform as they will be automatically added when they are successfully authenticated. However, roles need to be assigned for all users. To ensure a seamless login and authorization experience for your users, you can add users and assign roles for them ahead of time.
After you add a tenant, you can add user access from
Common Services
Identity & Access/Access Management
.
Any user access added to a tenant is also automatically added to all of that tenant's children.
  1. Go to the hub and log in.
  2. Select
    SASE Portal
    .
  3. Select
    Multitenant Portal
    .
  4. Select
    Identity & Access/Access Management
    .
  5. Select the tenant for which you want to add user access. For example:
    • Select the ParentTenant for a user who needs access to all the tenants in the hierarchy.
    • Select the ChildTenant for a user who only needs access to a single tenant or to a subset of tenants in the hierarchy.
    • About identity and access for more information.
  6. Select
    Add
    .
  7. Specify the following values to add user access:
    1. Select
      User
      as the
      Identity Type
      .
    2. Enter the email address of the user and select
      Next
      .
    The
    Prisma SASE Multitenant Cloud Management Platform
    attempts to verify that the email address you entered is registered with a Palo Alto Networks Customer Support Account.
  8. If the email address you entered in the previous step is not yet registered with a Palo Alto Networks Customer Support Account, you are prompted to
    Send Invite
    to invite the user to register.

Recommended For You