Create a Tenant-Level Administrative User
Focus
Focus
Prisma Access

Create a Tenant-Level Administrative User

Table of Contents

Create a Tenant-Level Administrative User

Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama)
  • For information about managing multiple tenants in Prisma Access (Managed by Strata Cloud Manager), see Prisma SASE.
You should create an administrative user for each tenant. In that way, a tenant-level administrator can view and make changes to their tenant configuration but doesn’t have access to other tenants. To create an administrative user for a specific tenant, complete the following task. For more information about role-based access control (RBAC) for tenant-level administrative users, see Control Role-Based Access for Tenant-Level Administrative Users.
Users who manage single tenants cannot see the system logs because the MonitorLogsSystem choice is not available. This limitation applies to all Administrators who have an administrative role of Device Group and Template. Only superusers can view system logs in multitenancy mode.
  1. Create an administrative role with a type of Device Group and Template.
    1. Select PanoramaAdmin Roles.
    2. Add an Admin Role Profile with a Role of Device Group and Template.
    3. Click OK.
      You can create a single Admin Role Profile and share it across multiple tenants; however, you must create a separate administrator for each tenant.
      While you tailor the administrative role for the needs of your organization, we recommend deselecting Commit for Other Admins. Deselecting this choice allows a tenant-level user to commit only the changes they have made, and prevents them from unintentionally committing other changes that other tenant-level administrative users have made that are not yet committed.
  2. Create and configure an Administrator for the tenant.
    1. Select PanoramaAdministrators.
    2. Add an Administrator.
    3. Enter and confirm a Password for the new Administrator.
    4. Specify an Administrator Type of Device Group and Template Admin.
    5. Specify the Access Domain that is associated with the device groups for that tenant.
    6. Specify the Admin Role that you created in Step 1 for the tenant.
  3. Click OK.
  4. Repeat Steps 2 and 3 to add additional users to manage your tenants as required.
  5. Select CommitCommit to Panorama and Commit your changes.