For organizations that have multiple CLP accounts for business, administrative, legal, or other considerations, Cloud App Security deploys separate tenants for each CLP account. Each tenant environment on the management console can be accessed only by the corresponding CLP account and the local administrator accounts created under the tenant.
To ease the cross-tenant security analytics and management within your organization, Cloud App Security allows you to associate a local administrator account with multiple Cloud App Security tenants, so you can switch among and manage these tenants with one single account on the management console, without repeated logoff and logon using different administrator accounts.
Make sure that the Cloud App Security tenants you want to associate are in the same Cloud App Security serving site, for the example, the US site. For more information about the Cloud App Security sites, see Data Center Geography.
Multi-tenant switching is also available for Trend Micro LMP customers.
The steps outlined below detail how to create and use an administrator account to switch among multiple Cloud App Security tenant environments on the management console. This procedure uses three tenants A, B, and C with CLP accounts A, B, and C respectively as an example.
On the Administrators screen, the status of this account under Multi-Tenant Switching is No. After it is added to another tenant, the status will change to Yes.
SSO to Console and Role change to Inherited. This administrator shares the same settings as configured in the tenant, for example, tenant A in this section, where it was created. The settings are not editable in the current tenant. You can go to tenant A to view and modify the settings for this administrator.
The administrator account is successfully added and displayed on the Administrators screen in the current tenant.
The Dashboard screen of tenant A the appears.
The tenant list with the respective CLP account name appears, with tenant A selected. The tenant where the administrator account was created always displays at the top.
The Dashboard screen of the selected tenant appears.
This administrator account can be removed from where it was created (tenant A in this procedure) only after it is removed from all the associated tenants (tenants B and C in this procedure).
The tenant disappears from the Switch tenant list.
Only the tenant where the account was created (tenant A in this procedure) appears in the Switch tenant list.