<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate to New Tenant in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/migrate-to-new-tenant/m-p/553610#M4955</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The migration of endpoints and configurations in Cortex XDR is a manual process and involves planning and manual efforts for the same.&lt;/P&gt;
&lt;P&gt;Following is being assumed here:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You have no third party/ Pro Per TB license&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;You do not have Airgapped systems behind brokers&lt;/LI&gt;
&lt;LI&gt;You do not have Kubernetes agents deployed in your environment&lt;/LI&gt;
&lt;LI&gt;You have already whitelisted all the URLs related to the new tenant required for agent communication.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I am listing the steps down in chronological order for use case and adoption for the same.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN class="il"&gt;Export&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;profiles&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;policies and associated exceptions.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Add them and create them in new tenant.&lt;/LI&gt;
&lt;LI&gt;Import any custom IOC/BIOC rules created and import them to the new tenant&lt;/LI&gt;
&lt;LI&gt;Create dynamic endpoint groups as in the old tenant&lt;/LI&gt;
&lt;LI&gt;Configure global settings as per recommended practice or replicate the same(recommended to use new practice as the new instance would be on v3.7)&lt;/LI&gt;
&lt;LI&gt;Add hash allowlist/block list using hash exceptions&lt;/LI&gt;
&lt;LI&gt;Create alert exclusions as per the used case or replicate as per the old tenant&lt;/LI&gt;
&lt;LI&gt;Check any global exceptions or exceptions.&lt;/LI&gt;
&lt;LI&gt;Incident Configuration Migrations(Exclusions, Scoring, Featured Fields)&lt;/LI&gt;
&lt;LI&gt;Export/Import Uncommon Host Firewall Rule Groups&lt;/LI&gt;
&lt;LI&gt;Create and append all scheduled queries and library queries&lt;/LI&gt;
&lt;LI&gt;Validate and migrate test batches to see if the behaviour is same.&lt;/LI&gt;
&lt;LI&gt;Migrate Agents using console or cytool commands as and when applicable.&lt;/LI&gt;
&lt;LI&gt;Delete all the existing packages in the old tenant so that the offline existing packages become unusable for agent communication on erroneous&amp;nbsp;installation.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;All of this would require some coordination and efforts from your internal teams (IT, servers, infrastructure and network teams) and needs to be handled manually.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps. Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Aug 2023 05:16:18 GMT</pubDate>
    <dc:creator>neelrohit</dc:creator>
    <dc:date>2023-08-14T05:16:18Z</dc:date>
    <item>
      <title>Migrate to New Tenant</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/migrate-to-new-tenant/m-p/553605#M4954</link>
      <description>&lt;P&gt;Hi XDR Experts,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For reasons, we need to migrate all the agents from existing "tenant A" to a new "tenant B" before the old one expires.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any automated/faster way to do so?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or we need to do it manually with bunch of export and import, change to the new managing server in the old tenant.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For manual procedure that come up to my mind,&lt;/P&gt;
&lt;P&gt;1) Activate new tenant&lt;/P&gt;
&lt;P&gt;2) Under old tenant, Export profiles (malware, exploit, agent setting, device control configuration,&amp;nbsp;&lt;SPAN&gt;Disk Encryption Profile&lt;/SPAN&gt; ), policies, exception rules, host firewall rules, global exceptions&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) Under new tenant, Import the settings from step2.&lt;/P&gt;
&lt;P&gt;4) Generate new agent installer (&lt;SPAN&gt;Agent Installation Id)&amp;nbsp;&lt;/SPAN&gt;in new tenant&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5) Change managing server with&amp;nbsp;&lt;SPAN&gt;Agent Installation Id (step 4) in the old tenant.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;6) Confirm the agents appear in the new tenant.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is there any missing?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your comments are welcome.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 02:59:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/migrate-to-new-tenant/m-p/553605#M4954</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2023-08-14T02:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate to New Tenant</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/migrate-to-new-tenant/m-p/553610#M4955</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The migration of endpoints and configurations in Cortex XDR is a manual process and involves planning and manual efforts for the same.&lt;/P&gt;
&lt;P&gt;Following is being assumed here:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You have no third party/ Pro Per TB license&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;You do not have Airgapped systems behind brokers&lt;/LI&gt;
&lt;LI&gt;You do not have Kubernetes agents deployed in your environment&lt;/LI&gt;
&lt;LI&gt;You have already whitelisted all the URLs related to the new tenant required for agent communication.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I am listing the steps down in chronological order for use case and adoption for the same.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN class="il"&gt;Export&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;profiles&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;policies and associated exceptions.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Add them and create them in new tenant.&lt;/LI&gt;
&lt;LI&gt;Import any custom IOC/BIOC rules created and import them to the new tenant&lt;/LI&gt;
&lt;LI&gt;Create dynamic endpoint groups as in the old tenant&lt;/LI&gt;
&lt;LI&gt;Configure global settings as per recommended practice or replicate the same(recommended to use new practice as the new instance would be on v3.7)&lt;/LI&gt;
&lt;LI&gt;Add hash allowlist/block list using hash exceptions&lt;/LI&gt;
&lt;LI&gt;Create alert exclusions as per the used case or replicate as per the old tenant&lt;/LI&gt;
&lt;LI&gt;Check any global exceptions or exceptions.&lt;/LI&gt;
&lt;LI&gt;Incident Configuration Migrations(Exclusions, Scoring, Featured Fields)&lt;/LI&gt;
&lt;LI&gt;Export/Import Uncommon Host Firewall Rule Groups&lt;/LI&gt;
&lt;LI&gt;Create and append all scheduled queries and library queries&lt;/LI&gt;
&lt;LI&gt;Validate and migrate test batches to see if the behaviour is same.&lt;/LI&gt;
&lt;LI&gt;Migrate Agents using console or cytool commands as and when applicable.&lt;/LI&gt;
&lt;LI&gt;Delete all the existing packages in the old tenant so that the offline existing packages become unusable for agent communication on erroneous&amp;nbsp;installation.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;All of this would require some coordination and efforts from your internal teams (IT, servers, infrastructure and network teams) and needs to be handled manually.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps. Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 05:16:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/migrate-to-new-tenant/m-p/553610#M4955</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-08-14T05:16:18Z</dc:date>
    </item>
  </channel>
</rss>

