Configuration/Whitelistings accross mutliple Cortex Tenants

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Configuration/Whitelistings accross mutliple Cortex Tenants

L0 Member

Hello everyone

I am working in an MSSP environment and managing several Cortex XDR tenants. While reviewing the official Palo Alto Networks documentation and online resources, I couldn’t find any information about whether it is possible to create configurations (such as exceptions, exclusions, custom detections likes BIOCs etc.) once and apply them across multiple tenants at the same time. A parent-child tenant constellation does not seem to offer this functionality.


For MSSPs, having to manually create the same exceptions or configuration changes for multiple individual tenant is extremely time‑consuming. It seems logical that a centralized mechanism should exist for this type of multi‑tenant operational need.


Does anyone know if Palo Alto provides any native capability, roadmap feature, or recommended best practice for pushing shared configurations or whitelists across multiple managed tenants? Or is manual replication still the only option?


Any insights, workarounds, or official guidance would be highly appreciated.


Thank you!

1 accepted solution

Accepted Solutions

L5 Sessionator

Hello @MaaHaa ,

 

Greetings for the day.

 

Yes, Cortex XDR provides native capabilities for MSSPs to create configurations once in a parent (main) tenant and apply them across multiple child tenants. This centralized management mechanism allows you to push security policies, exclusions, and rules without manual replication for each individual tenant.

Centralized Management Mechanism:

The core functionality is based on creating configurations in the parent tenant and then allocating them to specific child tenants.

 

1. Supported Configuration Types:

You can centrally manage and push the following types of configurations from a parent tenant to child tenants:

  • Prevention Profiles: Security settings for Malware, Exploit, and Restrictions
  • Alert Exclusions: Centralized suppression of specific alerts
  • Exception Rules: This includes Disable Prevention Rules (DPR), Support Exceptions (SuEx), and Legacy Agent Exceptions
  • BIOC Rules: Behavioral indicators can be managed by the master tenant and synced to sub-tenants
  • Allow/Block Lists: Centralized IP or hash-based whitelisting and blacklisting
  • Starred Alerts/Incidents Policy: For consistent incident prioritization.

    Note: I recommend reaching out to your Account Team, Solution Consultant, or Sales Engineer. They will be able to assist based on your specific requirements.

If you feel this has answered your query, please let us know by clicking Like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

View solution in original post

1 REPLY 1

L5 Sessionator

Hello @MaaHaa ,

 

Greetings for the day.

 

Yes, Cortex XDR provides native capabilities for MSSPs to create configurations once in a parent (main) tenant and apply them across multiple child tenants. This centralized management mechanism allows you to push security policies, exclusions, and rules without manual replication for each individual tenant.

Centralized Management Mechanism:

The core functionality is based on creating configurations in the parent tenant and then allocating them to specific child tenants.

 

1. Supported Configuration Types:

You can centrally manage and push the following types of configurations from a parent tenant to child tenants:

  • Prevention Profiles: Security settings for Malware, Exploit, and Restrictions
  • Alert Exclusions: Centralized suppression of specific alerts
  • Exception Rules: This includes Disable Prevention Rules (DPR), Support Exceptions (SuEx), and Legacy Agent Exceptions
  • BIOC Rules: Behavioral indicators can be managed by the master tenant and synced to sub-tenants
  • Allow/Block Lists: Centralized IP or hash-based whitelisting and blacklisting
  • Starred Alerts/Incidents Policy: For consistent incident prioritization.

    Note: I recommend reaching out to your Account Team, Solution Consultant, or Sales Engineer. They will be able to assist based on your specific requirements.

If you feel this has answered your query, please let us know by clicking Like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

  • 1 accepted solution
  • 1240 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!