Multitenancy

Kaspersky XDR Expert supports a multitenancy mode. This mode enables the main administrator to provide the Kaspersky XDR Expert functionality to multiple clients independently, or to separate assets, application settings, and objects for different offices. Each client or office is isolated from others and is called a tenant.

Typically, the multitenancy mode is used in the following cases:

The multitenancy mode has the following features:

Tenant isolation

A tenant is isolated and managed independently from other tenants. Only users who have assigned access rights to the tenant can work within this tenant and manage it. The tenant's data, resources, and assets cannot be accessed by an administrator of another tenant unless the main administrator grants the corresponding access rights to the administrator explicitly.

For each tenant, you define a number of objects, including the following ones:

Cross-tenant scenarios

All tenants are arranged into a tenant hierarchy. By default, the tenant hierarchy contains a pre-created Root tenant at the top of the hierarchy. No other tenants can be created at the same level as the Root tenant. You create a new tenant as a child to any existing tenant, including the Root tenant. The tenant hierarchy can have any number of nesting levels.

The tenant hierarchy is used to provide cross-tenant scenarios, including the following ones:

User roles

Kaspersky XDR Expert provides you a predefined set of user roles. You grant user rights to manage tenants by assigning user roles to the users.

User role

User right

Read

Write

Delete

Main administrator

Included.

Included.

Included.

Tenant administrator

Included.

Included.

Included.

SOC administrator

Included.

Included.

Excluded.

Tier 1 analyst

Included.

Excluded.

Excluded.

Tier 2 analyst

Included.

Excluded.

Excluded.

Junior analyst

Included.

Excluded.

Excluded.

SOC manager

Included.

Excluded.

Excluded.

Approver

Included.

Excluded.

Excluded.

Observer

Included.

Excluded.

Excluded.

Interaction with NCIRCC

Included.

Excluded.

Excluded.

Tenants and Kaspersky Single Management Platform Administration Servers

You can bind tenants to Kaspersky Single Management Platform Administration Servers, physical or virtual. A link between a tenant and an Administration Server allows you to combine features of both solutions—Kaspersky XDR Expert and Kaspersky Single Management Platform.

In this section

About binding tenants to Administration Servers

Configuring integration with Kaspersky Single Management Platform

Viewing and editing tenants

Adding new tenants

Deleting tenants

Configuring a connection to SMTP

Configuring notifications templates

Page top