Skip to main content

August 20, 2026

Workspace ONE Mobile Threat Defense Multi-Tenancy Overview

Multi-Tenancy enables administrators to manage multiple Workspace ONE Mobile Threat Defense (WS1 MTD) tenants, such as separate customers, groups, or geographies, from a centralized environment. Organization-level administrators can define security policies once and apply them consistently across multiple tenants.

This guide is intended for administrators who oversee WS1 MTD deployments across multiple tenants. It provides an overview of the Multi-Tenancy Admin Console and describes the tasks involved in configuring and managing multiple tenants.

For information about administering an individual WS1 MTD tenant, see the Workspace ONE Mobile Threat Defense Console Admin Guide.

Multi-Tenancy Administration

The WS1 MTD Multi-Tenancy Admin Console provides a centralized interface for reviewing and managing multiple Workspace ONE Mobile Threat Defense (WS1 MTD) tenants. Tenants are grouped under a single organization and can inherit security settings configured at the organization level.

Administrators who access the Multi-Tenancy Admin Console using local WS1 MTD credentials or Single Sign-On (SSO) are referred to as Super Admins in this guide. A Super Admin can access any tenant within the organization, and their assigned permission level applies consistently across all tenants.

Example: Omar is configured as a Super Admin in the Multi-Tenancy Admin Console with Read-Only access. He can sign in to the console and view any tenant in the organization with read-only privileges.

Note: If you administer only a single WS1 MTD tenant, you can refer the Workspace ONE Mobile Threat Defense Console Admin Guide instead of this guide.

Getting Started with Multi-Tenancy

Omnissa performs the initial configuration of your multi-tenancy environment, including creating the organization, adding the first Super Admin, and adding your WS1 MTD tenants to the organization.

After the initial setup, complete the following tasks to configure and manage your multi-tenancy environment:

  1. If you use an Identity Provider (IdP) for Single Sign-On (SSO), create a user group to control access to the Multi-Tenancy Admin Console and one or more groups to define administrator permission levels.

  2. Submit a Support Request (SR) to Omnissa to configure SSO for the Multi-Tenancy Admin Console. See Setting up SSO for Multi-Tenancy Administrators.

  3. Create policy groups to apply different protection policies to different tenants.

  4. Configure protection policies at the organization level.

  5. Configure Phishing and Content Protection (PCP) at the organization level.

  6. For each tenant in your environment:

    a. Create a user group in your IdP to control access to the tenant, and add tenant administrators to the group as needed.

    b. Assign a default device policy group from the Multi-Tenancy Admin Console.

    c. Assign any additional device policy groups from the Multi-Tenancy Admin Console.

    d. From the tenant's MTD Console, move devices into the appropriate device policy groups.

Logging in to the Multi-Tenancy Admin Console

Check your email for a welcome message with a sign-in link.

Local administrators sign in to the Multi-Tenancy Admin Console at the URL provided in your welcome email. If your organization uses SAML/SSO, sign in through your Identity Provider instead.

Note: To configure SSO, see Setting up SSO for Multi-Tenancy Administrators. Local administrator accounts require multifactor authentication (MFA) using a TOTP authenticator app, consistent with the MFA requirements documented for single-tenant WS1 MTD Console sign-in.

Opening the MTD Console for a Specific Tenant

To access a specific tenant from the Multi-Tenancy Admin Console:

  1. Click Tenants in the left navigation bar and click the row for the tenant you want to view.
  2. Click Manage Tenant in the upper right.

WS1 MTD navigates to the MTD Console Dashboard for the selected tenant. Return to the Multi-Tenancy Admin Console at any time by clicking Back to the Parent Admin Console in the banner notification.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…