When Omnissa Support adds a tenant to your organization, or when you first access the Multi-Tenancy Admin Console, you can push device policy groups and other settings from the Multi-Tenancy Admin Console.
Adding a Tenant to your Organization
To create a new tenant in your organization or move an existing tenant into your organization, raise a Support Request with Omnissa and provide the following details:
- Tenant name
- Number of licenses that apply to the tenant
For an existing tenant, also provide:
- Your organization name
- The tenant GUID, listed on the tenant's System > Account page (the same tenant identification number (GUID) shown in the WS1 MTD Console Admin Guide).
Setting up SSO for a New Tenant
If you use an IdP for Single Sign-On, the integration must be configured for each tenant:
-
In your IdP, create a tenant-specific group named WS1 MTD Tenant Console Users and note its Group Object ID.
-
Add users who should have access to that tenant. For example, for a "MyCompany EU" tenant, create a WS1 MTD EU Console Users group and add your EU MTD admins.
-
Raise a Support Request with Omnissa to configure the integration for that tenant, providing the following values:
Field Value Entra ID tenant ID (required) Your Entra ID tenant ID Access to this tenant (required) The Group Object ID for the WS1 MTD Tenant Console Users group Full access (required) The Group Object ID for your WS1 MTD Full Access Admins group Restricted access The Group Object ID for your WS1 MTD Restricted Access Admins group Read only The Group Object ID for your WS1 MTD Read-Only Admins group
Important: Users must belong to both the Tenant Access group and exactly one Role Permissions group. If they do not belong to both, they cannot sign in.
- After Omnissa Support confirms the integration, grant the requested permissions from your IdP as directed.
About Default Protection Policies
When Omnissa provisions a new tenant, it does not automatically inherit the organization's Default Policy Group settings. You must select the tenant in the Multi-Tenancy Admin Console, assign a default group, and click Apply Defaults in the Protections module to copy settings from the Multi-Tenancy Admin Console.
Important: If you do not assign a default group to a tenant, devices in the tenant’s Default Device Policy Group continue to use the tenant’s protection policy settings rather than the organization’s settings.
Setting Default Device Policy Group of a Tenant
By default, newly added tenants do not inherit any settings from the Multi-Tenancy Admin Console. To push changes to a tenant, assign default device policy group to the tenant.
Important: The first time you assign a default device policy group from the Multi-Tenancy Admin Console, it deletes the tenant's original local "Default Group," and any devices in that group move to the newly assigned group.
To assign a default device policy group:
- Click Tenants in the left navigation bar, then click the tenant to configure.
- Click the Device Policy Groups tab.
- Click Add device policy groups.
- Check the group to use as the new default and enable the Default Group radio button.
- Click Add. This changes the Default Group designation to the newly added group.
- Click Manage Tenant in the upper right, then Protections in the left navigation bar.
- Click Reset Defaults in the upper right to apply the new default policy group's settings.
Disable Device Group Creation for a Tenant
By default, tenant-level MTD Console administrators can still create device policy groups even when the tenant is part of a Multi-Tenancy deployment. You can prevent this from the Multi-Tenancy Admin Console:
- Click Tenants, then click the tenant you want to modify.
- On the Tenant Details screen, click the Device Policy Groups tab.
- Toggle Allow admins of this tenant to create groups to OFF.
Removing a Tenant from your Organization
You can remove a tenant from the Multi-Tenancy Admin Console, but you cannot add the tenant back yourself. Contact your Omnissa Support if you later want to re-add your tenant. For more information, see Adding a Tenant to your Organization.
Disconnecting a tenant has the following effects:
- Multi-Tenancy Administrators can no longer access the tenant unless they are members of the IdP group associated with that tenant or are configured as local administrators on the tenant.
- The tenant retains its existing policy configuration but no longer receives policy updates from the Multi-Tenancy Admin Console.
- Restrictions on device groups and policy configuration are removed, allowing tenant administrators to modify the configuration as needed.
- Dashboard items in the Multi-Tenancy Admin Console that rely on statistics from the tenant may take up to 24 hours to reflect the change.
To remove a tenant:
- Click Tenants, then click the tenant you want to remove.
- In the upper right, click Disconnect Tenant and read the warning.
- Select the checkbox I understand and want to disconnect this tenant.
- Click Yes, disconnect tenant.
Was this page helpful?