Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Configure tenants

Prev Next

Introduction

The Auth Server supports multi-tenancy and allows tenant-specific configuration. Tenancy allows you to logically separate users while still using the same server. For example, a company with two subsidiaries may want to keep the two user groups entirely separate. This can be done by creating two different tenants. Each tenant is identified by a tenant id, so the tenant id must be unique to the deployment.

Creating multiple tenants allows you to have control over how each tenant is configured without worrying about potential impacts on the other tenants.

On the other hand, multiple tenants means each tenant requires its own registration and authentication endpoints as well as apps, FIDO Policies that specify acceptable authenticators, Adaptive Rulesets, and so on. If the tenant's trusted apps support out-of-band (OOB) authentication, you also need to create separate OOB registration and authentication endpoints. You have increased complexity since you need to track and manage configuration settings for each tenant.

This page helps you quickly create and configure a new tenant. As a result, it focuses on functionality that enables you to create a new tenant and copy an existing tenant's entire configuration into your new tenant. Once you have done that, you can further customize your new tenant. Perform the following steps:

  1. Create a new tenant. We refer to this tenant as the target tenant.
    A tenant must exist before you can import a configuration into it.

  2. Export an existing tenant's configuration. We refer to this tenant as the source tenant.
    There are 2 primary use cases for exporting a tenant's configuration:

    • You intend to use the entire tenant configuration with no modifications in order to:

      • Move a tenant from a development deployment to a production deployment.

      • Replicate the tenant on another production server.

      • Make a backup copy of a tenant before modifying it.

    • You want a target tenant based on a source tenant, but with some modifications.

  3. Import the source tenant's configuration into the target tenant.

  4. Customize the target tenant.

Alternatively, you can choose to create a new tenant and then manually configure that tenant. This includes configuring the authentication methods, creating FIDO policies, creating rulesets, configuring apps and configuring the API server for the new tenant.