When you export a tenant's configuration, you can get the following configurations and objects in a ZIP file:
Authentication Server Configuration Properties
Configuration for the API Server and its plugins
Active Adaptive Rulesets
Active FIDO policies
App Configurations
Lists used by the active Adaptive Rulesets
authenticator groups
country lists
device model lists
geofence lists
IP address lists
WiFi network lists
You can use either the Admin Console or nnl-mgmt.sh to export the configurations of the source tenant.
An Admin user must have read access to the Configuration, Metadata Management, and Rulesets resources in the tenant to successfully export. To verify or modify an Admin user's permissions, see Assign Permissions to Admin Console Resources.
Using the Admin Console
Log in to the Admin Console. Navigate to Administration > Tenants and under the Actions column of the source tenant you want to copy, click the Export icon.
A dialog appears.
Select the Include API Server Configurations checkbox.
You can optionally select the Include metadata checkbox to export authenticator metadata that is referenced by the authenticator groups in this tenant.
Use this option in limited situations, such as when you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 installation. Normally, you should use the instructions in Updating Authenticator Metadata to import metadata.Based on your browser’s download file save/download settings, the Admin Console downloads the ZIP file to your machine.
Using nnl-mgmt.sh
Use the tenant export command to export all of the tenant configuration files from the original tenant. The following command exports the default tenant's configuration, including its API Server configuration objects but not the metadata used by its authenticator groups, to a file named default_config.zip.
./nnl-mgmt.sh tenant export -tenantid default -file default_config.zip -include‑metadata no ‑include‑apiserver‑config yesFor details on the nnl-mgmt.sh tenant export command, see subsection Export under Tenant Commands.