When you import a source tenant into a target tenant, you are importing apps, Adaptive Rulesets, FIDO policies, authenticator groups, and data lists from the source tenant. You can optionally specify if the target tenant's existing API Server configuration and metadata used by its authenticator groups should also be overridden by the source tenant's configurations and metadata.
Apps, Authentication Server configuration properties, Adaptive Rulesets, FIDO policies, lists, and authenticator groups from the ZIP file overwrite their counterparts in the target tenant that share the same name. Apps, Authentication Server configuration properties, Rulesets, FIDO policies, lists, and authenticator groups that are unique to the target tenant remain. All imported Rulesets and policies are automatically activated.
You can use either the Admin Console or nnl-mgmt.sh to import an existing tenant's configuration into a new tenant.
An Admin user must have write access to the Configuration, Metadata Management, and Rulesets resources in the target tenant to successfully import. To verify or modify an Admin user's permissions, see Assign Permissions to Admin Console Resources.
Using the Admin Console
Login and switch to the target tenant.
Navigate to Administration > Tenants and click the Import button.
The Import Tenant Configurations dialog appears.
Click Choose File and browse to the ZIP file containing the configuration information.
If you intend to reuse all API Server Configurations from the source tenant configuration with no modifications, then select the Import and Overwrite API Server Configurations checkbox.
IMPORTANT: In most cases the target tenant must use a jwt_config and keys that are different from the source tenant. For this reason we recommend that you do NOT select Import and Overwrite API Server Configurations. If you do import the API Server configuration, then all JWT and JWS configurations must be generated after the import. See Customize an imported tenant.If you intend to use the authenticator metadata referenced by the source tenant's authenticator groups, then select the Import and overwrite metadata checkbox. Do not select the Import and overwrite metadata checkbox if the import file doesn't contain authenticator metadata, or your import will fail.
Click Import. A Summary of imported configurations is displayed. If you chose to import and overwrite API Server Configurations, then save a screenshot of this so you can refer to it in Customize an imported tenant.
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A54%3A51Z&se=2026-09-30T04%3A06%3A51Z&sr=c&sp=r&sig=fTKzjmJBUIzZNCsIpa8DPGYOsLEVnmXlSj4QCbzfLD4%3D)
Follow the instructions in the next section to customize your new target tenant.
Using nnl-mgmt.sh
The following command imports the default tenant's configuration from a file named default_config.zip into the target tenant with the tenant id: newtenant. This command does not import the API Server configuration objects nor the metadata used by the source tenant's authenticator groups.
./nnl-mgmt.sh tenant import -tenantid newtenant -file default_config.zip ‑include‑metadata no ‑include‑apiserver‑config noFor details on the nnl-mgmt.sh tenant import command, see subsection Import under Tenant Commands.