This step is optional. The Admin and default tenants are built-in tenants that come with default configurations.
You can change these configurations by creating different configuration files under the "default" and "Admin" directories in <MFAS_HOME>/install/tenants/. Below is an example showing the structure of the <MFAS_HOME>/install/tenants/ directory to update default's configuration during installation.
├── default.zip
├── default
│ ├── apiserver
│ │ └─ SessionPlugin
│ │ ├── jwt_config.json
│ │ └── Main.json
│ ├── policies
│ │ ├── A_2nd_factor_ACTIVE_1694737766409.json
│ │ └── ...
│ ├── rulesets
│ │ ├── A_default_ACTIVE_1700157172979.json
│ │ └── ...In this example, the installer first creates the tenant named default using default.zip. The presence of a "default" directory tells the installer to use the configuration files under this directory to customize default. Objects with a unique name are added while objects with an existing name overwrite their counterparts. In the example above, the installer overwrites the Session plugin's jwt_config.json and Main.json, adds or overwrites FIDO policies, and adds or overwrites Adaptive Rulesets.
This is useful if you want to copy configurations from an existing installation to a new installation. Download Admin and/or default's configuration as a ZIP file using the instructions in Exporting a Tenant's Configuration. Referring to the example above, let's say that you have a tenant named Europe in your existing installation. You want to apply Europe's configurations for the Session plugin, FIDO policies, and Adaptive Ruleset to the default tenant. You would download Europe's configuration as a ZIP file and then unzip the file. Edit the directory structure to only keep the apiserver > SessionPlugin, policies, and rulesets directories and their contents. Create a directory with default's name in <MFAS_HOME>/install/tenants/, then copy the structure under the directory you just created.
You can also have the installer create tenants other than Admin or default using this same mechanism. The ZIP file name must use the new tenant's name and any customizations must be under a directory with that tenant's name. Alternatively, in place of the ZIP file, you can have the tenant's complete configuration under the directory named after the tenant.
For more details, refer to the readme file at <MFAS_HOME>/install/tenants/Tenant-Creation-README.