cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
403
Views
0
Helpful
4
Replies

Migrate clients to a new tenant

jleonard
Level 1
Level 1

We have a customer using MSSP for Endpoint Security. They want to manage their endpoints themselves. How can I migrate the endpoint to their own, self-managed, tenant?

4 Replies 4

Someone from Cisco may pop up with a definitive answer, but I'm betting it will have to be an uninstall/reinstall.

Roman Valenta
Cisco Employee
Cisco Employee

Hi,

I guess the real question here is what do you mean by "They want to manage their endpoints themselves..."

A: If they just want to be able to log in to the AMP portal and manage deployments, policies, look events, etc.. you can just create Admin Accounts for those individuals for that specific child ORG. Those users will still need to create SXSO accounts https://sign-on.security.cisco.com/ with their real email address that will be used to create account in AMP console. To prevent any integrity issue please make sure those emails ale created using all lower case letters, both in AMP and SXSO.  You as MSSP will be still responsible for licensing and billing for the tenant.

B: If they wanted to be on their own and buy their own license in which case I believe new ORG will have to be provisioned, and if that's the case then NEW ORG = NEW GUID = New Deployment. In other words all connector in that customer ORG will have to be removed and re-deployed with new connector that will be downloaded and associated with the new ORG UUID.

 

Unfortunately I do not know all the licensing details and if there is a way to de-couple a tenant from MSSP with out need to create new ORG, that will be good question for provisioning team to confirm this scenario. So I would recommend to contact them as they will give you the ultimate answers if scenario B: is desired.

 

Hope that helps.

 

-Roman

 

 

Scenario B is active here. I'll see about contacting the provisioning team. I was hoping for a way to change the GUID of an installed connector. Either from the AMP portal or a  command on the endpoint.

Troja007
Cisco Employee
Cisco Employee

Hello @jleonard ,
please get in contact with your Cisco representative. There have been ways to move a customer out from a MSSP console without the need to reinstall the connector, as the ORG GUID does not change.
There have been a lot of changes and improvements to our product, therefore not 100% sure if this is still possible. So therefore, please check with your Cisco representative.

Greetings,
Thorsten