Onboard a Client Tenant
use this guide each time you add a new client tenant to an existing ai soc for mssp deployment the central tenant is already live; you copy central values, install client packages, configure sync in the new client, and validate propagation for first time mssp deployment (install all three solution layers and configure both tenants), use getting started for mssp docid\ ivvy6gxajwc34xvmnnqc instead of this guide before you start central tenant deployment is already active and operational you have admin access to the new client tenant and the central tenant you have approved naming conventions for client name values so central case and reporting views do not fragment you have a swimlane pat for the client ai soc tenant configuration asset ( private token ), and an admin privatetoken for ai soc mssp central sync these are different tokens after you install ai soc mssp client extension , disable enrich tia record (create) flow in the client ai soc main playbook do not disable the playbook itself see disable enrich tia record in ai soc main in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw gather values from the central tenant you do not reconfigure the central tenant during client onboarding copy values from the existing central deployment copy the ingest record from client webhook url, username, and password from the central tenant (documented under configure the central tenant in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw ) this webhook is required for case management and reporting sync confirm the sensor is enabled copy the central threat intelligence artifact cache application identifier for the new client ai soc mssp client configuration central tiac app id field (procedure find the central ti cache application id in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw ) prepare the new client tenant create or verify the new client tenant confirm tenant users, roles, and access controls are configured confirm base ai soc dependencies are available for this tenant install client side solution layers install ai soc core solution (26 2 0 or later) in the new client tenant install ai soc mssp client extension in the same client tenant when the installer prompts to overwrite the get application fields schema component, accept that overwrite do not skip or deselect this component see accept get application fields schema overwrite in getting started for mssp docid\ ivvy6gxajwc34xvmnnqc verify installation succeeded and mssp assets are present ( ai soc mssp client configuration , ai soc mssp central sync , ai soc mssp reporting ) include tia central sync fields on the client threat intelligence application ( support β threat intelligence metadata ) see include tia central sync fields in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw disable the enrich tia record (create) flow in the core playbook ai soc main see disable enrich tia record in ai soc main in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw configure the new client tenant in the new client tenant only, complete the client sections in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw configure the client tenant ( ai soc tenant configuration pat, include tia central sync fields , disable enrich tia record (create) flow in ai soc main , and confirm mssp reporting) configure mssp client sync assets using the central values you gathered confirm client name in ai soc mssp client configuration matches how you filter records in central central case management and central soc reporting validate client onboarding create or ingest a test record in the new client tenant confirm the record appears in central central case management with the correct client name confirm related tiac records appear or update in central threat intelligence artifact cache verify updates continue after additional status or field changes in the client tenant after the reporting job runs, confirm a reporting aggregate for this client name appears in central soc reporting if validation fails, see validate and troubleshoot mssp sync docid\ qyesknwk rnsc1w1uax d common onboarding issues issue likely cause action hero ai or core playbooks fail in client incomplete ai soc tenant configuration (including private token ) complete configure the client tenant in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw new client records do not appear in central client endpoint or tenant identifier mismatch recheck configure mssp client sync assets in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw sync fails with authentication errors webhook credentials do not match align client sync asset and central ingest record from client webhook in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw ti cache does not update missing or incorrect central tiac app id or privatetoken , or tia central sync fields not included recheck find the central ti cache application id , privatetoken , and include tia central sync fields in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw client still enriches tia when central tiac already has the observable enrich tia record (create) flow is still enabled in ai soc main complete disable enrich tia record in ai soc main in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw central reporting is empty for the new client reporting playbooks not running, or client name mismatch confirm ai soc mssp reporting / soc reporting sync and client name central api calls fail from the client tenant invalid privatetoken or incorrect central tenant id recheck ai soc mssp central sync privatetoken and ai soc mssp client configuration