Reference Guide
Kron PAM Administration

Multitenancy

As organizations expand, the need for robust security solutions that can scale across multiple departments, teams, or clients becomes increasingly critical. Multitenancy in Kron PAM addresses this demand by providing a powerful capability to manage and isolate privileged access for multiple entities within a single instance of the platform. This feature enables administrators to create distinct and secure environments, known as tenants, each with its own set of users, policies, access controls, and resources.

Multitenancy for Kron PAM
Multitenancy for Kron PAM


To enable multitenancy:

  1. Navigate to Administration > System Config. Man.
  2. Set multitenancy.enabled as true.
  3. Save configuration.
  4. Navigate to Portal Function > Function Group Definition.
  5. Enter the function group a name and select the single.connect.tenant.admin function
  6. Save configuration.
  7. Open the Function Realm Definition tab.
  8. Enter the realm a name, select a tenant admin user group and select the function group that you created in step 6 and Save.
  9. Restart the PAM GUI service
    • Connect to the Kron PAM CLI as the pamuser user.
    • Run the systemctl restart pam-gui command to restart the service

Kron PAM can accommodate up to 30 tenants. No more than this number is supported.