---
title: "Set up and Access the Tenant Manager"
slug: "set-up-and-access-tenant-manager"
updated: 2025-11-03T18:47:58Z
published: 2025-11-03T18:47:58Z
canonical: "support.controlup.com/set-up-and-access-tenant-manager"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.controlup.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up and Access the Tenant Manager

> [!NOTE]
> Note
> 
> This feature has limited availability and applies only to MSPs or multi-organization accounts. If you are interested in accessing this feature, contact us at [support@controlup.com](https://support.controlup.com/docs/ticket-deflector/ask-us-anything).

## Setup for New customers

Before creating a Tenant Manager, new customers must have a [ControlUp account](/v1/docs/create-your-controlup-organization).

1. Contact [Support](https://support.controlup.com/docs/ticket-deflector/ask-us-anything) to request a Multi-Tenant status.
2. ControlUp Support creates the Tenant Manager and assigns the requester as the designated Admin.
3. Once approved, the Admin receives an email invitation to join the Tenant Manager.
4. The Admin logs in and completes the setup.

## Setup for Existing customers

If you already have a commercial ControlUp license, you can activate the Tenant Manager by contacting **Sales** or **Support**. The designated Admin receives:

- An **activation link** (valid for 72 hours)
- An **activation key**

After activation, the Admin can log into the Tenant Manager and link existing organizations to the account. Access to the Tenant Manager is limited to authorized organizations and users with the appropriate permissions, which are enforced at both the Tenant Manager level and at each organization level.

Note

Product-level settings, such as Employee Experience and roles, must still be configured separately for each organization.

## Create a Tenant Manager Organization

An account can have only one Tenant Manager.

To create the Tenant Manager:

1. Log into ControlUp.
2. Open your profile menu and click **Create Tenant Manager.**

![](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/image-YIEU26IU.png)

1. Enter the Tenant Manager name and region, then click **Create Tenant Manager.**

![](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/Create a TM screen.png)

1. The main Tenant Manager dashboard opens. You can now can add tenants by clicking **Add Tenant.**

**Note**: Once the Tenant Manager organization is created, all subsequent organizations must be created from within it.

### User notifications and guidance

After creation, a pop-up appears, providing:

- Instructions for distributing existing licenses between current and new organizations.
- An option to start creating a new organization.

## Log into Tenant Manager

1. Sign into your [ControlUp account](https://www.controlup.com/) with your registered email.
2. Enter the verification code sent to your inbox.
3. Select your Tenant Manager organization from the organization list.

![Log into Tenant Manager - select organization](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/log%20in%20-select%20organization%281%29.png)

1. Choose your preferred login method: **Entra ID**, **Google**, **SAML** or email and password.

![Tenant Manager login](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/Tenant%20Manager%20login%281%29.png)

After login, you’re taken to the Tenant Manager platform. The Tenant Manager organization is selected by default based on your credentials and permissions.

### Access Organizations in Tenant Manager

To open an organization, select it from the organization picker in the top bar.

- **Tenant Manager Admins** can access all connected organizations, even if they are not members of those organizations.
- **Tenants** can access other organizations in the Tenant Manager only after signing in through the Tenant Manager first.

**Note**: If a tenant later logs directly into a target organization (without going through the Tenant Manager), their roles are overridden by the roles configured in the Tenant Manager organization.

### VDI Web Login

Tenant Manager Admins can enable VDI users to log into the **Real-Time DX Console** through the Tenant Manager account. VDI users only see organizations they have permission to access.

To enable VDI login:

1. Open the **Real-Time DX Console**.
2. In the Console’s **Web Login** screen, select the organization to log in to (under your Tenant Manager).
3. Log into the Console as Tenant Manager. Authentication is performed using the same methods as other products. ![Login screen](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/login(2).PNG)

> [!NOTE]
> Note: VDI users don’t see their Tenant Manager organization in the org picker. They access organizations based on their assigned groups.

**In DEX**

Tenant Manager opens the organization that you selected in the login screen. You can switch between tenant organizations and the Tenant Manager in the organization picker.

To synchronize roles:

1. Go to **Settings > Roles** in Tenant Manager.
2. Make sure that the roles required in the Console are also configured in the Tenant Manager. **Note:** You can create a role for one organization, or apply it to all your Tenant Manager tenants.

In the **Real-Time DX Console**

Configure the Security Policy:

1. Open the **Security Policy** tab. ![Security Policy tab](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/Security Policy tab.PNG)
2. Under **Identity Provider**, add the DEX roles that you have already associated in the app with the relevant users or user groups (such as Entra ID Groups) into the appropriate Admin role within the Security Policy. This synchronizes roles between Tenant Manager and the Console. See [User group roles for VDI users](/v1/docs/tenant-manager-settings#user-group-role-for-vdi-users). ![Select Identity Provider](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/Select provider(1).png)

Once you have completed these steps, VDI users can log into the Real-Time DX Console using their Tenant Manager credentials.
