Managing Your Primary Account
Environment
This section serves as an actionable guide for account Superusers. The new self-service capabilities in the CSP empower you to configure and manage your account structure, allowing you to tailor the portal to your organization's specific operational model.
Strategic Consideration
Consider designating an account as Primary if it is managed by a central IT or procurement team responsible for onboarding all new entitlements. This ensures new assets are immediately visible to the team that needs to activate and allocate them, aligning your CSP structure with your organization's operational workflow. And if you need segregation for visibility purposes within your company/organization, consider managing entitlement groups & users in other accounts within the organization (by using the new self-service functionality to Create/Clone CSP accounts & the self-service functionality to transfer entitlements).
Viewing Primary Account Information
As a user, you can identify your organization's Primary Account in two primary ways:
-
Account Selector: In the account/s you have access to, the designated Primary Account will be clearly marked with a (Primary) tag next to its name in the account selector dropdown menu at the top of the page.
-
Homepage Notifications: Upon logging in, a notification will appear in the "Action" section of the CSP homepage, informing if your account has been designated as the primary for your organization.
Changing the Primary Account Designation
Only a Superuser of the current Primary Account can change this designation, and they must also have Superuser permissions on the account they intend to select as the new primary. This ensures that control over where new assets land remains with the appropriate administrators.
To change the Primary Account, follow these steps:
-
Navigate to the Account Management section in the left-hand menu.
-
Click on Account Details.
-
Select the Account Actions tab.
-
Locate the "Change the Primary Account" section.
-
From the dropdown menu, select the CSP account you wish to designate as the new Primary. This list will only contain accounts where you also have Superuser permissions.
-
Click the Confirm Change button. A dialog box will appear explaining that all future net new purchases and trials will now land in the selected account. You must acknowledge this to complete the change.
-
Verifying the Change
-
Verifying the successful change of your primary account ensures that future entitlements will be routed as intended. The verification process is simple and can be done directly within the CSP.
-
To confirm the new primary account designation, navigate to the account you just selected as the new primary. Within that account, view the Account Actions tab. You should now see the ability to switch the primary designation from this account to another one. This confirms that it is now the active primary account for your purchasing entity.
-
-
This self-service functionality provides Superusers with enhanced control and operational agility, empowering you to effectively manage your organization's SaaS entitlements and user onboarding processes.
-
Changing the Primary account designation triggers a notification to the other superusers of the current & new accounts. This is also logged in the ‘Account Log’ tab (under ‘Account Details’) for superuser visibility only.
Communication for Non-Primary Account Superusers
If you are a Superuser of a non-primary account and need to contact the administrators of the Primary Account—for example, to request membership for one of your users—a communication channel is available. Navigate to the Account Actions tab within your own account's details. You will find a section providing information about the organization's Primary Account, along with an option to initiate communication with its Superusers.
These management tools are supported by a clear notification system designed for every user role in your organization.
Setting a Cross-Organization Primary Account
In complex company structures with multiple organizations (orgs), you may wish to centralize entitlement management by designating a single CSP account as the Primary Account for multiple different orgs.
This advanced configuration allows entitlements from one org's purchases to automatically land in a central CSP account belonging to a different org within the same company.
Prerequisites for Cross-Org Designation
To designate a CSP account from "Org B" as the Primary Account for "Org A," you must meet two specific access conditions:
-
Access to the Target Account: You must be a Superuser of the account you wish to designate as the new Primary (the account in "Org B").
-
Access to the Current Primary Account: You must be a Superuser of the current Primary Account of the org you are modifying (the account in "Org A").
Note: If you do not have Superuser access to the target account, you cannot perform this action self-service.
First, attempt to resolve this internally by contacting the existing Superusers of the target account:
-
Navigate to the Account Actions tab within your account details.
-
Locate the Primary Account Info section. * Use the provided text box to send a message directly to the Superusers of that account to request the necessary access .
You should only contact Palo Alto Networks Support to request access if there are no active Superusers for that account or if you are unable to resolve the permissions issue internally.
Step-by-Step: Changing to a Cross-Org Primary Account
-
Log In: Log in to the Customer Support Portal (CSP).
-
Navigate to Account Management: Select Account Management > Account Details.
-
Open Account Actions: Click on the Account Actions tab.
-
Locate "Change Primary Account": Scroll to the "Change Primary Account" section.
-
Select the New Account: Click the dropdown menu. You will see a list of all CSP accounts where you have Superuser privileges, including those belonging to different organizations within your company .
-
Confirm the Selection: Select the desired account from the different org.
-
Review the Confirmation Prompt: A confirmation dialog will appear. It will verify that you have selected a CSP account belonging to a different organization.
-
The prompt confirms that all future purchases and trials for the current org will now be deposited into this external org's CSP account .
-
-
Finalize the Change: Click Confirm to complete the designation.
Once confirmed, the selected account (from the different org) will serve as the landing spot for all new SaaS orders and trials for the org you just modified .
Frequently Asked Questions (FAQ)
This section provides answers to some frequently asked questions about the Primary Account functionality.
What happens if my organization only has one CSP account? Your single account is automatically designated as the Primary Account. No action is required on your part, and all new SaaS purchases and trials will be deposited there.
Will changing the Primary Account designation move my existing SaaS entitlements? No, it will not. The Primary Account designation only affects where future net new and trial entitlements are deposited. All of your existing assets/entitlements will remain in their current CSP accounts.
How do I find a list of all the CSP accounts I have access to? Any user can see a complete list of accounts where they have direct membership by clicking on the account selector dropdown at the top of the portal. Additionally, Superusers can navigate to the Account Actions tab to view a list of all accounts they have access to across the organizations they help manage (if applicable).