Introduction
This document describes the expected behavior when adding new users to SAML enabled Multiorg Console or MOC and Child Orgs in Cisco Umbrella.
Prerequisites
Requirements
There are no specific requirements for this document.
Components Used
The information in this document is based on Cisco Umbrella.
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
Overview
In multi-org, it is advisable to add users to the "Single Sign-On" MSP org first, and then invited to the relevant other child orgs later.
If you do this the other way round, which is first create user in child org and then create the user in a MSP org, then the user requires a static password before they can join the "Single Sign-On" org. This is undesirable for most customers.
Steps to Perform
1. Add user into Multi org and follow.
2. Add user into secure x and follow email instruction.
3. Log into to Multi org first and then child org and see whether it works or not.