---
title: "Configure a Tenant Restriction ruleset"
canonical: "https://docs.aryaka.com/space/KNOW/529629450/Configure%20a%20Tenant%20Restriction%20ruleset"
format: markdown
---
This topic describes how to create or edit a Tenant Restriction ruleset. Tenant Restriction rules are used to manipulate the HTTP headers of SaaS application traffic to enforce tenant restrictions. You can add multiple Tenant Restriction rules to a ruleset and then apply the ruleset to one or more sites. If you want to create a Tenant Restriction rule that applies only to one site, see the  Configure site-level security features  help topic.  Tenant restriction SaaS applications generally allow a user to access multiple accounts, such as an enterprise account and a personal account. If your organization wants to prevent users from accessing certain accounts, you can create a Tenant Restriction rule to restrict users' access to the SaaS application.  Tenant Restriction rules allow you to intercept traffic and manipulate the HTTP headers by injecting tenant-specific information, such as a tenant domain name, workspace ID, or directory ID. You can manipulate a header by adding, modifying, or removing a value from the HTTP request. To successfully implement the Tenant Restriction rules described on this page, your organization's administrator for the SaaS application you want to create a rule for must complete the required tenant restriction configuration in the administration portal of the corresponding SaaS application. This configuration is required to map the tenant identifier used in your Aryaka Tenant Restriction rule to your enterprise account for the SaaS application. The option to configure tenant restriction and any associated configuration procedures are dependent on the SaaS application. These details are outside the scope of Aryaka SmartSecure CASB.  See the  CASB  topic for additional details about the Tenant Restriction security engine and the  NGFW-SWG  topic for details about the other security engines that are used to inspect network traffic. Create a ruleset The Tenant Restriction page displays a table of Tenant Restriction rulesets. Rulesets are associated with one or more of your sites and include one or more rules that permit or deny traffic based on configured match criteria. See the  Security engine rulesets  topic for an overview of the different types of security rulesets.  Complete the procedures later in this topic to create or edit a Tenant Restriction ruleset.  Default rule If you do not configure any Tenant Restriction rulesets or  site-level rules , the Tenant Restriction Default template is applied to traffic for all sites. The Default template includes a rule that matches all traffic and does not perform header manipulation. Manage the Rules table The Rules table within a ruleset displays a list of configured rules that are evaluated when traffic is inspected by the associated security engine for any sites that the ruleset is applied to. Each table row includes the following details: Rule ID—Identification number for the rule, used in security logs. Name—User-defined name for the rule. Source—Match criteria related to the source of the traffic (for example, source IP address or user).  Destination—Match criteria related to the destination of the traffic (for example, destination IP address or domain). Manipulate Header—Indicates whether header manipulation is performed on matched traffic. Schedule—Match criteria related to a defined schedule. Action—Action applied to matched traffic (for example, permit or drop).  Note the following when interacting with the Rules table: If a single match criteria has more than four entires, click  Show More  to view all entires.  If an asset is used as match criteria, click the asset name to display an in-page view of what the asset includes. The Rules table also includes the following components: Detailed View toggle—Turn this toggle on to display details on the type of match criteria (for example, IP or URL) and the required condition (for example, is or is not) included in a rule. When this toggle is turned off, only the specific match criteria are displayed.  Download Table icon—Download the rule table as a CSV file. Configure table icon—Select whether to display the columns related to match criteria (for example, source, destination, and schedule) in the table. Reorder button—Reorder the rules in the table. See step 14 of the  Add a Tenant Restriction ruleset  procedure for details.  Note that Rule tables are evaluated from top to bottom. If a more specific rule appears above a more generic rule, and the traffic matches the more specific rule, the rule's corresponding action is executed and the next (more generic) rule is not evaluated. When you configure your Tenant Restriction rules, you can use the following match criteria to permit or deny traffic: Source IPs Source zones Users SaaS applications SaaS application categories SaaS application suites User functions Domains URLs Schedules These match criteria can be specified individually when you create a rule or as part of a named asset, defined on the  Asset Management  page. Assets can be reused in your security rules, but must be configured  before  you create the rule in which you want to use it. To add a Tenant Restriction ruleset Open the Tenant Restriction page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  CASB  in the left navigation pane. The CASB page appears. Click  Manage  in the Tenant Restriction Rulesets tile. The Tenant Restriction page appears and displays a list of configured rulesets. Click the  Add  icon. The Add a Template page appears and displays the Ruleset Details pane and the Rules table.  In the Ruleset Details pane, enter a name and, optionally, a description for your new ruleset, then click the  Type  drop-down list and select one of the following options: High Priority Custom Template—Define a set of high priority rules for a specific site or group of sites. Only rules in the Global Non-Overridable Template take precedence over the rules in this ruleset. You can only configure one ruleset of this type for a given site.  Normal Priority Custom Template—Define a set of rules for a specific site or group of sites. Rules in this ruleset are evaluated after all rules in Global Non-Overridable and High Priority Custom templates. The rules in this ruleset can be overridden by  site-level rules  and rules in other Normal Priority Custom templates, based on your configured evaluation order. Note:  You cannot add a Global Non Overridable template, but you can edit the existing one. You cannot add a Default template or edit the existing one. See the  Security engine rulesets  topic for an overview of the different types of security rulesets. Click  Add  in the Rules table. The Add a Policy page appears and displays a Details pane, a Header Manipulation pane, and a Match Criteria pane. In the Details pane, enter a name for your rule and, optionally, a description. Then, select Yes or No (default) to indicate whether subsequent rules should be evaluated after the current rule.   In the Header Manipulation pane, click the toggle to include header manipulation in the rule. The Header Manipulation pane appears in edit mode. Click  Add . Fields appear in the Header Manipulation pane.  Click the  Operation Type  drop-down list and select the type of header manipulation you want the rule to perform on matched traffic: Add Request Header—The specified header is added to the HTTP request. Modify Request Header—The specified header is changed in the HTTP request. Delete Request Header—The specified header is removed from the HTTP request. Enter the header name and value in the Header Name and Header Value fields. Note:  If entering multiple header values, use comma separated values.   In the Match Criteria pane, complete the following procedure for each of the criterion you want to include in the rule:  Click the  Condition  drop-down list and select a condition for the criterion. Complete one of the following procedures to add match criteria: Type a criterion into the appropriate field and hit Enter. The criterion is added. Click the  Add  icon. The Add < criterion > dialog appears. Depending on the type of match criteria selected, do one of the following: Click one or more entities you want to include as match criteria for the rule. The selected entities are highlighted in green and display a check. Click  Add Selected . The page displays the selected entities for each criterion.  Enter one or more entities you want to include as match criteria for the rule. Click  Add Selected . The page displays the selected entities for each criterion.  Click  Continue . The Add a Template page appears with the rule you added included in the Rules table. (Optional) Repeat steps 4–11 to add additional rules to your ruleset. Do one of the following: Click  Save as Draft  to save a draft of the ruleset. Click  Submit  to save the ruleset. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the Tenant Restriction page displays your new ruleset in the list of Tenant Restriction rulesets. Note:  The rules included in the ruleset are not applied to network traffic until the ruleset is associated with at least one site. Complete this procedure to associate a ruleset with one or more sites.  (Optional) Complete the following procedure to reorder the Rules table: Note:  Rules are evaluated in a top-down manner based on the table. The first rule that matches the traffic is executed and the rest are ignored.  Click  Reorder  in the rule table. The displayed table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected rule down one row in the table. Move Up—Move the selected rule up one row in the table. Move to Bottom—Move the selected rule to the bottom of the table. This rule is now evaluated last.  Move to Top—Move the selected rule to the top of the table. This rule is now evaluated first.  Change Precedence—Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your rule list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Click  Submit . The Rules table is updated according to the modified rule order. To associate a Tenant Restriction ruleset with a site Open the Tenant Restriction page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  CASB  in the left navigation pane. The CASB page appears. Click  Manage  in the Tenant Restriction Rulesets tile. The Tenant Restriction page appears and displays a list of configured rulesets. Click the name of the ruleset you want to associate with a site. The  <rulesetName>  page appears and displays the following tiles: Ruleset Details—Displays the number of rules included in the ruleset and the current status of the ruleset. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the ruleset and the current status of the site associations.  Click the  Site Associations  tile. The  <rulesetName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete at least one of the following procedures to associate the ruleset with a site or a group of sites: To associate the ruleset with a site:  In the Associated Sites pane, click  Add . The Add Site dialog displays the sites that you can associate with this Tenant Restriction ruleset.  Click one or more sites you want to associate with this Tenant Restriction ruleset. The selected sites are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected sites in the Associated Sites table.  To associate the ruleset with a group of sites: In the Associated Site Classes pane, click  Add . The Add Site Class dialog displays the site classes that you can associate with this Tenant Restriction ruleset. Click one or more site classes you want to associate with this Tenant Restriction ruleset. The selected site classes are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected site classes in the Associated Site Classes table. Click  Submit . You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the rules included in the Tenant Restriction ruleset are now used to permit or deny traffic for the sites the ruleset is associated with. To edit a Tenant Restriction ruleset Open the Tenant Restriction page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  CASB  in the left navigation pane. The CASB page appears. Click  Manage  in the Tenant Restriction Rulesets tile. The Tenant Restriction page appears and displays a list of configured rulesets. Click the name of the Tenant Restriction ruleset you want to edit. The < rulesetName > page appears and displays the following tiles: Ruleset Details—Displays the number of rules included in the ruleset and the current status of the ruleset. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the ruleset and the current status of the site associations. (Optional) Click  Disable  to render the ruleset inactive. The ruleset can be enabled again later.  (Optional) Click the  Delete  icon to remove the ruleset. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the ruleset is removed from the list of Tenant Restriction rulesets. Note:  You cannot delete the global or default templates. (Optional) Click  Reorder  in the Rules table. The displayed table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected rule down one row in the table.  Move Up—Move the selected rule up one row in the table. Move to Bottom—Move the selected rule to the bottom of the table. This rule is now evaluated last.  Move to Top—Move the selected rule to the top of the table. This rule is now evaluated first.  Change Precedence—Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your rule list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Click  Edit  in the Ruleset Details pane. The < rulesetName > page appears in edit mode. Use the following options to modify rules as needed: Edit —Displays the match criteria in edit mode. Add, edit, or remove entities from any of the match criteria. Complete step 6 of the  Add a Tenant Restriction ruleset  procedure to add or edit the entities included in a criterion, then click  Continue . Add Below —Adds a new blank rule below the selected rule. Options  >  Clone —Adds a new rule with the same match criteria as the cloned rule. The new rule is added to the rule table directly after the rule it was cloned from. Options  >  Disable —Renders the rule inactive, but does not remove it from the rule table. The rule can be reenabled later.  Options  >  Delete —Removes the rule from the site's rule table.  Do one of the following: Click  Save as Draft  to save a draft of the ruleset changes. Click  Submit  to save the ruleset changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the Tenant Restriction ruleset are saved. Click the  Site Associations  tile. The  <rulesetName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete the  Associate a Tenant Restriction ruleset with a site  procedure to edit the sites with which the ruleset is associated.  Click  Submit  to save the ruleset changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the Tenant Restriction ruleset are saved.  In this topic Related topics CASB Security engine rulesets Configure site-level security features Asset management Monitor Tenant Restriction security engine