Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-4847: Can a Centrify cloud tenant be removed, disabled or deleted?

App Access Service ,  

30 December,16 at 09:38 PM

Applies to: Centrify Identity Service, Centrify Privilege Service



Our organization registered for the Centrify Cloud Service and has decided to retire the tenant instance. Is there a method for the tenant to be removed or disabled?




Centrify Cloud Tenants do not need to be removed in the current version as there is no actual Active Directory data replicated to the service. When a user becomes “known” to the service (either by being invited to the service, by being provisioned to a downstream app, or through an authentication processed by our service) certain contact attributes are cached for the user record.

All data is encrypted and is only shared with the User himself/herself, and administrators who you have given the rights to see this data.


The following data appears in the drill-down of a user if known by AD:

  • First Name
  • Last Name
  • Email Address
  • Office Number
  • Mobile Number
  • Home Number
  • Website
  • Address
  • Manager / Direct Reports
  • Group membership

In addition, to the above attributes, all publicly readable properties of the user in AD (i.e. account state, password expiration date, etc.) are cached by the service to optimize performance.

Note: Disabling a cloud tenant will prevent all portal and application access and could cause production impact. 

Customers may choose to perform the following steps if the tenant is no longer used and prior to any tenant disable:

  1. Login to the tenant Cloud Manager at
  2. Select the Users tab and delete all user accounts (Active Directory accounts will be removed from cloud portal view only - not AD)
  3. Select the Apps tab and delete/remove all deployed applications - be sure to first remove user access and federation settings prior to deleting any app.
  4. Select the Devices tab and unenroll / delete all mobile devices, then delete all devices from the list.
  5. Select the Roles tab and delete all created roles.
  6. Select the Policies tab and delete all created policies.
  7. Select the Settings tab and delete or rename all login suffix entries (append with "-old" for example), corporate IP range and provisioning settings.
  8. Uninstall the AD cloud connector and extensions (if installed).
  9. Online help is also available for completing the above tasks.
Note: Centrify does not currently provide a user-selectable option to delete or reset the tenant to defaults at this time.


Also, when swapping tenants, it is recommended to first rename any login suffix entries in the original tenant so they can be reused in the new tenant.

Once the suffix entries are available for use, simply re-register the cloud connector using any system administrative account available in the new tenant. Once the connector has completed registration, new login suffix entries will automatically be entered in the new tenant.

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.