Grant the Tenant Service access to xConnect

Version: 6.0

You must give your Tenant Service permission to access data on your Sitecore xConnect instance.

To grant the Tenant Service access:

  1. On your Sitecore server, open Manage computer certificates.

  2. Navigate to Certificates-Local Computer\Personal\Certificates. In the certificate list, right-click on your Sitecore xConnect Client (for example, sc10_xconnect_client), click All Tasks, then click Manage Private Keys.

    Personal certificates in the Windows Manage computer certificates dialog.
  3. On the Security tab, in the Group or user names list, verify that your Tenant Service IIS App Pool is on the list.

    Note

    You can find your Tenant Service IIS App Pool name in the IIS Manager, under <Your local computer name>\Application Pools.

    If it is there, you can skip steps 4 to 8 and proceed directly to step 9. If it is not there, follow steps 4 to 8 to add it.

  4. Click Add.

    Windows permissions dialog with the Add button highlighted.
  5. Click Locations, select the name of your local computer, and click OK.

    Select Users, Computers, Service Accounts, or Groups dialog in the Windows Permissions app.
  6. In the Enter the object names to select (examples) field, type IIS AppPool\<your Tenant Service IIS App Pool name>. Click Check Names and then click OK.

    Select Users or Groups dialog in the Windows Permissions app, with object name and Check Names button highlighted.
  7. In the Permissions dialog box, in the Group or user names field, select your Tenant Service. In the Permissions field, in the Allow column, select the Read check box, then click Apply and OK to close the dialog.

    WIndows permissions dialog with the username sc10.service selected, and the allow read permission checkbox checked.
  8. In the certificate list, right-click your Sitecore xConnect Client, and click Open.

  9. On the Details tab, scroll down to the Thumbprint field. Copy the value. You must have this value to configure the connection strings on your Tenant Service server.

    Certificate dialog showing the Thumbprint field.
If you have suggestions for improving this article, let us know!