Grant the Tenant Service access to xConnect

Version: 6.0

You must give your Tenant Service permission to access data on your Sitecore xConnect instance.

To grant the Tenant Service access:

  1. On your Sitecore server, open Manage computer certificates.

  2. Navigate to Certificates-Local Computer\Personal\Certificates. In the certificate list, right-click on your Sitecore xConnect Client (for example, sc10_xconnect_client), click All Tasks, then click Manage Private Keys.

    Windows Certificates dialog
  3. On the Security tab, in the Group or user names list, verify that your Tenant Service IIS App Pool is on the list.

    Note

    You can find your Tenant Service IIS App Pool name in the IIS Manager, under <Your local computer name>\Application Pools.

    If it is there, you can skip steps 4 to 8 and proceed directly to step 9. If it is not there, follow steps 4 to 8 to add it.

  4. To add your Tenant Service IIS App Pool to the list, click Add.

    Windows permissions dialog
  5. Click Locations…, select the name of your local computer, and click OK.

    Windows add permissions dialog
  6. In the Enter the object names to select (examples) field, type IIS AppPool\. Click Check Names and then click OK.

    Check Names in Windows add permissions dialog
  7. In the Permissions dialog box, in the Group or user names field, select your Tenant Service. In the Permissions field, in the Allow column, select the Read check box, then click Apply and OK to close the dialog.

    Give Tenant Service access in Windows permissions dialog
  8. In the certificate list, right-click your Sitecore xConnect Client, and click Open.

  9. On the Details tab, scroll down to the Thumbprint field. Copy the value. You must have this value to configure the connection strings on your Tenant Service server.

    Details tab in Windows certificate dialog
If you have suggestions for improving this article, let us know!