Security intelligence lists and multitenancy

A security intelligence list is a multitenancy feature that

  • enables the creation of block or do not block lists that apply to specific subdomains,

  • supports descendant domain lists that aggregate the lists of a domain’s descendants, and

  • allows administrators at or above a domain to populate lists, while only domain-specific administrators can remove items.

Domain lists and descendant domain lists

Domain lists are block or do not block lists whose contents apply to a particular subdomain. The global lists are domain lists for the global domain. Each subdomain has its own named lists, and their contents apply only to that subdomain.

For example, a subdomain named Company A owns these lists:

  • Domain Block list - Company A and Domain Do Not Block list - Company A

  • Domain Block list for DNS - Company A, Domain Do Not Block list for DNS - Company A

  • Domain Block list for URL - Company A, Domain Do Not Block list for URL - Company A

Any administrator at or above the current domain can populate these lists. You can use the context menu to add an item to the block or do not block list in the current and all descendant domains. However, only an administrator in the associated domain can remove an item from a domain list.

For example, a global administrator could add the same IP address to the block list in the global domain and Company A’s domain, but not in Company B’s domain. This action would add the same IP address to:

  • Global Block list (removable only by global administrators)

  • Domain Block list - Company A (removable only by Company A administrators)

A descendant domain list is a do not block list or block list that aggregates the domain lists of the current domain’s descendants. Leaf domains do not have descendant domain lists.

Descendant domain lists are useful because a higher-level domain administrator can enforce general security intelligence settings, while subdomain users can add items to a block or do not block list in their own deployment.

For example, the global domain has these descendant domain lists:

  • Descendant Block lists - Global, Descendant Do Not Block lists - Global

  • Descendant Block lists for DNS - Global, Descendant Do Not Block lists for DNS - Global

  • Descendant Block lists for URL - Global, Descendant Do Not Block lists for URL - Global

Note

Descendant domain lists do not appear in the object manager because they are symbolic aggregations, not hand-populated lists. They appear where you can use them: in access control and DNS policies.