Documentation
Secure Domains website العربية

Administration Guide

Administering the DNS Armor™ platform: tenants, users and license-aware RBAC, MFA, API access, audit logs, MSP reseller audit, downloads, and tenant-scope troubleshooting.

Comprehensive Guide for Network Administrators and Security Engineers


1. Introduction

This guide is designed for network administrators, security engineers, and IT professionals responsible for administering the DNS Armor™ platform for their organization or, as an MSP, for the tenants they manage. It covers the parts of the portal that are shared by every DNS Armor™ service: the architecture and multi-tenancy model, roles and permissions, getting started and account self-service, master- and normal-tenant administration, troubleshooting, and the glossary. Configuration of the individual services is documented in their own guides — see the note after §4.

1.1 About DNS Armor™

DNS Armor™ is an enterprise-grade DNS security platform delivering two services from a single portal: DNS Armor™ Protect (DNS Firewall) — protective DNS available as Cloud Delivered (fully managed security-as-a-service) or Cloud Managed (on-premise deployment with cloud management) — and DNS Armor™ Resolve (Authoritative DNS), sovereign authoritative DNS hosting for your own zones. As the first dual-deployment DNS firewall provider in the GCC region and Africa, DNS Armor™ delivers comprehensive threat protection, network visibility, and granular security controls across 52 global data centers.

Key capabilities include:
  • Real-time Threat Intelligence: Over 10 million threat indicators updated continuously
  • AI-Powered Detection: Advanced machine learning algorithms for DNS tunneling and C2 detection
  • Multi-Tenancy Architecture: Complete data isolation for enterprise and MSP deployments
  • Regulatory Compliance: Modular design ensuring data residency requirements

1.2 Document Purpose

This administration guide provides comprehensive instructions for administering the shared DNS Armor™ platform in enterprise and MSP environments — tenants, users, roles, auditing, API access, and the supporting infrastructure pages. Service-specific configuration lives in the DNS Armor™ Protect (DNS Firewall) Guide and the DNS Armor™ Resolve (Authoritative DNS) Guide. This guide is intended for:

  • System Administrators
  • Security Operations Teams
  • Network Engineers

1.3 Prerequisites

Before proceeding with DNS Armor™ administration, ensure you have:

  • Administrative credentials for the DNS Armor™ portal
  • Understanding of DNS fundamentals and security concepts
  • List of authorized administrators and their roles

1.4 Support Information

For technical assistance:


2. Architecture Overview

DNS Armor™ is built on a cloud-native platform that provides scalable DNS security services through a unified management interface. The architecture supports enterprise requirements for organizational segmentation, regulatory compliance, and managed service delivery while maintaining high availability and performance across distributed environments.

2.1 Multi-Tenancy Model

The platform implements a two-tier hierarchical tenancy structure that enables secure isolation and delegation of administrative responsibilities:

2.1.1 Master Tenant

  • Complete platform administration
  • Cross-tenant visibility and management
  • Global policy enforcement
  • License management

2.1.2 Sub-Tenants

  • Isolated operational environments
  • Independent security policies
  • Dedicated user management
  • Segregated logging and reporting

2.2 User Roles and Permissions

DNS Armor™ employs role-based access control (RBAC) with a catalogue of granular roles. Each role grants a defined set of read or read/write permissions across the platform's services. A user is assigned one or more roles when their account is created or edited from Sidebar → Administration → Users (§4.3).

2.2.1 Role Catalogue

Role Scope of Access Typical Use Case
Admin Full read/write across most platform services within the assigned tenant Security administrators, IT managers
Read-Only Read access to configurations, monitoring, and reports across most services Auditors, compliance officers, junior staff
Security Operator Write access to security-focused services: Security Policies, Rulesets, Bypass Domains, Dynamic DNS, Endpoints, Networks, AI Threat Detection SOC engineers responsible for policy and ruleset changes
Security Analyst Read-only counterpart to Security Operator — view security configurations, monitor events, but make no changes SOC analysts, investigators
License Administrator Write access to licensing and account-management services: Customers, Tenants, Users, Resolvers, MSP Audit Billing administrators, account owners
License Reader Read-only counterpart to License Administrator — view licensing and account data without modifying it Procurement reviewers, finance auditors
DNS Zone Operator Write access to the DNS Armor™ Resolve (Authoritative DNS) services: Zones, Zone Profiles, DNSSEC Profiles, Traffic Steering / Health Checks, transfer and query access controls; read access to Auth DNS Statistics DNS administrators managing hosted zones and records
DNS Zone Reader Read-only counterpart to DNS Zone Operator — view zones, records, DNSSEC configuration, and Auth DNS statistics without making changes NOC staff, zone-change reviewers
Root Bypasses all RBAC checks; full platform-wide access including operations reserved for platform administrators Platform operators only; assignable only by Root / App Root accounts, and only to users of a Root or App Root customer

2.2.2 Role Combination Rules

The portal permits some roles to be combined on a single user account, while others are mutually exclusive:

  • Exclusive roles – Admin, Read-Only, and Root are each assigned on their own; they cannot be combined with any other role.
  • Combinable roles – A user may hold at most one role from each of the three combinable groups: one Security role (Security Operator or Security Analyst), one License role (License Administrator or License Reader), and one Auth DNS role (DNS Zone Operator or DNS Zone Reader) — for example Security Operator + License Reader + DNS Zone Operator. This supports separation-of-duties patterns where the same person handles security policy, reads (but does not change) account data, and operates hosted zones.
  • Mutually exclusive within a group – Security Operator and Security Analyst cannot be combined with each other; License Administrator and License Reader cannot be combined; DNS Zone Operator and DNS Zone Reader cannot be combined.
  • Maximum roles per user – Three combinable roles (one Security + one License + one Auth DNS). Exclusive roles count as one and replace any other selection.

The Users page enforces these rules in the role selector — invalid combinations cannot be saved — and offers a View Permission Matrix link showing the full role-to-service grid.

License-aware role availability: the role selector only offers roles for products the target user's tenant is licensed for. Security roles require the DNS Armor™ Protect (DNS Firewall) service; DNS Zone roles require the DNS Armor™ Resolve (Authoritative DNS) service. If a tenant does not hold the Resolve license, DNS Zone Operator and DNS Zone Reader do not appear in the dropdown, and the backend rejects any attempt to assign them — on both create and edit. Product-independent roles (Admin, Read-Only, License roles) are always assignable. A tenant with no licenses recorded is treated as a legacy DNS Firewall-only tenant (Security roles offered, DNS Zone roles not). If the selected target tenant is changed to one with fewer licenses, already-selected roles that are no longer assignable are removed automatically.

2.2.3 Tenant Scoping

Every assigned role is scoped to the user's tenant. A user with the Admin role on Tenant A cannot read or write data belonging to Tenant B. The exceptions are platform-administrator roles (Root and the App Root account type) which can access all tenants.

2.2.4 RBAC Services Reference

Each portal page is governed by a named RBAC service. Roles grant read, write, or no-access permission against each service. The Views and Access block of every section in §4 of this guide — and of every section in the DNS Armor™ Protect (DNS Firewall) Guide and the DNS Armor™ Resolve (Authoritative DNS) Guide — names the RBAC service for that page so administrators can troubleshoot visibility and permission issues.

Common services include: Customer, Tenant, User, APICodes, AuditLog, MspAudit, Resolver, ExternalNetwork, PrivateNetwork, LocalResolvers, BypassDomainConfig, DDNSName, SecurityPolicy, LocalRuleset, RemoteRPZFeeds, NameServerGroup, Dns, DnsDailyStats, DnsTunnelling, Endpoint, Apps, DomainIntelligence, and the Authoritative DNS services AuthZone, AuthDnssec, AuthGeoHealth, AuthDnsStats.

ℹ️ NOTE: If a user reports "I cannot see the menu item" or "the buttons are greyed out", check which role(s) they hold against the service that governs the affected page. The fix is usually to grant the missing role rather than to elevate the user to Admin.

2.3 Security Framework

The platform implements defense-in-depth security:

  • Authentication: Multi-factor authentication (MFA) support
  • Session Management: Configurable timeout periods (default: 30 minutes)
  • Audit Trail: Comprehensive logging of all administrative actions
  • Data Encryption: TLS 1.3 for all communications

3. Getting Started

This section covers the initial setup and navigation of the DNS Armor™ platform.

3.1 Initial Login

The sign-in page pairs a branding panel — carrying the platform headline "Protect. Resolve. Stay Sovereign." and product feature highlights — with the sign-in form, and has dedicated mobile views.

  1. Navigate to your DNS Armor™ instance URL: https://dnsarmor.secure-domains.org
  2. Enter your credentials:
    • Username: Your portal username or email address
    • Password: Provided during onboarding
  3. Complete the anti-bot verification challenge if presented
  4. Complete MFA verification if enabled: a Two-Factor Authentication step asks you to "Enter the verification code from your authentication app" — enter the 6-digit code and click Verify & Sign In
  5. Accept the Terms and Conditions on first login (Accept & Continue)

ℹ️ NOTE: On deployments where self-service signup is enabled, the sign-in page also offers a "Don't have an account? Sign up" link for creating a self-service account. Self-service accounts, plans, and billing are covered in the dedicated Self-Service Guide; this guide covers the administrator portal.

3.2 Dashboard Overview

The sidebar is organised product-first. A shared area at the top covers your account and infrastructure, followed by a block for each DNS Armor™ service your tenant is licensed for — DNS Firewall (the DNS Armor™ Protect service) and, where enabled, Authoritative DNS (the DNS Armor™ Resolve service). Tenants without the Resolve licence do not see the Authoritative DNS block; the DNS Firewall block remains visible for all existing customers.

3.2.1 Overview, Administration & Infrastructure

  • Platform Overview – cross-product dashboard (top of the sidebar; documented in §4.1)
  • Manage Subscription – top-level link shown to self-service accounts only (see the Self-Service Guide)
  • Administration – Customers (platform operators only), Tenants, Users, MSP Audit, Audit Logs, API Keys, Downloads
  • Self-Signup Analytics – shown only to platform administrators (Root / App Root with an Admin, Root, or License role); summarizes Consumer, SMB, and Education & Library self-service accounts (documented in §4.8)
  • Cloud Servers – the shared DNS server screen, listing DNS Firewall resolvers, RPZ distribution servers, and Authoritative DNS nodes (page titled "Assigned Cloud Servers"; documented under DNS Server Management in the DNS Armor™ Protect Guide (§2.1)). It sits above the product blocks because it is shared by both services.

3.2.2 DNS Firewall

The DNS Firewall block groups the Protect (recursive-protection) pages into three sections:

  • Setup – Networks, Local Resolvers, Bypass Domains, DDNS Names
  • Security – Cloud Policies, Rulesets, Automated Feeds (feed management, including external RPZ feeds)
  • Monitoring – DNS Monitor, DNS Statistics, Daily DNS Analytics, Discovery Analytics, AI Threat Detection, Domain Intelligence (platform administrators only), Domain Lookup, Endpoints

3.2.3 Authoritative DNS

Shown only for tenants licensed for DNS Armor™ Resolve (Authoritative DNS) — the service for hosting and serving your own domains:

  • Zones – host zones and records, manage zone settings (SOA metadata), enable DNSSEC, and configure Traffic Steering and Health Checks
  • Zone Profiles – reusable zone configuration templates
  • DNSSEC Profiles – reusable signing policies
  • Query ACLs – source-IP access control for zone queries
  • TSIG Keys – transfer keys for authenticated zone transfers
  • Transfer ACLs – outbound zone-transfer (AXFR-out) permissions
  • Statistics – zone and record counts plus per-zone query volume

For full coverage of the Resolve service, see the dedicated Authoritative DNS Guide.

Menu items are additionally hidden per user by RBAC: an entry only appears when at least one of the user's roles can read the service that governs the page (§2.2.4).

3.3 Navigation Guide

The interface is designed with intuitive navigation patterns that provide quick access to all administrative functions while maintaining security through role-based access controls.

Administrative tables across the portal share a common toolbar: a free-text search box (type your term and press Enter), a filter bar whose active filters appear as removable chips, clickable dashboard summary cards that apply the matching filter, and a CSV export action. Searching and filtering are evaluated server-side across the full dataset — results are not limited to the rows currently visible on the page. The filter dimensions available on each page are listed in that page's "Filters and Search" block — in §4 of this guide for shared administration pages, and in the DNS Armor™ Protect (DNS Firewall) Guide or the DNS Armor™ Resolve (Authoritative DNS) Guide for the product pages.

3.4 Account Self-Service

Self-service account features are reachable from the user avatar in the top-right corner of every portal page. They are available to every authenticated user regardless of role.

3.4.1 My Profile

Where to find it: Top navigation bar → user avatar → My Profile

The My Profile modal is your personal account settings panel. It opens as a dialog (you do not navigate away from the current page). The modal has three tabs:

3.4.1.1 User Information Tab
  • Username, Email, First Name, Last Name, Job Title, Contact Number – Read-only summary; ask your administrator to update these via the Users page (§4.3)
3.4.1.2 Access & Permissions Tab
  • Tenant – The tenant your account is bound to
  • Role(s) – Your assigned roles (Admin, Read-Only, etc.)
  • Customer / Region – The default customer region your account uses
  • Timeout Period – Editable by you; the number of inactivity minutes before your session expires (default 30)
3.4.1.3 Session Information Tab
  • MFA Status – Whether multi-factor authentication is enabled for your account
  • Last Login – Timestamp of your most recent successful login
  • Current Session Started – When the active session began

To save changes made on the Access & Permissions tab, click Save in the modal footer.

3.4.2 Change Password

Where to find it: Top navigation bar → user avatar → Change Password (or visit /change-password directly)

  1. Open the Change Password page from the user avatar menu.
  2. Enter your Current Password.
  3. Enter your New Password; the form indicates whether the password meets the strength requirements (length, mixed case, numeric, symbol).
  4. Re-enter the new password in the Confirm Password field.
  5. Click Update Password. You stay signed in with the new credentials in effect immediately.

ℹ️ NOTE: First-time users are routed through this page automatically after accepting the Terms & Conditions on initial login.

3.4.3 Forgot Password / Reset

Where to find it: Login page → Reset Password link (or visit /reset-password directly)

  1. From the sign-in page, click Reset Password.
  2. Enter the email address or username associated with your account in the Email / Username field.
  3. Submit the form; the platform sends a secure password-reset email.
  4. Open the email and follow the link to set a new password. The link is single-use and time-limited.

3.4.4 Terms & Conditions

When you see it: Automatically presented on first login.

New users are required to read and accept the Terms & Conditions before reaching the dashboard. Acceptance is recorded against the user account and is not asked again on subsequent sign-ins. After accepting, the user is routed to the Change Password page (§3.4.2) to set their permanent password.

3.4.5 Sign Out

Where to find it: Top navigation bar → user avatar → Logout

Selecting Logout terminates your session immediately and returns you to the sign-in page. Sessions also end automatically when the inactivity timeout configured in My Profile (§3.4.1.2) elapses.


4. Master Tenant Administration

The Master Tenant dashboard provides enterprise-wide visibility and control over all DNS Armor™ resources.

4.1 Dashboard and Overview

Where to find it: Sidebar → Platform Overview (the top entry of the sidebar; this is also the page you land on by default after sign-in)

The Platform Overview page is the main administrative dashboard. It summarizes activity for the tenants and time period you have access to so you can see how DNS Armor™ is performing across your environment at a glance.

4.1.1 What You See on the Page

The page presents summary cards followed by trend charts. Typical metrics include:

  • Licensed Tenants: Current usage vs. available licenses
  • Active Users: Breakdown by tenant and role
  • DNS Query Volume: 24-hour trending
  • Security Events: Threats blocked by category
  • Threat Overview: Real-time threat statistics
  • Network Health: DNS query performance metrics
  • Policy Status: Active security policies summary
  • Recent Alerts: Critical security events
  • Web-Filter Hits and Apps Detected: Category and application activity counts
  • Top Domains and Top Threats: Most frequent entries in the period

4.1.2 How to Use It

  1. Open Sidebar → Platform Overview (or click the platform logo).
  2. Use the date-range picker to select a quick preset (Last 7 / 14 / 30 / 60 days) or a custom range.
  3. Click any summary card to drill into the queries, threats, applications, or domains that contributed to the metric.
  4. Click the Refresh icon to pull the latest data on demand.

ℹ️ NOTE: The metrics shown are scoped to the tenants you have access to — MSP administrators see aggregated data across the tenants they manage, while tenant administrators see data for their own tenant only.

4.2 Tenant Management

Where to find it: Sidebar → Administration → Tenants

The Tenants page is where you create, activate, and retire tenants. Each tenant is a self-contained environment with its own users, networks, policies, and reporting scope.

All searching and filtering on this page runs server-side across every tenant you can see, not just the visible page.

  • Search – Free-text search in all columns (press Enter)
  • Status – Active / Inactive (also applied by clicking the matching dashboard card)
  • Subscription – Current / Expired
  • Type – Master / Normal tenant
  • Segment – Account-type segment: Consumer, SMB, Education & Library, MSP, Enterprise, Platform, Legacy. This filter (and the matching Segment column) is visible only to platform administrators — Root / App Root accounts holding an Admin, Root, or License role. Self-service segments (Consumer, SMB, Education & Library) are described in the Self-Service Guide.
  • Customer / Reseller – Entity picker (platform administrators; MSP accounts see their resellers)
  • Tenant – Entity picker

4.2.1 Creating a New Tenant

  1. Open Sidebar → Administration → Tenants.
  2. Click Create Tenant. The modal is a multi-step wizard: Basic Information → Organization Details → Contact Information.
  3. Complete the steps:
    • Customer / Reseller – Required (Root and App Root users only)
    • Tenant Name – Required (e.g. default tenant); must be unique within the customer
    • Service licenses – For MSP child tenants, tick the services this tenant may use: DNS Armor™ Protect (DNS Firewall) and/or DNS Armor™ Resolve (Auth DNS). The choice is constrained to the services the reseller itself is licensed for — a tenant cannot be given a service its reseller does not hold. For non-MSP customers and the MSP master tenant, service licenses are inherited from the customer and are not editable here. Protect and Resolve are two separate licenses — a tenant may hold either or both, and neither depends on the other. Tenants without the Resolve license never see the Authoritative DNS sidebar block, its roles, or its pages.
    • Auth DNS Max Zones / Auth DNS Max Records – Shown when the Resolve license is ticked; the tenant's independent zone and record caps (defaults 50 zones / 10,000 records)
    • Send License Delivery Email to Tenant's Primary Contact – Optional toggle (MSP child tenants); emails the tenant's primary contact a license notification on creation
    • Organization Name – Optional
    • Organization Website – Optional
    • Sector – Optional
    • Number of Employees – Optional
    • Contact Name / Email / Number – Optional
    • Subscription Start Date / End Date – Optional (visible to MSP and Root users)
    • Create Admin User – Toggle. When enabled, expose:
      • Admin User Email – Required
      • First Name – Required
      • Last Name – Required
      • Job Title – Optional
      • Contact Number – Optional
  4. Click Create.
Tenant Name Use Case Description
CORP_HQ_Production Corporate headquarters Main office production environment with strict security
RETAIL_Stores_US Retail locations All US retail stores with unified policy
DEV_Environment Development team Isolated environment for testing policies
GUEST_WiFi_Global Guest networks All guest WiFi across locations
IOT_Devices IoT infrastructure Smart devices and sensors

Important: Newly created tenants must be activated before use. Activation enables:

  • User association
  • Policy creation
  • DNS service provisioning

4.2.2 Tenant Activation Process

  1. Locate the tenant in the management table
  2. Click the Actions menu (⋮)
  3. Select Activate
  4. Confirm activation in the dialog

4.2.3 Managing Existing Tenants

Available actions for each tenant:

  • View Details: Comprehensive tenant information, including subscription details and — for Resolve-licensed tenants — an Auth DNS Usage block showing zones and records used against the tenant's limits (tenants that draw from a shared customer-wide pool are marked accordingly)
  • Edit: Update tenant details, subscription dates, service licenses, and Auth DNS limits
  • Deactivate: Temporarily disable tenant access. A tenant cannot be deactivated while security policies are still associated with it — disassociate or delete the policies first
  • Delete: Permanently remove the tenant (requires deactivation first). A master tenant cannot be deleted while other tenants of the customer still exist

ℹ️ NOTE: On deployments with self-service signup, platform administrators also see an Education requests button on this page — the approval queue for pending Education & Library account verifications. Approving or rejecting requires a License Administrator, Admin, or Root role. The applicant-side flow is described in the Self-Service Guide.

4.2.4 MSP Analytics Dashboards

Above the tenants table, MSP and platform-administrator (Root / App Root) accounts see a set of collapsible analytics dashboards. Their data can also be downloaded with the Export Tenant Analytics toolbar action.

4.2.4.1 Tenants Analytics Dashboard

Tenant status, subscription and licensed-service distribution: totals for Active/Inactive tenants, Current/Expired subscriptions, and an MSP Service Licenses breakdown showing how many tenants hold Auth DNS, DNS Firewall, both, or neither.

4.2.4.2 MSP Employee Analytics Dashboard

Shown to MSP and Root users whose scope includes the DNS Armor™ Protect (DNS Firewall) service. It summarizes workforce distribution across all managed tenants: total employees, tenant counts by combined state (Active & Valid, Active & Expired, Inactive & Valid, Inactive & Expired), a License Status breakdown (Valid vs Expired), and an Employee Distribution chart with All / Active Only / Inactive Only views.

4.2.4.3 MSP Auth DNS Analytics Dashboard

Shown to MSP and Root users whose scope includes the DNS Armor™ Resolve (Auth DNS) service. It compares provisioned limits vs actual usage across MSP tenants — zones (used / limit) and records (used / limit) — split between Active & Valid Subscription and Active (Valid + Expired) tenant populations. Controls:

  • Include master tenants – Toggle that adds or removes MSP master tenants from the aggregation
  • Filter MSP resellers – Root-only multi-select picker that restricts the dashboard to specific MSP resellers (default: all MSP resellers)

4.3 User Management

Where to find it: Sidebar → Administration → Users

The Users page is where you provision administrators, assign them to tenants, set their roles (from the catalogue in §2.2.1), and manage their session security and password lifecycle.

All searching and filtering on this page runs server-side across the full user list. The four dashboard cards apply the matching filter when clicked: Total Users (clears all filters), User Status (active / inactive counts), MFA Status (MFA enabled / disabled counts), and User Roles (Admin / Read-only counts).

  • Search – Free-text search across users (username, email, and full name), customers, and tenants (press Enter)
  • Status – Active / Disabled (also applied by clicking the matching dashboard card)
  • MFA – Enabled / Disabled
  • Roles – Multi-select across the role catalogue (§2.2.1)
  • Email / Username – Free-text "contains" filters
  • Customer / Reseller – Entity picker (platform administrators)
  • Tenant – Entity picker (accounts that can see more than one tenant)

4.3.1 User Creation Workflow

  1. Open Sidebar → Administration → Users.
  2. Click Create User.
  3. Complete the modal:
    • Username – Required; must be unique
    • Email Address – Required; must be a valid email
    • First Name – Required
    • Last Name – Required
    • Job Title – Optional
    • Contact Number – Optional
    • Tenant – Required (autocomplete; only active tenants appear)
    • Role – Required; one or more roles picked in the grouped role selector (Standalone, Security, License, Auth DNS groups — see §2.2.2 for combination rules). The selector is license-aware: roles tied to a product the selected tenant is not licensed for are not offered — for example, DNS Zone Operator / DNS Zone Reader only appear when the target tenant holds the DNS Armor™ Resolve (Authoritative DNS) license. A View Permission Matrix link opens the full role-to-service permission table.
    • Session Timeout (minutes) – Optional, defaults to 30
  4. Click Create. An automated email is sent to the new user with temporary credentials; on first login they are prompted to set a new password.
4.3.1.1 Edit User Modal

Editing an existing user exposes the same fields as Create plus:

  • MFA – Enable or disable two-factor authentication for the user
  • Account Status – Enable or disable the user account
Example User Provisioning Scenarios:
Scenario 1: Security Operations Center (SOC)
  • Username: soc_analyst_01
  • Email: john.smith@company.com
  • Tenant: CORP_HQ_Production
  • Role: Read-Only
  • Session Timeout: 4 hours (extended for shift work)
Scenario 2: Network Administrator
  • Username: netadmin_jane
  • Email: jane.doe@company.com
  • Tenant: Master-Tenant-Normal_Customer
  • Role: Admin
  • Session Timeout: 30 minutes (default)
Scenario 3: Compliance Auditor
  • Username: audit_external_kpmg
  • Email: auditor@kpmg.com
  • Tenant: CORP_HQ_Production
  • Role: Read-Only
  • Session Timeout: 8 hours (full day access)

4.3.2 Session Security Settings

  • Default timeout: 30 minutes
  • Configurable range: 5 minutes to 24 hours
  • MFA (configurable after user's login)

4.3.3 User Lifecycle Management

Available user actions:

  • Enable MFA: Enforce two-factor authentication
  • Deactivate User: Suspend access while preserving configuration
  • Edit User: Modify role or session timeout
  • Send Password Reset: Trigger secure password reset email

4.4 Audit and Compliance

Where to find it: Sidebar → Administration → Audit Logs

The Audit Logs page is the forensic record of every administrative action taken in the portal. Use it for compliance reporting, change reviews, and investigation of unexpected configuration changes.

4.4.1 What You See on the Page

Each audit entry records:

  • Timestamp – When the action occurred (with timezone)
  • User – The administrator who performed the action
  • Action – What was done (create, update, delete, etc.)
  • Resource – The object that was affected
  • Source IP – Originating IP address of the request

4.4.2 Filters and Search

Filtering and search run server-side across the full audit history.

  • Search – Free-text search across the log (press Enter)
  • Action – Create, Update, Delete, Login, Logout, Other (the dashboard cards apply the same filter)
  • Customer / Reseller – Entity picker (platform administrators)
  • Tenant – Entity picker (accounts that can see more than one tenant)
  • Refresh Data – Re-fetch the audit log
  • Delete Logs – Restricted to platform administrators; deletes the logs of a selected customer and/or tenant after a confirmation dialog

4.4.3 How to Use It

  1. Open Sidebar → Administration → Audit Logs.
  2. Use the toolbar filters to narrow by action, customer, or tenant, or search for a user, resource, or IP.
  3. Click an audit row to open the Audit Log Details dialog with the full record (user, resource, tenant/customer, and action details).
  4. Click Export to CSV to download the filtered log for compliance reporting.

4.5 API Management

Where to find it: Sidebar → Administration → API Keys

The API Codes page is where you generate and manage the API codes used for programmatic access and for authenticating Endpoint Agents and Local Resolver appliances during enrollment.

4.5.0 Views and Access

  • Master Tenant view: See and manage API codes across every tenant the account is authorized for
  • Normal Tenant view: See and manage only the API codes scoped to the assigned tenant
  • RBAC: Users with write permission on the APICodes service (the Admin role) can create, reset, and delete codes; Read-Only users can view metadata but cannot generate or revoke codes

Filtering and search run server-side across all codes in scope.

  • Search API codes – Free-text search across customer / reseller name, tenant name, API code, and customer / tenant IDs (press Enter)
  • Dashboard cards – Click a customer (reseller) or tenant listed on the Customers / Resellers or Tenants card to filter the table
  • Customer / Reseller – Entity picker (platform administrators)
  • Tenant – Entity picker

4.5.2 Creating API Codes

  1. Open Sidebar → Administration → API Keys.
  2. Click Create API Code.
  3. Complete the modal:
    • Customer / Reseller – Required (Root and App Root users only)
    • Tenant – Required. Each tenant can hold at most 3 API codes; the picker shows the current count per tenant (for example, 3/3 API codes). When every tenant available to the selected customer has reached this limit, the create action reports that the maximum has been reached — delete or reset an existing code to free a slot
  4. Click Create API Code. The generated 24-character code is shown once in a copy-to-clipboard field — save it securely immediately. Afterwards only the last 4 characters remain visible in the table.

Existing codes can be Reset (regenerated — the old code stops working) or Deleted from the Actions column.

✅ BEST PRACTICE: Store API codes in a secrets manager. Rotate them on a defined cadence and revoke any code that may have been exposed.

4.6 MSP Audit

Where to find it: Sidebar → Administration → MSP Audit

The MSP Audit page is a chronological log of changes affecting tenants you manage. Use it for billing reconciliation, compliance review, and tracking how long each tenant has been active.

4.6.1 What You See on the Page

The page shows a table of audit entries with the following columns:

  • Tenant Name – The tenant that the change applies to
  • Activity – Activation, Deactivation, or Limit Change
  • Timestamp – When the change took place
  • Total Active Time – How long the tenant has been active in total (days, hours, minutes)
  • Details – Description of what changed

Filtering and search run server-side across the full audit history.

  • Search – Free-text search across tenant and customer name (press Enter)
  • Activity Type – Activation, Deactivation, Limit Change
  • Customer / Reseller – Entity picker (platform administrators)
  • Tenant – Entity picker

4.6.3 How to Use It

  1. Open Sidebar → Administration → MSP Audit.
  2. Use the activity type, customer, and tenant filters to narrow the entries shown.
  3. Sort entries by clicking the Timestamp column header (default order is most recent first).
  4. Click a tenant name to see the full activity timeline for that tenant.
  5. Click Export to download the filtered list as CSV for offline reporting.

ℹ️ NOTE: MSP Audit is visible only to Root, App Root, and MSP user types. The view always shows the audit entries for tenants the account manages.

4.7 Downloads

Where to find it: Sidebar → Administration → Downloads

The Downloads page is the central location for product installers and supporting documents. Use it whenever you need to deploy a Local Resolver appliance, install the Endpoint Agent, or grab a copy of the official guides.

4.7.1 What You Can Download

The page is organised into three tabs:

  • Local Resolver – Virtual appliance images for VMware ESXi, Microsoft Hyper-V, and KVM/QEMU
  • Endpoint Agent – Installers for Windows, macOS, and Linux/Ubuntu
  • Certificates – Trust certificates, such as the Block Page CA certificate (the SNMP MIB file for monitoring integrations is on the Local Resolver tab)

4.7.2 How to Download

  1. Open Sidebar → Administration → Downloads.
  2. Select the product tab for the item you need (for example, Endpoint Agent).
  3. Hover the version label to view system requirements before downloading.
  4. Click the platform-specific download button (Windows / macOS / Linux).
  5. Open the linked installation guide for step-by-step deployment instructions.

✅ BEST PRACTICE: Always download the latest version listed on the page so you receive the most current security definitions and feature updates.

ℹ️ NOTE: Downloads is part of the DNS Armor™ Protect (DNS Firewall) service — tenants licensed only for Resolve do not see this menu item.

4.8 Self-Signup Analytics

Where to find it: Sidebar → Self-Signup Analytics (a top-level entry, visible only to platform administrators — Root / App Root accounts holding an Admin, Root, or License role)

The Self-Signup Analytics dashboard summarizes all self-service accounts on the platform: Consumer, SMB, and Education & Library segments — seats, subscriptions, and usage. It includes Protect seat totals (all / Basic / Advanced), tenant distribution and totals by segment, Resolve licenses and usage against caps, and a signup trend chart with selectable ranges (last month up to last year). Use the segment selector to focus on a single account segment.

For how self-service accounts are created, billed, and managed by the account holders themselves, see the Self-Service Guide — this page is the administrator-side reporting view only.


Product configuration has moved

This guide covers the shared platform: architecture, getting started, master- and normal-tenant administration, troubleshooting, and the glossary. The configuration of each DNS Armor™ service now lives in its own guide:

ℹ️ NOTE: DNS Armor™ Protect and DNS Armor™ Resolve are two separate licenses — Resolve is not an add-on to Protect. A tenant may hold either service or both; neither depends on the other, and each is purchased and enabled on its own. The two may be purchased together on one invoice, which is a billing convenience rather than a dependency. What appears in the portal follows the license(s) the tenant holds.

5. Normal Tenant Administration

The Normal Tenant View provides a tailored interface for users assigned to specific tenant environments. This view maintains the same functional capabilities as the Master Tenant View but with important access restrictions that ensure proper multi-tenant isolation and security.

5.1 Access Restrictions and Limitations

5.1.1 Limited Tenant Operations

  • No Tenant Creation: Cannot create new tenant environments
  • No Tenant Deletion: Cannot remove existing tenant environments
  • No Tenant Activation: Cannot activate or deactivate tenant environments
  • Read-Only Tenant View: Can access their tenant details in read-only mode

5.1.2 Resource Visibility

  • Tenant-Specific Access: Can only view and manage resources within assigned tenant
  • Configuration Isolation: Cannot access configurations from other tenant environments
  • User Management: Limited to users within the same tenant environment
  • Policy Management: Can only create and modify policies for assigned tenant

5.1.3 Data Access Restrictions

  • Monitoring Data: Limited to tenant-specific DNS queries and events
  • Audit Logs: Can only view audit events related to assigned tenant
  • Reporting: All reports and analytics filtered to tenant scope
  • Export Functions: Data exports contain only tenant-specific information

5.2 Available Administrative Functions

5.2.1 User Management

  • Create and manage users within assigned tenant
  • Configure user roles and permissions from the role catalogue (§2.2.1); the role selector offers only roles whose product the tenant is licensed for
  • Enable MFA and manage user authentication settings
  • Send password reset emails and manage user lifecycle

5.2.2 Audit and Compliance

  • View comprehensive audit logs for tenant activities
  • Export audit data for compliance and analysis purposes
  • Monitor user activities and system changes within tenant scope
  • Generate compliance reports for assigned tenant environment

5.2.3 Network Services

  • View assigned DNS servers and infrastructure
  • Configure external and private networks for tenant
  • Manage Local Resolver configurations
  • Monitor DNS server performance and availability
Network Management:
  • Create and manage network segments within tenant scope
  • Configure network-to-policy mappings
  • Optimize network performance through proper configuration
  • Maintain network documentation and change management

5.2.4 Security Management

  • Create and manage security policies for assigned tenant
  • Configure local rulesets and custom filtering rules
  • Integrate with automated threat intelligence feeds
  • Schedule policy activation and time-based enforcement
Threat Protection:
  • Configure threat detection and response settings
  • Manage whitelist and blacklist policies
  • Monitor security events and threat activities
  • Generate security reports and compliance documentation

5.2.5 DNS Monitor

  • Real-time monitoring of DNS queries and responses
  • Historical analysis of DNS traffic patterns
  • Security event correlation and analysis
  • Performance monitoring and optimization recommendations
Reporting Capabilities:
  • Generate comprehensive DNS activity reports
  • Export data for external analysis and compliance

ℹ️ NOTE: The network, security-policy, and monitoring functions listed in §5.2.3–§5.2.5 belong to DNS Armor™ Protect (DNS Firewall) and are documented in full in the DNS Armor™ Protect (DNS Firewall) Guide (§2–§4). Zone and record administration for tenants licensed for DNS Armor™ Resolve is covered in the DNS Armor™ Resolve (Authoritative DNS) Guide. The restrictions described in §5.1 apply to those pages exactly as they do to the pages in this guide.


6. Troubleshooting

This section provides guidance for resolving common issues and troubleshooting scenarios.

6.1 Common Issues Overview

Common Issue Symptoms Resolution
DNS Resolution Failures Queries timing out Verify network configuration and bypass domains
Policy Not Applied Traffic not blocked Check policy activation and network mapping
High Latency Slow DNS responses Review your geographic server selection to ensure you are assigned to the correct region closest to your location. If you need to change your region assignment, please contact support
Login Issues Authentication failures Verify credentials and MFA settings

6.2 Detailed Troubleshooting Scenarios

6.2.1 Issue 1: Internal Applications Not Resolving

Symptoms:
  • Users cannot access intranet.company.local
  • Active Directory authentication failing
  • Internal services unreachable
Investigation Steps:
  1. Check Local Resolver bypass domains configuration
    • Verify company.local is listed
    • Confirm local DNS servers are specified
  2. Test from affected subnet
    • nslookup intranet.company.local
    • Verify query goes to local DNS (10.1.1.10)
  3. Review Local Resolver logs for dropped queries
Resolution:
  • Add missing domains to bypass list via Local Resolver configuration:
    • _ldap._tcp.company.local
    • _kerberos._tcp.company.local
    • gc._msdcs.company.local
  • Restart Local Resolver service after changes

6.2.2 Issue 2: Legitimate Sites Being Blocked

Symptoms:
  • Users report "This site has been blocked"
  • Business partner portal inaccessible
  • SaaS application not working
Investigation Steps:
  1. Check DNS query logs
    • Filter by user IP or domain
    • Identify which rule triggered block
  2. Review security policy
    • Check rule priority order
    • Verify threat feed categories
  3. Analyze domain reputation
Resolution Example:

6.2.3 Issue 3: Policy Changes Not Taking Effect

Symptoms:
  • Modified rules still show old behavior
  • New blocks/allows not working
  • Inconsistent policy application
Diagnostic Process:
  1. Verify policy activation
    • Check "Active" status
    • Confirm network mappings
    • Review time-based schedules
  2. Check rule priority
    • Higher priority rules override
    • Examine all applicable policies
  3. Clear DNS cache
    • Client-side: ipconfig /flushdns
    • Wait for DNS cache TTL to expire
Common Fixes:
  • Policy showing "Inactive": Re-activate policy
  • Wrong network mapping: Update IP ranges
  • Rule conflict: Reorder rules appropriately
  • Cache issues: Wait 5 minutes or force refresh

7. Local Resolver Administration

For comprehensive information about Local Resolver deployment, configuration, and management, please refer to the dedicated DNS Armor™ Local Resolver Deployment Guide.

The Local Resolver Deployment Guide covers:

  • Solution Overview and Operating Modes
  • Pre-Deployment Planning
  • Installation and Configuration
  • Active Directory Integration
  • High Availability Configuration
  • Deployment Validation
  • Monitoring and Operations
  • Troubleshooting Guide

ℹ️ Note: Local Resolver configuration replaces the legacy Bypass Domains functionality, providing enhanced local DNS resolution capabilities with comprehensive policy management.


8. Glossary

Term Definition
DNS Armor™ Protect The DNS Firewall (protective DNS) service of the DNS Armor™ platform
DNS Armor™ Resolve The Authoritative DNS (zone hosting) service of the DNS Armor™ platform; licensed separately from DNS Armor™ Protect — a tenant may hold either service or both
Local Resolver DNS Forward Proxy - Encrypts and forwards DNS queries
RPZ Response Policy Zone - DNS firewall ruleset format
C2 Command and Control - Malware communication channel
DoH DNS over HTTPS - Encrypted DNS protocol
DoT DNS over TLS - Encrypted DNS protocol
MSP Managed Service Provider
RBAC Role-Based Access Control
AXFR DNS Zone Transfer - Protocol for transferring zone data
NXDOMAIN DNS response code indicating domain does not exist
NODATA DNS response with empty answer section
PASSTHRU Allow DNS query to be resolved normally
CIDR Classless Inter-Domain Routing - IP address notation
MFA Multi-Factor Authentication
SIEM Security Information and Event Management

END OF DOCUMENT

DNS Armor™ Administration Guide

v2.1 · July 2026

© 2026 Secure Domains - All Rights Reserved

For technical support: support@secure-domains.org
Portal: https://dnsarmor.secure-domains.org
Documentation: https://www.secure-domains.org/documentation