Cisco Cloud Control Administration

 
Updated July 23, 2026
PDF
Is this helpful? Feedback

Manage users

In Users, you can view and manage the users who have access to Cisco Cloud Control and connected products.

note.svg

If you are using an external Identity Provider (IdP) and notice stale administrator entries, please note that this is not a security vulnerability. This behavior occurs due to a current lack of integration with your IdP’s lifecycle management feature. Cisco defers to your IdP as the authoritative source for all user access control.


users.jpg

From this page, you can:

  • Search for a user by their name or email address.

  • Filter the table by the products users can access.

  • View user details.

  • Select Manage users to:

  • Select settings.jpg to configure the information that the Users page displays.

  • Select a user’s display name link to view their summary page. Here, you can update their profile information and change their admin role.
    You can also select ellipsis.jpg to open a menu that provides the same options.

Add a user

  1. Open the Admin Console:

    1. In the top navigation bar, select app-launcher.jpg.

    2. Under Platform Services, select Admin Console.

  2. From the left navigation, select Users.

  3. Select Manage users > Add user.

  4. In Add user, complete these tasks:

    1. Enter the email address of the user you are adding, then select Next.

    2. (Optional) Enter the user’s first and last name, then select Next.

    3. (Optional) Assign one of these admin roles to the new user, then select Next:

      • Tenant Full Admin: Has the privileges necessary to configure and manage all tenant-level settings.

      • Tenant Read-only Admin: Can view all tenant-level settings, but cannot change them.

      • Integration Admin: Can manage cross-product and third-party integrations in Cisco Cloud Control, but does not have platform administration rights.

    4. In Summary, confirm the information you have entered for the new user is correct, then select Add user.

Configure Nexus Dashboard access

Complete this procedure to configure a Cisco Cloud Control user’s access to Nexus Dashboard.

  1. Open the Admin Console:

    1. In the top navigation bar, select app-launcher.jpg.

    2. Under Platform Services, select Admin Console.

  2. From the left navigation, select Users.

  3. Select Manage users > Manage Nexus Dashboard access.
    To change the settings for a user who already has access to Nexus Dashboard, select ellipsis.jpg > Manage assignment, then skip ahead to Step 5b.

  4. Select Assign.

  5. In Assign user, complete these tasks:

    1. Select a Cisco Cloud Control user, then select Next.

    2. Check the role you want to assign to user:

      • Fabric Administrator: Has full fabric management privileges.

      • Designer: Can modify configurations, but cannot deploy these changes to network fabrics.

      • Approver: Can approve or deny submitted configuration changes when change control is enabled.

      • Observer: Has read-only access.

      • Support Engineer: Performs support tasks. Can also deploy or revert approved changes under change control, but cannot modify configurations.

    3. Indicate why you are assigning the user with an access role, then select Next.

    4. Confirm that the settings you entered are correct, then select Save.

Manage tenants

In the Tenants page, you can view all the product tenants that are accessible from Cisco Cloud Control. This page displays both grouped and ungrouped tenants.

tenants.jpg
Callout Action

1

Opens the tenant switcher.

2

Search for a tenant by name.

3

Filter the table by the products associated with a tenant.

4

View tenant details, such as:

  • Name

  • Email address

  • Associated products

note.svg

If a number is displayed next to a product name, this indicates that the tenant has access to more products. To view these products, either place your cursor over this number or select > in the tenant’s Name column.


  • Type: Indicates whether a tenant has been grouped.

5

Create a new tenant group.

6

Select to:

  • Create a new tenant group.

  • Add this tenant to an existing group.

note.svg

Depending on the tenant you are adding, you may need to sign in to continue with this operation.


7

Rename a tenant group.

Tenant considerations

  • Authentication: You may be prompted to sign in when adding a tenant to a group for the first time. This security measure authenticates your identity across different product environments.

  • Permissions: You can only group tenants for which you have the Tenant Full Admin role. Users configured with the Tenant Read-only Admin role can view all tenant-level settings, but cannot change them.

  • Browser behavior: When switching tenants, Cisco Cloud Control may open a pop-up window to handle authentication of the cross-launch. Ensure your browser is configured to allow pop-ups from the Cisco Cloud Control domain.

  • Orphaned tenants: When tenants are grouped, Cisco Cloud Control uses one of these tenant’s ID as the primary identifier. Cisco Cloud Control does not automatically delete the IDs of the other tenants that joined the group.

Create a tenant group

  1. Open the Admin Console:

    1. In the top navigation bar, select app-launcher.jpg.

    2. Under Platform, select Admin Console.

  2. From the left navigation, select Tenants.

  3. Select Group tenants.
    The system displays the products for which you have full administrative access.

  4. Select the tenants you want to include in the group, choosing one tenant for each product.

    note.svg

    To verify your identity and obtain the necessary tokens, you are prompted to sign in to each individual tenant you are adding.


  5. Enter a name for the group.
    A check box indicates that after logging into a grouped tenant, a user can access any of the other tenants that belong to the same group.

  6. Select the check box, then select Save.

Tenant switcher

The Cisco Cloud Control tenant switcher allows you to navigate efficiently between different product tenants, such as Cisco Cloud Security, Intersight, and Meraki. If you are moving between linked tenants or products within the same realm, Cisco Cloud Control performs a background token exchange. You are then transitioned to the new environment without needing to re-enter your credentials.

Tenant switcher considerations

  • Permissions and roles: Access is governed by your assigned permissions. You will only see and be able to switch to tenants for which you have the appropriate access.

  • Session security: For security, your session has a defined timeout. If your token expires, you may be required to re-authenticate regardless of your previous activity.

  • Linked products: The feature is optimized for products linked to Cisco Cloud Control. If you switch to a tenant that is not associated with your current product, you may be redirected to the main Cisco Cloud Control dashboard.

Troubleshooting tenant switching

  • Latency: A brief loading period during a switch is normal as the system verifies your credentials across products.

  • Missing tenants: If a specific tenant does not appear in the tenant list, verify with your administrator that your user account has been properly provisioned and linked with that product.

  • Browser issues: If a switch fails or hangs, check your browser’s pop-up settings and ensure that pop-ups are not blocked for Cisco Cloud Control.

Set up SSO

To configure single sign-on (SSO) for Cisco Cloud Control users, complete these tasks:

Create a domain

  1. Open the Admin Console:

    1. In the top navigation bar, select app-launcher.jpg.

    2. Under Platform, select Admin Console.

  2. From the left navigation, select Settings > Manage domains.

  3. Select Add a domain.

  4. Enter your domain or subdomain name and select Next.

  5. Copy the verification token into your DNS TXT record.

    • If your DNS host supports only one TXT record, add the token on a separate line.

    • If your DNS host supports multiple records, add your token on a single line in its own TXT record.

  6. Choose one of the following:

    • Add the DNS TXT record to your DNS server.

    • If your DNS server is configured by another administrator, send the DNS TXT record to your administrator to add to your DNS server.

    • Select Add domain.

      • Your domain appears in your list of domains with the status Pending. Once verified, the status changes to Verified.

        After the domain is verified, the TXT record is no longer required, and you can remove the verification token from your DNS server.

      • If the verification fails, the error is cached by your DNS server. Your DNS server clears the cache after the specified length of time in the Time To Live (TTL) setting. You must wait to try again after the DNS server clears the cache. You can add the verification token again and request the verification for the domain.

Configure an IdP using SAML

SAML provides a structured framework that allows IdPs and service providers to communicate with each other, making federated identity and single sign-on possible and efficient. You have a choice when setting up a SAML IdP. You can manually enter your IdP’s metadata or directly upload the metadata to the admin portal.

  1. Open the Admin Console:

    1. In the top navigation bar, select app-launcher.jpg.

    2. Under Platform, select Admin Console.

  2. From the left navigation, select Settings > Manage IdPs.

  3. Select Add an IdP.

  4. In Add an Identity Provider, select SAML as your IdP and select Next.

  5. Select one of these methods to connect your IdP:

    • Fill out configuration form: Manually enter your IdP’s metadata.
      Proceed to Step 6 if you select this option.

    • Upload your IdP’s metadata: Upload an XML file containing your IdP’s metadata.
      Proceed to Step 7 if you select this option.

  6. If you selected Fill out the configuration form:

    1. Enter your Entity ID (SAML Identifier).

    2. Enter your Single sign-on URL.

    3. Select a binding method: HTTP-Post or HTTP-Redirect.

    4. (Optional) Enter your Single sign-out URL.

    5. (Optional) Select a binding method: HTTP-Post* or HTTP-Redirect**.

    6. Check the checkbox to enable Sign SAML request.

      Select this checkbox if your IdP requires authentication requests to be signed.

    7. Select a NameID format.

      You can select one of these options:

      • urn:oasis:names:tc:SAML1.1:nameid-format:emailAddress (default): This format uses your email address as your NameID.

      • urn:oasis:names:tc:SAML2.0:nameid-format:transient: This format generates a temporary, one-time NameID for each authentication.

      • urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified: This format indicates that no specific NameID format is requested, leaving it to your IdP to determine or default to an appropriate format.

    8. Upload your IdP certificate files.
      If your IdP uses multiple signing certificates, you can upload up to two IdP certificate files (in .pem or .cer format).

    9. Select Next.

  7. If you selected Upload your IdP’s metadata:

    1. Upload an XML file containing your IdP’s metadata.
      When uploading the metadata file, there are two ways to validate the metadata from the Customer IdP:

      • Not signed, self-signed, or private CA-signed IdP metadata file: Your IdP provides a self-signed private CA or doesn’t provide a signature for their metadata. This option is less secure.

      • Signed by a public certificate authority: Your IdP provides a signature in the metadata that is signed by a Public Root CA.

    2. Select Next.

      warn.svg

      Only upload metadata generated by your IdP. Uploading the wrong metadata file will cause SSO failure and might lock all administrators out of the account.


  8. (Optional) Configure SAML attributes and settings.
    The SAML identity provider (IdP), by default, uses the uid attribute to identify the user when sending authentication data to Cisco Cloud Control. If the IdP supports other NameID configurations, you can modify this configuration.

  9. Select Add IdP.
    If this is the first IdP you have configured, the IdP is saved as your default IdP, and a default routing rule is created.

Configure an IdP using OpenID

Use OpenID Connect (OIDC) to set up Single Sign-On (SSO) using your identity provider. OIDC is built on the OAuth 2.0 framework and supports secure authentication through encrypted tokens and built-in certificate validation.

note.svg

When you set up OpenID Connect with Entra ID or an IdP where the email isn’t a permanent identifier, we recommend that you use the externalId linking attribute to map to a unique identifier. For Entra ID, we suggest mapping OIDC to externalId. If the email you enter doesn’t match the linking attribute, you’re prompted to verify your identity or create a new user with the correct email address.


  1. Open the Admin Console:

    1. In the top navigation bar, select app-launcher.jpg.

    2. Under Platform, select Admin Console.

  2. From the left navigation, select Settings > Manage IdPs.

  3. Select Add an IdP.

  4. In Add an Identity Provider, select OpenID Connect as your IdP and select Next.

  5. Enter your IdP information.

    1. Enter your IdP Name.

    2. Enter your Client ID: This is the unique ID that identifies you and your IdP.

    3. Enter your Client Secret: This is the password that you and your IdP know.

    4. Select the scopes you want to associate with your IdP.
      OpenID and Email are selected by default.

  6. Select one of these methods to add endpoints:

    • Use the discovery URL: Enter the discovery URL for your IdP. This URL will automatically populate the necessary endpoints for OIDC single logout (SLO).

    • Manually add all endpoint information: Select this option if your IdP doesn’t support discovery URLs. You’ll be prompted to enter each endpoint manually. Fill in these fields:

      • Issuers (comma-separated): Enter one or more issuer URIs, separated by commas.

      • Authorization endpoint: URL used to initiate the authorization flow.

      • Token endpoint: URL to retrieve access tokens.

      • (Optional) JWKS URI: URL to retrieve the JSON Web Key Set.

      • (Optional) Userinfo endpoint: URL to retrieve user profile information.

      • (Optional) End session endpoint: URL to support single sign-out.

  7. (Optional) Check Allow the session to automatically sign out if you want to enable automatic sign-out.

  8. Select Add IdP.
    If this is the first IdP you have configured, the IdP is saved as your default IdP and a default routing rule is created.

Create a routing rule

  1. Open the Admin Console:

    1. In the top navigation bar, select app-launcher.jpg.

    2. Under Platform, select Admin Console.

  2. From the left navigation, select Settings > Manage IdPs.

  3. Select Routing rules > Add a routing rule.

  4. Enter the details for a routing rule:

    • Rule Name: Enter a name for the routing rule.

    • Select a routing type: Select the drop-down and then select Domain or Group.
      If you select Domain, your domain must be verified. See Create a domain.

    • If these are your domains/groups: Select the drop-down and then select domains or groups within your organization.

    • Then use this identity provider: Select the drop-down and then select IdP.

  5. Select Add.

  6. Select …​ (next to your new routing rule), then select Activate.

Manage service provider certificates

From Service providers, you can manage the service provider certificates used by Cisco Cloud Control.

c3-sp-certificates.jpg

Complete any of these tasks:

  • View the Redirect URI for your OIDC provider (1).

  • Download the metadata for your IdP (2).

  • Add or renew your service provider certificate (3).

  • View your certificate (4).

  • Download the certificate or its metadata (5).

Add or renew your service provider certificate

  1. Open the Admin Console:

    1. In the top navigation bar, select app-launcher.jpg.

    2. Under Platform, select Admin Console.

  2. From the left navigation, select Settings > Manage IdPs.

  3. Select Service providers.

  4. Select Add or renew certificate.

  5. Select one of these options:

    • Self-signed by Cisco: We recommend this choice. Let Cisco sign the certificate so you only need to renew it once every five years.

    • Signed by a public certificate authority: The customer IdP provides a signature in the metadata that is signed by a Public Root CA. This option is more secure but you’ll need to frequently update the metadata (unless your IdP vendor supports trust anchors).

  6. Select Save.

View audit log files

Whenever a user makes a system change, or an event takes place, Cisco Cloud Control creates a corresponding log file. The Audit Log page is where you can view the available log files and their specifics.

c3-audit-log.jpg

From here, you can complete these tasks:

  • Select the type of log files you want to view:

    • Identity and Access: Changes and events involving user authentication, as well as tenant and user management.

    • Admin Activity: Configuration and security changes and events.

  • Filter the table by entering a text string or selecting values from the drop-down lists.

  • Select a log file’s timestamp to view the details of the relevant system change.

  • Select Generate report to download the Audit Log table as a CSV file.

  • Select settings.jpg to configure the information that the Audit Log table displays.

View audit log file details

To view the details for a particular event or system change:

  1. Open the Admin Console:

    1. In the top navigation bar, select app-launcher.jpg.

    2. Under Platform Services, select Admin Console.

  2. From the left navigation, select Audit Log.

  3. For the specific event, select the corresponding log file’s timestamp in the Audit Log table. If a user does not have a display name configured in CUI, the system defaults to their email address.

    c3-audit-log-details.jpg
  4. From here, you can also:

    • Copy the tenant and tracking ID associated with this change or event.

    • Download this log file’s contents as a JSON file.