Cisco Cloud Control Administration

 
Updated August 6, 2026
PDF
Is this helpful? Feedback

Manage users

In Users, you can view and manage the users who have access to Cisco Cloud Control and connected products.

note.svg

If you are using an external Identity Provider (IdP) and notice stale administrator entries, those entries are not a security vulnerability. This behavior occurs because Cisco Cloud Control does not currently integrate with your IdP lifecycle management feature. Cisco defers to your IdP as the authoritative source for user access control.


Use these tasks to manage users:

users.jpg

Add a user

Follow these steps to add a user.

  1. Select app-launcher.jpg and choose Admin Console.

    By default, Users is displayed.

  2. Select Manage users > Add user.

  3. In Add user, complete these steps:

    1. Enter the email address of the user you are adding. Then select Next.

    2. (Optional) Enter the first and last name of the user. Then select Next.

    3. (Optional) Assign one of these admin roles to the new user:

      • Tenant Full Admin: Can configure and manage all tenant-level settings.

      • Tenant Read-only Admin: Can view all tenant-level settings, but cannot change them.

      • Integration Admin: Can manage cross-product and third-party integrations in Cisco Cloud Control, but does not have platform administration rights.

    4. Select Next.

    5. In Summary, confirm that the information you entered for the new user is correct. Then select Add user.

  4. To grant this user access to Nexus Dashboard, complete the steps in Configure Nexus Dashboard access.

Search for users

Follow these steps to search for and view users.

  1. Select app-launcher.jpg and choose Admin Console.

  2. Use Search to find a user by name or email address.

  3. Select Products and then select relevant accessible products to filter the results.

  4. Select a user name to view the user details.

Manage a user

Follow these steps to manage a user.

  1. Select app-launcher.jpg and choose Admin Console.

  2. Select the display name to view the user details.

    You can also select ellipsis.jpg to open a menu with the same options.

  3. Select Actions, and then select one of these options:

    • Edit profile: Update the user profile information.

    • Edit role assignments: Change the role assignments for that user.

Customize the displayed information on Users

Follow these steps to customize the information displayed on Users.

  1. Select app-launcher.jpg and choose Admin Console.

  2. Select settings.jpg to customize the table density and column settings.

Configure Nexus Dashboard access

Complete this procedure to configure Nexus Dashboard access for a Cisco Cloud Control user.

  1. Select app-launcher.jpg and choose Admin Console.

  2. Select Manage users > Manage Nexus Dashboard access.

    To change the settings for a user who already has access to Nexus Dashboard, select ellipsis.jpg > Manage assignment. Then proceed to the role assignment step.

  3. Select Assign.

  4. In Assign user, complete these steps:

    1. Select a Cisco Cloud Control user, then select Next.

    2. Check the role that you want to assign to the user:

      • Fabric Administrator: Has full fabric management privileges.

      • Designer: Can modify configurations, but cannot deploy these changes to network fabrics.

      • Approver: Can approve or deny submitted configuration changes when change control is enabled.

      • Observer: Has read-only access.

      • Support Engineer: Performs support tasks. Can also deploy or revert approved changes under change control, but cannot modify configurations.

    3. Indicate why you are assigning an access role to the user. Then select Next.

    4. Confirm that the settings you entered are correct. Then select Save.

Manage tenants

In Tenants, you can view all product tenants that are accessible from Cisco Cloud Control. Tenants displays both grouped and ungrouped tenants.

tenants.jpg

Use these topics to manage tenants and troubleshoot tenant-switching issues:

Switch tenants

The Cisco Cloud Control tenant switcher allows you to navigate between different product tenants, such as Cisco Cloud Security, Intersight, and Meraki.

When you switch tenants, consider these factors:

  • Permissions and roles: Access is governed by your assigned permissions. You will only see and be able to switch to tenants for which you have the appropriate access.

  • Session security: For security, your session has a defined timeout. If your token expires, you may be required to re-authenticate regardless of your previous activity.

  • Linked products: The feature is optimized for products linked to Cisco Cloud Control. If you switch to a tenant that is not associated with your current product, you may be redirected to the main Cisco Cloud Control dashboard.

  • Cross-product authentication: When switching tenants, Cisco Cloud Control may open a pop-up window to handle authentication of the cross-launch. Ensure your browser is configured to allow pop-ups from the Cisco Cloud Control domain.

Follow these steps to switch tenants.

  1. From the top navigation bar, select the current tenant name.

  2. Select an available tenant.

    If you move between linked tenants or products within the same realm, Cisco Cloud Control performs a background token exchange. You are then transitioned to the new environment without needing to re-enter your credentials.

Troubleshoot tenant switching

Use these possible solutions to troubleshoot tenant-switching issues:

  • Switch takes time: A brief loading period is normal while the system verifies your credentials across products.

  • Tenant does not appear: Ask your administrator to verify that your user account is provisioned and linked to the product.

  • Switch fails or hangs: Check your browser pop-up settings and ensure that pop-ups are allowed for Cisco Cloud Control.

View tenants

Follow these steps to view tenants.

  1. Select app-launcher.jpg and choose Admin Console.

    By default, Users is displayed.

  2. Select Tenants.

  3. Find a tenant:

    • Search for a tenant by name.

    • Filter the table by products associated with a tenant.

    The tenant list is filtered based on your selections.

  4. Review the tenant information:

    • Name

    • Email address

    • Associated products

      note.svg

      If a number is displayed next to a product name, this indicates that the tenant has access to additional products. To view these products, place your cursor over this number or select > under the tenant Name.


    • Type: Indicates whether a tenant has been grouped.

Create a tenant group

You can only group tenants for which you have the Tenant Full Admin role. Users configured with the Tenant Read-only Admin role can view all tenant-level settings, but cannot change them.

Follow these steps to create a tenant group.

  1. Select app-launcher.jpg and choose Admin Console.

    By default, Users is displayed.

  2. Select Tenants.

  3. Select Group tenants.

    The system displays the products for which you have full administrative access.

  4. Select the tenants you want to include in the group, choosing one tenant for each product.

    note.svg

    When adding a tenant to a group for the first time, you may be prompted to sign in to each individual tenant. This sign-in step authenticates your identity across different product environments and obtains the necessary tokens.


  5. Enter a name for the group.

  6. Select the check box to acknowledge that users who sign in to any tenant in the group can access all other grouped tenants.

  7. Select Save.

    note.svg

    When tenants are grouped, Cisco Cloud Control uses one tenant ID as the primary identifier. Cisco Cloud Control does not automatically delete the IDs of the other tenants that joined the group.


Add a tenant to a group

You can only group tenants for which you have the Tenant Full Admin role. Users configured with the Tenant Read-only Admin role can view all tenant-level settings, but cannot change them.

Follow these steps to add a tenant to an existing group.

  1. Select app-launcher.jpg and choose Admin Console.

    By default, Users is displayed.

  2. Select Tenants.

  3. For the tenant you want to add to a group, select ellipsis.jpg.

  4. Add this tenant to an existing group.

    note.svg

    • When adding a tenant to a group for the first time, you may be prompted to sign in. This sign-in step authenticates your identity across different product environments.

    • When tenants are grouped, Cisco Cloud Control uses one tenant ID as the primary identifier. Cisco Cloud Control does not automatically delete the IDs of the other tenants that joined the group.


Rename a tenant group

Follow these steps to rename a tenant group.

  1. Select app-launcher.jpg and choose Admin Console.

    By default, Users is displayed.

  2. Select Tenants.

  3. For the tenant group you want to rename, select the pencil icon.

  4. Rename the tenant group.

Set up SSO

Complete these setup tasks to configure single sign-on (SSO) for Cisco Cloud Control users.

Create a domain

Follow these steps to create a domain.

  1. Select app-launcher.jpg and choose Admin Console.

    By default, Users is displayed.

  2. Select Domains.

  3. Select Settings > Manage domains.

  4. Select Add a domain.

  5. Enter your domain or subdomain name and select Next.

  6. Copy the verification token into your DNS TXT record.

    • If your DNS host supports only one TXT record, add the token on a separate line.

    • If your DNS host supports multiple records, add your token on a single line in a separate TXT record.

  7. Choose who adds the DNS TXT record:

    • If you can add the DNS TXT record, add it to your DNS server.

    • If another administrator configures your DNS server, send the DNS TXT record to that administrator.

  8. Select Add domain.

    Your domain appears in your list of domains with the status Pending. When it’s verified, the status changes to Verified.

    After the domain is verified, the TXT record is no longer required, and you can remove the verification token from your DNS server.

    If verification fails, the error is cached by your DNS server. Your DNS server clears the cache after the time specified in the Time To Live (TTL) setting. You must wait to try again after the DNS server clears the cache. You can add the verification token again and request verification for the domain.

Configure an IdP using SAML

SAML provides a framework for IdPs and service providers to communicate with each other for federated identity and SSO. You can set up a SAML IdP by manually entering IdP metadata or uploading metadata to the Admin Console.

Follow these steps to configure an IdP using SAML.

  1. Select app-launcher.jpg and choose Admin Console.

  2. Select Domains.

  3. Select Settings > Manage IdPs.

  4. Select Add an IdP.

  5. In Add an Identity Provider, select SAML as your IdP and select Next.

  6. Select one of these methods to connect your IdP:

    • Fill out configuration form: Manually enter your IdP metadata. Then proceed to Step 7.

    • Upload your IdP’s metadata: Upload an XML file containing your IdP metadata. Then proceed to Step 8.

  7. If you selected Fill out configuration form:

    1. Enter your Entity ID (SAML Identifier).

    2. Enter your Single sign-on URL.

    3. Select a binding method: HTTP-Post or HTTP-Redirect.

    4. (Optional) Enter your Single sign-out URL.

    5. (Optional) Select a binding method: HTTP-Post or HTTP-Redirect.

    6. Check the check box to enable Sign SAML request.

      Select this check box if your IdP requires authentication requests to be signed.

    7. Select a NameID format.

      You can select one of these options:

      • urn:oasis:names:tc:SAML1.1:nameid-format:emailAddress (default): This format uses your email address as your NameID.

      • urn:oasis:names:tc:SAML2.0:nameid-format:transient: This format generates a temporary, one-time NameID for each authentication.

      • urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified: This format indicates that no specific NameID format is requested, allowing your IdP to determine or use an appropriate format.

    8. Upload your IdP certificate files.

      If your IdP uses multiple signing certificates, you can upload up to two IdP certificate files in .pem or .cer format.

    9. Select Next.

  8. If you selected Upload your IdP’s metadata:

    1. Upload an XML file containing your IdP metadata.

      When uploading the metadata file, there are two ways to validate the metadata from the customer IdP:

      • Not signed, self-signed, or private CA-signed IdP metadata file: Your IdP provides a self-signed private CA or doesn’t provide a signature for its metadata. This option is less secure.

      • Signed by a public certificate authority: Your IdP provides a signature in the metadata that is signed by a Public Root CA.

      warn.svg

      Only upload metadata generated by your IdP. Uploading the wrong metadata file will cause SSO failure and might lock all administrators out of the account.


    2. Select Next.

  9. (Optional) Configure SAML attributes and settings.

    By default, the SAML IdP uses the uid attribute to identify the user when it sends authentication data to Cisco Cloud Control. If the IdP supports other NameID configurations, you can modify this configuration.

  10. Select Add IdP.

    If this is the first IdP you have configured, the IdP is saved as your default IdP, and a default routing rule is created.

Configure an IdP using OpenID Connect

Use OpenID Connect (OIDC) to set up SSO using your identity provider. OIDC is built on the OAuth 2.0 framework and supports secure authentication through encrypted tokens and built-in certificate validation.

note.svg

When you set up OpenID Connect with Entra ID or an IdP where the email is not a permanent identifier, we recommend that you use the externalId linking attribute to map to a unique identifier. For Entra ID, we suggest mapping OIDC to externalId. If the email you enter does not match the linking attribute, you are prompted to verify your identity or create a new user with the correct email address.


Follow these steps to configure an IdP using OpenID Connect.

  1. Select app-launcher.jpg and choose Admin Console.

  2. Select Domains.

  3. Select Settings > Manage IdPs.

  4. Select Add an IdP.

  5. In Add an Identity Provider, select OpenID Connect as your IdP and select Next.

  6. Enter your IdP information.

    1. Enter your IdP Name.

    2. Enter your Client ID. This is the unique ID that identifies you and your IdP.

    3. Enter your Client Secret. This is the password that you and your IdP know.

    4. Select the scopes you want to associate with your IdP.

      OpenID and Email are selected by default.

  7. Select one of these methods to add endpoints:

    • Use the discovery URL: Enter the discovery URL for your IdP.

      This URL automatically populates the necessary endpoints for OIDC single logout (SLO).

    • Manually add all endpoint information: Select this option if your IdP does not support discovery URLs. Provide these details:

      • Issuers (comma-separated): Enter one or more issuer URIs, separated by commas.

      • Authorization endpoint: URL to start the authorization flow.

      • Token endpoint: URL to retrieve access tokens.

      • (Optional) JWKS URI: URL to retrieve the JSON Web Key Set.

      • (Optional) Userinfo endpoint: URL to retrieve user profile information.

      • (Optional) End session endpoint: URL to support single sign-out.

  8. (Optional) Check Allow the session to automatically sign out if you want to enable automatic sign-out.

  9. Select Add IdP.

    If this is the first IdP you have configured, the IdP is saved as your default IdP, and a default routing rule is created.

Create a routing rule

Follow these steps to create a routing rule.

  1. Select app-launcher.jpg and choose Admin Console.

  2. Select Domains.

  3. Select Settings > Manage IdPs.

  4. Select Routing rules > Add a routing rule.

  5. Provide these details for a routing rule:

    • Rule Name: Enter a name for the routing rule.

    • Select a routing type: Select Domain or Group.

      If you select Domain, your domain must be verified. For more information, refer to Create a domain.

    • If these are your domains/groups: Select domains or groups within your organization.

    • Then use this identity provider: Select IdP.

  6. Select Add.

  7. Select …​ (next to your new routing rule), then select Activate.

Service provider certificates

From Service providers, you can manage the service provider certificates used by Cisco Cloud Control.

c3-sp-certificates.jpg

Complete any of these tasks to manage service provider certificates:

note.svg

The numbered callouts identify where in Service providers you can complete these tasks.


Add or renew your service provider certificate

Follow these steps to add or renew your service provider certificate.

  1. Select app-launcher.jpg and choose Admin Console.

  2. Select Domains.

  3. Select Settings > Manage IdPs.

  4. Select Service providers.

  5. Select Add or renew certificate.

  6. Select one of these options:

    • Self-signed by Cisco: We recommend this choice. Let Cisco sign the certificate so you only need to renew it once every five years.

    • Signed by a public certificate authority: The customer IdP provides a signature in the metadata that is signed by a Public Root CA. This option is more secure, but you need to update the metadata frequently unless your IdP vendor supports trust anchors.

  7. Select Save.

Audit logs

Cisco Cloud Control creates a log file whenever a user makes a system change or an event takes place. Use Audit Log to view and export available log files.

c3-audit-log.jpg

Use these tasks to work with audit logs:

View audit log files

Follow these steps to view audit log files for event or system changes.

  1. Select app-launcher.jpg and choose Admin Console.

    By default, Users is displayed.

  2. Select Audit Log.

  3. Select the type of log files that you want to view:

    • Identity and Access: Changes and events involving user authentication, tenant management, and user management.

    • Admin Activity: Configuration and security changes and events.

  4. Find the audit log:

    • In Search, enter a text string.

    • Select Filters and select values from the available drop-down lists.

    • (Optional) Select settings.jpg to customize the table density and displayed columns.

    The audit log information is filtered based on your selections.

  5. Select the date and time of a log file to view more details about it.

    If a user does not have a display name configured in CUI, the system defaults to their email address.

    c3-audit-log-details.jpg

    You can also:

    • Copy the Tenant ID and Tracking ID associated with this change or event.

    • Select Copy to copy and paste the contents of this log file to a local file.

Generate an audit report

Follow these steps to generate an audit report.

  1. Select app-launcher.jpg and choose Admin Console.

  2. Select Audit Log.

    Audit Log displays log file information for either Identity and Access or Admin Activity.

  3. Select Generate report to download the audit log data as a CSV file.