Cisco Secure Access Help

PDF

Cisco Secure Access Help

ThousandEyes Account Management in Experience Insights

Want to summarize with AI?

Log in

Provides reference information about ThousandEyes Account Management in Experience Insights in Cisco Secure Access, including ThousandEyes Organization and Default Account Group, Unified Collaboration Application, and Default Test Target. It summarizes the values, options, and related details presented in the topic.


Account Management in Experience Insights is a centralized interface to manage your ThousandEyes organization and account group, configure collaboration applications, update default test targets, view tenant and data storage details, and register ThousandEyes agents on endpoint devices.

Navigate to Experience Insights > Overview > Account Management.

ThousandEyes Organization and Default Account Group

The top of the ThousandEyes Account page displays your ThousandEyes organization and default account group. To delete the integration between Secure Access and ThousandEyes, click Remove Integration. Removing the integration means that endpoints registered to the account group will no longer be monitored within Experience Insights. Your endpoints will continue to be monitored directly in ThousandEyes.

Unified Collaboration Application

View your organization's current collaboration application. You chose the application during onboarding. To change it, click the pencil icon and select the most commonly used application within your organization from the options: Webex, Zoom, Microsoft Teams, or None.

Default Test Target

Synthetic tests allow you to identify performance issues with user journeys to destinations. You chose the default target during onboarding. To change the default test target that will apply to all endpoints, click the pencil icon and select from the options: Zero Trust Access, RAVPN, SWG Roaming Module, and Custom Target. For more information, see Edit Default Test Target.

Tenant and Data Storage Location

The section displays the location of your ThousandEyes tenant and data storage. To update data storage location, contact Thousand Eyes support via [support@thousandeyes.com](mailto:support@thousandeyes.com)

ThousandEyes Agent Registration Scripts

When you deployed Cisco Secure client to your endpoints, the ThousandEyes Endpoint Agent was installed. The ThousandEyes Endpoint Agent will register to your Secure Access org automatically once your endpoints have connected to VPN, ZTA, or Roaming module so that you can monitor their performance.

For endpoints that are not using one of those security connection methods, you must register the ThousandEyes Endpoint Agent manually by copying and pasting the command script on the endpoints. For more information, see Register ThousandEyes Agents

Account Group Integration

This is where you select multiple ThousandEyes account groups to integrate with Secure Access. You can select Default account group or Multiple account groups.

Default Account Group:

If you choose the Default Account Group during onboarding: Data is pulled only from the default group. No default tests are created in other account groups.

If you switch to the Default Account Group after onboarding: If you are switching from Multiple account groups to Default account group, then only tests for the default account group are enabled and tests for the multiple account groups are disabled. You can still edit the tests in ThousandEyes.

Multiple account groups: By selecting Multiple account groups, you will see all the ThousandEyes account groups and tests associated with the ThousandEyes user who did the initial integration with Secure Access. Additionally, you can see the unique registration scripts for each connected account group.

Changing user roles or account group settings may take up to 5-10 minutes to reflect the new changes.

Endpoint Registration

Automatic Registration: Enabling automatic registration will register all agents with the Default account group. If you change your mind, you can manually transfer the agents to other account groups in the ThousandEyes agent settings.

Manual Registration: You can create distinct deployment packages, each with a unique registration script for a specific account group.

To learn more about Automatic and Manual registration, see Step 5: ThousandEyes agent in Onboard Experience Insights.

Create Tests for New Account Groups

If the ThousandEyes admin who completed the Secure Access integration was added to a new account group in ThousandEyes and the two default tests were not generated- then a Create tests banner will appear on the Experience Insights Overview page.

The Create tests banner only appears if If the ThousandEyes admin who completed the Secure Access integration was added to a new account group in ThousandEyes and the two default tests were not generated.

Click Account Management > Create tests. The two default tests from the Default account group are copied to the new account group. This ensures that all your account groups have consistent monitoring and performance baselines from the start.

Click Create Tests to copy two default tests from the Default account group to the new account group.

Edit Default Test Target

When you onboarded Experience Insights, you chose a security method as a target for the default test based on what is used by most of your endpoints. If needed, you can change the target, including choosing a custom private or public application as the target.

Procedure

  1. Choose a target for the default test.


    By most of your endpoints. If needed, you can change the target, including choosing a custom private or public application as the target. Choose a target for the default test.
  2. If you choose Custom target, complete the onscreen fields.

    Note
    Heavy traffic may be sent to custom applications (per the onscreen note). For information on managing the traffic, see Estimate Peak Traffic to Custom Targets for Default Endpoint Tests.

    May be sent to custom applications (per the onscreen note). For information on managing the traffic, see Estimate Peak Traffic to Custom Targets for Default Endpoint Tests.

Register ThousandEyes Agents

When you set up Secure Access, you registered the ThousandEyes endpoint agent on all endpoints. Each time you add a new endpoint device in your organization, you must register the agent on the new device.

This process explains how to register ThousandEyes endpoint agents and begin reporting endpoint telemetry. You can enroll agents in different ways:

Procedure

  1. Automatic registration (recommended) – happens automatically when users connect using Cisco Secure Client.

  2. Manual registration – you enroll by running the registration script on the endpoint’s command line manually or via MDM.

What to do next

Result: The endpoint is now available in Experience Insights and will begin reporting data. To see the endpoint in the endpoint list, navigate to: Experience Insights > Endpoint list.

Note

The process for managing your ThousandEyes account is different than the process for managing your Secure Access account. In Secure Access, you choose whether to save logs for events and traffic for your account to the data center in the U.S. or Europe.


Automatic Registration of ThousandEyes Endpoint Agents

When Cisco Secure Client is installed and users start an active session with ZTA, URC, or VPN, the ThousandEyes endpoint agent automatically registers to the connected default ThousandEyes account group.

We recommend that you validate the workflow with a small test group before deploying the configuration more broadly.

Before you begin

To use automatic registration, ensure that the following requirements are met:

  • ThousandEyes endpoint agent is installed.

  • Integration completed between your Cisco Secure Access and your ThousandEyes account.

  • Cisco Secure Client is installed on the endpoint and is connected using at least one of the following features: Zero Trust Access (ZTA), Umbrella Roaming Client (URC), or VPN.

  • An active user session on the endpoint with at least one of the following features enabled: Zero Trust Access (ZTA), Umbrella Roaming Client (URC), and VPN.

Procedure

  1. Follow these steps to Download and Install Cisco Secure Client on the endpoint.

  2. The end user establishes a valid session using ZTA, URC, or VPN.

    The following happens automatically once the user establishes a valid session: The agent automatically requests the default ThousandEyes Account Group to confirm the Secure Access integration. Next, the system automatically verifies that the device is a legitimate asset belonging to the organization.

What to do next

Once the session is active, the ThousandEyes Endpoint Agent automatically validates local data collected from the device. The agent gathers device and organization identifiers from the active module.

Depending on the active connection type, the agent uses the following data sources:

  • VPN: The ThousandEyes endpoint agent uses the vpncli tool to identify the active VPN connection and extract the FQDN from the VPN profile folder. The agent uses this FQDN to resolve the Secure Access OrgID. VPN cluster FQDN identifiers can be 4 or 6 characters.

  • ZTA: The ThousandEyes endpoint agent reads cached configuration data from Windows or macOS and uses it to retrieve the ztna_device_id, user_id, and org_id.

    • Windows:

      C:\\ProgramData\\Cisco\\Cisco Secure Client\\ZTA\\enrollments\
    • macOS:

      /opt/cisco/secureclient/zta/enrollments
  • URC: The ThousandEyes endpoint agent reads cached configuration data from the local OrgInfo.json file on Windows or macOS and uses it to retrieve the organizationId and userId.

    • Windows:

      C:\\ProgramData\\Cisco\\Cisco Secure Client\\Umbrella\\OrgInfo.json
    • Mac:

      /opt/cisco/secureclient/umbrella/OrgInfo.json

What happens if automatic registration fails?

If automatic registration does not succeed on the first attempt, the agent retries every 10 minutes. The agent attempts registration in the following order: ZTA, Umbrella Roaming Client (URC), and VPN. The agent continues retrying until it validates a supported session and completes registration.


Manual Registration of ThousandEyes Endpoint Agents

If an endpoint will not connect via Zero Trust Access (ZTA), the Umbrella Roaming Client (URC), or a VPN, you can manually register the endpoint with Secure Access by running the registration script on the endpoint command line.

Procedure

  1. Navigate to Experience Insights > Account Management> Endpoint registration> Manual registration to copy your organization's registration scripts with your unique connection string.

    1. For Windows: you can manually register the agent using your connection string and execute the subsequent register command:
      "C:Program Files (x86)CiscoCisco Secure ClientThousandEyes Endpoint Agentcsc_te_agent" --register <connection string>
    2. For macOS: you can manually register the agent using your connection string and execute the subsequent register command:
      sudo /Applications/Cisco/Cisco Secure Client - ThousandEyes Endpoint Agent.app
  2. MDM Registration to use ThousandEyes Endpoint (Intune, Jamf, and other MDM Tools)

    1. Navigate to Deploy Cisco ThousandEyes Module via Microsoft Intune for steps to install Secure Client and register the ThousandEyes endpoint agent.