Provides an overview for Secure Access Sign On workflow in Cisco Secure Access.
Cisco Secure Access supports Security Assertion Markup Language (SAML) for the authentication of administrators to the Secure Access console. An administrator signs in to Secure Access from Cisco Security Cloud Sign On (SCSO). Cisco Duo Security or the IdP that you integrated with Security Cloud Sign On provides single sign-on (SSO) authentication of Secure Access administrators through SCSO. For more information, see Cisco Security Cloud Sign On Identity Provider Integration Guide.
To sign in to Secure Access, an administrator must have a Secure Access account and configure single sign-on authentication in SCSO. A Secure Access administrator signs in to SCSO authenticates to the IdP, and then automatically signs in to Secure Access.
Any changes made in your organization's SAML identity provider (IdP) are synced with Secure Access. If you update an account or change a password in the IdP, the changes are immediately reflected in your login. Only the username (email address) is stored in Secure Access. You must sign in to Secure Access with the same email address that you configured in your SCSO account. For more information, see Getting Started Guide for New Customers of Security Cloud Control.
You can only use SCSO to authenticate your login to Secure Access. The IdP that you set up in SCSO does not authorize an administrator's permissions to read, create, or update resources on Secure Access. A Secure Access role defines the permissions on the Secure Access account. For more information about user roles, see Manage Accounts.
Add Your Organization's Identity Provider in Security Cloud Sign On
You can add an SAML identity provider (IdP) in SCSO for Secure Access. Once you add an IdP and provision user accounts in Security Cloud Sign On, administrators in your organization are not required to complete the Sign Up Now steps. For more information, see Cisco Security Cloud Sign On Identity Provider Integration Guide.
Add Administrators to Secure Access
A Cisco Secure Access administrator can add additional administrators to their Secure Access organization (Org) and assign a role to the new administrator's account. To establish an account, provide the email address of the new administrator and choose the Secure Access role for the account. For more information, see Manage Accounts.
When an administrator provisions a Secure Access account, an email is sent from Secure Access to the new administrator with the instructions to use SSO authentication to sign in to their Secure Access Org.
The new administrator has a Secure Access account and must create an SSO account through the Security Cloud Sign On (SCSO) portal. The email address in the Secure Access account must match the email address entered to create the SCSO account. The SCSO portal manages SSO authentication through an integrated IdP.