Cisco Secure Access Help

PDF

Cisco Secure Access Help

Secure Access Single Sign-On Authentication

Want to summarize with AI?

Log in

Provides an overview for Secure Access Sign On workflow in Cisco Secure Access.


Cisco Secure Access supports Security Assertion Markup Language (SAML) for the authentication of administrators to the Secure Access console. An administrator signs in to Secure Access from Cisco Security Cloud Sign On (SCSO). Cisco Duo Security or the IdP that you integrated with Security Cloud Sign On provides single sign-on (SSO) authentication of Secure Access administrators through SCSO. For more information, see Cisco Security Cloud Sign On Identity Provider Integration Guide.

To sign in to Secure Access, an administrator must have a Secure Access account and configure single sign-on authentication in SCSO. A Secure Access administrator signs in to SCSO authenticates to the IdP, and then automatically signs in to Secure Access.

Any changes made in your organization's SAML identity provider (IdP) are synced with Secure Access. If you update an account or change a password in the IdP, the changes are immediately reflected in your login. Only the username (email address) is stored in Secure Access. You must sign in to Secure Access with the same email address that you configured in your SCSO account. For more information, see Getting Started Guide for New Customers of Security Cloud Control.

Note
You can only use SCSO to authenticate your login to Secure Access. The IdP that you set up in SCSO does not authorize an administrator's permissions to read, create, or update resources on Secure Access. A Secure Access role defines the permissions on the Secure Access account. For more information about user roles, see Manage Accounts.

Add Your Organization's Identity Provider in Security Cloud Sign On

You can add an SAML identity provider (IdP) in SCSO for Secure Access. Once you add an IdP and provision user accounts in Security Cloud Sign On, administrators in your organization are not required to complete the Sign Up Now steps. For more information, see Cisco Security Cloud Sign On Identity Provider Integration Guide.

Add Administrators to Secure Access

A Cisco Secure Access administrator can add additional administrators to their Secure Access organization (Org) and assign a role to the new administrator's account. To establish an account, provide the email address of the new administrator and choose the Secure Access role for the account. For more information, see Manage Accounts.

When an administrator provisions a Secure Access account, an email is sent from Secure Access to the new administrator with the instructions to use SSO authentication to sign in to their Secure Access Org.

The new administrator has a Secure Access account and must create an SSO account through the Security Cloud Sign On (SCSO) portal. The email address in the Secure Access account must match the email address entered to create the SCSO account. The SCSO portal manages SSO authentication through an integrated IdP.


Sign into Secure Access with Security Cloud Sign On

Cisco Secure Access supports Security Assertion Markup Language (SAML) for authenticating administrators to the Secure Access console. Administrators sign in to Secure Access using their Cisco Security Cloud Sign On (SCSO). Cisco Duo Security provides single sign-on (SSO) authentication of Secure Access administrators through SCSO.

Sign in to Secure Access through the Cisco Security Cloud Sign On (SCSO) portal. If you do not have an SCSO account, follow the steps to Configure Single Sign-On Authentication.

Before you begin

  • A valid Secure Access account. For more information, see Manage Accounts.

Procedure

  1. Navigate to your Secure Access organization at https://dashboard.sse.cisco.com/org/<org_number>.

    Secure Access uses single sign-on authentication through Security Cloud Sign On.

  2. In Security Cloud Sign On, enter the email address where you received the invitation to join a Secure Access organization.

    Your Secure Access account and the SCSO account must use the same email address.


    Login screen to join the Cisco Secure Access organization using Security Cloud Sign On
  3. If you have a Security Cloud Sign On account, click Continue to sign in to Secure Access.


Configure Single Sign-On Authentication

Configure SSO authentication for Secure Access through Cisco Security Cloud Sign On (SCSO).

Cisco Secure Access supports Security Assertion Markup Language (SAML) for the authentication of administrators to the Secure Access console. An administrator signs in to Secure Access using Cisco Security Cloud Sign On (SCSO). Cisco Duo Security provides single sign-on (SSO) authentication of Secure Access administrators through SCSO.

Before you begin

  • A valid Secure Access account. For more information, see Manage Accounts.

Procedure

  1. Navigate to your Secure Access organization at https://dashboard.sse.cisco.com/org/<org_number>.

    Secure Access uses single sign-on authentication through Security Cloud Sign On.

    Login page to join the Cisco Secure Access organization using Security Cloud Sign On.
  2. In Security Cloud Sign On, enter the email address where you received the invitation to join a Secure Access organization.

    Your Secure Access account and the SCSO account must use the same email address.

  3. Click Sign up now and create an SCSO account.

    Secure Access sends you an invitation to create an SCSO account.

  4. Once you receive an email from Secure Access inviting you to create an SCSO account, click the link in the email and follow the instructions to set up your SCSO account with your IdP.

  5. Follow the steps to sign in to your Secure Access organization.


Troubleshoot Single Sign On Authentication

If you are unable to sign in to Secure Access through Cisco Security Cloud Sign On, contact Support.