De-identification helps protect user privacy by hiding source identities in Cisco Secure Access reports and activity data. When you enable de-identification, you can investigate security activity without unnecessarily exposing personally identifiable source details.
Some regions or organizations require restrictions to hide the sources of users making internet requests. To comply with these restrictions, you can hide source names when generating a report by enabling de-identification for a user. When enabled, a hash unique to that source replaces the source (identity) name.
You cannot enable or disable de-identification on your own account. At least two administrators are required to use this feature and any administrator can turn it on or off for another account.
Source Types
The following source types are de-identified in Secure Access:
-
AD usernames
-
computer/hostnames
-
internal IP addresses
-
Chromebook identities
-
mobile identities
-
GSuite users and groups
-
SAML-obtained users and groups
-
internal IP addresses
Limitations
Because the purpose of de-identification is to remove the visibility of the identity names for the user, de-identification includes the following limitations:
-
The scheduling and exporting of reports is unavailable.
-
The Application Discovery report is unavailable.
-
You cannot search by an active directory username, roaming computer name, or internal IP name.
However, you can click the hash name to view the source's (identity) details.
-
There is no access to API key management and creation.
-
There is no access to S3 Log Management (self-managed or Cisco-managed).
-
Full administrators with the De-identification option enabled will see encoded information in all reports except for the Data Loss Prevention Report.