Cisco Secure Access Help

PDF

Cisco Secure Access Help

Integrate Cisco Identity Intelligence with Secure Access

Want to summarize with AI?

Log in

Integrate Cisco Identity Intelligence into Secure Access to address issues with user identity fragmentation that can complidate user trust assessment, consistent policy enforcement, and breach detection.


Cisco Identity Intelligence is an AI-powered solution that addresses user identity fragmentation. Fragmentation occurs when an organization relies on multiple identity sources, including:

  • Traditional Identity Providers (IdPs), such as Entra ID (formerly Azure AD), Duo, and Okta.

  • Non-traditional sources, such as Github, Google, and Salesforce.

  • HR systems, such as Workday.

Fragmented identities complicate user trust assessment, consistent policy enforcement, and breach detection. Identity Intelligence continuously monitors user identities, behaviors, and access patterns to detect anomalies and enforce adaptive security policies, mitigating unauthorized access risks.

Identity Intelligence is available as a shared Cisco service through Cisco Security Cloud Control. Security Cloud Control is a platform for managing your Cisco security products. By connecting your IdPs to Security Cloud Control, a unified identity context becomes available to Cisco products such as Secure Access, Cisco XDR, and Cisco Duo. This approach streamlines identity management and ensures consistent identity context across multiple services.

The Cisco Identity Intelligence integration, accessible via Security Cloud Control, is included at no additional charge with any Secure Access subscription. This does not include access to the standalone Cisco Identity Intelligence dashboard. For more information, see Cisco Identity Intelligence.


Configure a New Duo and Cisco Identity Intelligence Tenant with Secure Access

Your Secure Access subscription includes a limited license to Duo and Cisco Identity Intelligence at no additional charge. This limited access to Cisco Identity Intelligence provides the essential identity visibility and security features required for your deployment, though it may not include the full suite of advanced features available in standalone Duo or Cisco Identity Intelligence premium subscriptions. See, Duo Limited Usage Details for more information.

This document describes how to claim and activate your Secure Access subscription with a new Duo and Cisco Identity Intelligence tenant.

Before you begin

Confirm the following before using this procedure.

  • You are not already a Duo customer. If you are an existing Duo customer, follow this procedure instead: Configure an Existing Duo and Cisco Identity Intelligence Tenant with Secure Access.

  • Claim code: You have the welcome email with the subscription claim code automatically sent to the Provisioning Contact specified when your organization purchased Secure Access. If you do not have the email or claim code, contact Cisco Technical Assistance. For more information, see Overview of Subscription Process in Cisco Security Cloud Control documentation.

  • Security Cloud Control Administrator Group: Within Security Cloud Control, the administrator must be a member of the All Products Administrator group. To add an administrator to Security Cloud Control and assign them to a group, navigate to Platform Management > Access Management > Administrator Access in the Security Cloud Control dashboard.

At the end of this process, you will have four integrated accounts: Security Cloud Control (SCC), Duo, Secure Access, and Cisco Identity Intelligence (CII).

Procedure

  1. In Security Cloud Control, enter your Secure Access Subscription Code. For a detailed procedure, see Claim a Subscription in Security Cloud Control documentation.

    The Scc Claim 01 interface.
    Secure Access will begin the activation process within Security Cloud Control. Secure Access will be listed under Products in the left navigation menu.
  2. Next, activate Duo and Cisco Identity Intelligence. Click Action required > select Create new account > click Activate. This may take a minute to activate.


    Click the Action required button to link to your Cisco Duo and Identity Intelligence accounts.
  3. The SCC admin who initiated the activation process (received the initial claim code), gets an email from Duo to complete registration.


    The SCC admin gets an email to complete registration for Duo.
  4. Click Complete Registration and follow the steps to setup your first Duo Admin account.

  5. Integrate Duo with Cisco Identity Intelligence. For a detailed procedure, see Duo Identity Security with Cisco Identity Intelligence.

  6. In Duo’s dashboard, click Monitoring > Cisco Identity Intelligence > Connect to Cisco Identity Intelligence.


    Click Connect to Cisco Identity Intelligence to integrate with Duo, Security Cloud Control, and Secure Access.

    A success notification appears when Cisco Identity Intelligence is connected.


    A success notification appears when you created the Cisco Identity Intelligence account.

What to do next

Add the same Identity Providers (IdPs) to both Cisco Identity Intelligence (via Security Cloud Control) and Secure Access. For more information, see After Integrating Cisco Identity Intelligence.

For more information on the Systems Logs feature, see Systems Logs.


Configure an Existing Duo and Cisco Identity Intelligence Tenant with Secure Access

This procedure is specific to existing Duo accounts and does not use the restricted Duo license provided with new Secure Access subscriptions. If you are performing a first-time setup for a new Duo account and CII tenant follow these instructions here: Configure a New Duo and Cisco Identity Intelligence Tenant with Secure Access.

Before you begin

Confirm the following before using this procedure.

  • You are an existing Duo Advantage or Premier customer with an existing Cisco Identity Intelligence tenant in Cisco Security Cloud Control. For more information, see Duo Identity Security with Cisco Identity Intelligence.

    If you are a Duo Essentials customer, you are entitled to a Cisco Identity Intelligence tenant with a Duo limited license. For more information see, Duo Limited Usage Details.

  • Claim code: You have the welcome email with the subscription claim code automatically sent to the Provisioning Contact specified when your organization purchased Secure Access. If you do not have the email or claim code, contact Cisco Technical Assistance. For more information, see Overview of Subscription Process in Cisco Security Cloud Control documentation.

  • Duo Administrator with Owner Role: Ensure this Duo Owner account holder is also an administrator in Security Cloud Control. Log in to the Duo dashboard, then navigate to Users > Manage > Administrators.

  • Verify Security Cloud Control Administrator Group: Within Security Cloud Control, the Duo Owner account holder must be a member of the All Products Administrator group. To add an administrator to Security Cloud Control and assign them to a group, navigate to Platform Management > Access Management > Administrator Access in the Security Cloud Control dashboard.

    The Duo owner’s email must match the Security Cloud Control’s Administrator email and in the All Products Administrator group.

Procedure

  1. In Security Cloud Control, navigate to Platform management > Administrator Access. If the Duo owner is not in this list, click + Invite to create an account for the Duo owner.



  2. Click Admin Groups > All Products Administrator. If the Duo owner is not listed here, click Add users to add the Duo owner to the list.


    If the Duo owner is not listed in the All Products Administrator page, click Add users to add the Duo owner.
  3. In Security Cloud Control, enter your Secure Access subscription claim code. For a detailed procedure, see Claim a Subscription in Security Cloud Control documentation.

    The Scc Claim 01 interface.
    Secure Access will begin the activation process within Security Cloud Control.
  4. The Security Cloud Control Overview dashboard will update the Product and service activation status menu when your Duo and Cisco Identity Intelligence entitlements are available. Click Action required to link to your existing Cisco Duo and Identity Intelligence accounts.


    Click the Action required button to link to your existing Cisco Duo and Identity Intelligence accounts.
  5. Select Connect an existing account.


    Select Connect an existing account and select the Duo Owner for the Initial administrator.
  6. From the Initial administrator drop-down, choose the Security Cloud Control administrator with the same email address as the Duo Owner.

  7. Click Activate.

    The Security Cloud Control Overview dashboard will update to show that Cisco Identity Intelligence is being activated. Security Cloud Control will send an authorization email to the initial administrator.
  8. Instruct the Duo Owner to follow these steps to connect their Security Cloud Control and Duo accounts:

    1. Click the Connect accounts link in the email. They will be directed to log in to Duo.

      The Duo Owner recieves an email to connect their Duo account with Security Cloud Control.
    2. At the top of the Duo dashboard, a banner will appear. Click Connect Duo to Security Cloud Control.

      Click the banner that says, Connect Duo to Security Cloud Control.
    3. In the pop-up window, click Authorize.

      To connect your existing Duo account to Security Cloud Control, click the Authorize button.

    The Duo owner will receive an email that Duo, Cisco Identity Intelligence, and Security Cloud Control accounts are connected.

    Once your Cisco Identity Intelligence instance is successfully activated, a Cisco Identity Intelligence menu item will become available under Platform services in the Security Cloud Control's left navigation menu.

    The Scc Claim 04 interface.

    To integrate Duo with Cisco Identity Intelligence, follow steps 5 and 6 in Configure a New Duo and Cisco Identity Intelligence Tenant with Secure Access.

What to do next

Add the same Identity Providers (IdPs) to both Cisco Identity Intelligence (via Security Cloud Control) and Secure Access. For more information, see After Integrating Cisco Identity Intelligence.

For more information on Systems Logs, see Systems Logs.

Integrate your Duo directory with Secure Access. Follow these steps, Duo Directory Integration with Secure Access.


After Integrating Cisco Identity Intelligence

To maximize the effectiveness of Cisco Identity Intelligence (CII), we recommend integrating all available third-party products and IdPs— especially recommend integrating Duo Directory. For more information, see Duo Directory Integration with Secure Access.

By aggregating these disparate identity and data points alongside your primary identity provider, Cisco Identity Intelligence generates a more accurate and comprehensive trust score for every user.

Procedure

  1. To add IdPs in the Secure Access dashboard:

    1. In Secure Access, navigate to Connect > Essentials > Users, Groups, and Endpoint Devices.
    2. Select Configuration management.
    3. Choose Integrate directories and follow the detailed instructions in Add a Cloud Identity Provider.
  2. To add IdPs to Cisco Identity Intelligence in the Security Cloud Control dashboard:

    1. In Security Cloud Control, navigate to Platform Services > Identity Intelligence > Integrations
    2. Select your provider and click Add Integration.
      The Cii Integrations interface.
    3. Follow the instructions for specific integrations in Configuring Integrations in the Cisco Identity Intelligence knowledge base (formerly Oort).

After successful integration and once the same IdPs are added to both products, user trust levels will become visible in Secure Access.

Note

It can take up to 24 hours for user trust levels to update in Secure Access after the initial integration.

What to do next

After successfully integrating Secure Access with Identity Intelligence via Security Cloud Control, you can verify the integration and explore user trust levels:

For comprehensive information on user trust levels and their calculation, refer to the User Trust Level documentation in the Cisco Identity Intelligence knowledge base (formerly Oort).


Duo Directory Integration with Secure Access

We highly recommend integrating your Duo directory as an identity provider with Secure Access. This integration ensures users can securely access both private and internet applications while strengthening the accuracy of your user’s trust level. If you are interested in integrating other IdPs, see Configure Identity Providers.

Before you begin

Procedure

  1. In the Security Cloud Control dashboard > click Secure Access in the left navigation bar. For a detailed procedure to add Duo IdP directory, see Add the Duo IdP directory to Secure Access.

    Once Duo Directory Integration is complete, you will see the user’s information added to the Users, Groups, and Endpoint Devices page.
  2. Next, you need to integrate a SAML 2.0 or OIDC SSO provider.

    1. See Configure Integrations with SAML Identity Providers for steps on how to configure Duo for SAML.
    2. See Configure Integrations with OIDC Identity Providers for steps on how to configure Duo for OpenID Connect.
    May take up to 24 hours for these trust levels to be calculated and updated.

Integrate Cisco SASE with Meraki SD-WAN

Cisco SASE (Secure Access Service Edge) securely connects users, devices, and applications from anywhere with minimal effort. It combines networking, security, and visibility in a single, easy-to-manage solution. This enables a flexible hybrid work experience that boosts productivity and protects the network.

Cisco SASE supports 1:1 integration between each Secure Access organization and Meraki organization. Secure Access Multi-organization is supported but each Secure Access child organization can connect with one and only one Meraki organization. For more information about this supported integration, see the Cisco Secure Access integration - Design Best Practices and Meraki IPSec to autoVPN Secure Access Manual Migration Guide.

Cisco SASE does not support integration between Meraki SD-WAN and Secure Access DNS.

The Cisco SASE integration established between Meraki SD-WAN and Secure Access is available with no special licensing requirements. This allows the following to ensure smooth onboarding:

  • Secure Access organizations created prior to July 2, 2025 may need a flag enabled in order to access this functionality. If your Secure Access org was created after July 2, 2025, you will have this flag. If you encounter an error when onboarding via Meraki, contact Cisco Secure Access Support.

  • Secure Access organizations must be managed with Security Cloud Control (SCC). If your Secure Access org was created after March 31, 2025, you have this funcoitnality. If you do not have your Secure Access org tied to an SCC enterprise, onboarding via Meraki causes an error. See About Cisco Security Cloud Control or contact Cisco Secure Access Support, your Account team, or CX contact for assistance integrating Secure Access with SCC.

  • For more information, see Cisco SASE: Getting Started Guide in Meraki documentation.

Before you begin

Before you begin, review the following prerequisites.

  • A Cisco Meraki MX/Z4 device (running Security and SD-WAN (MX,Z) version 19.1+ firmware). For more information, see Meraki Security and SD-WAN (MX,Z) Features Directory.

  • A valid Meraki SD-WAN license or subscription.

  • A valid Cisco Secure Access subscription.

  • An integration established between Secure Access and Security Cloud Control. For more information, see About Cisco Security Cloud Control.

  • A Cisco SASE integration established between Cloud Managed Meraki SD-WAN and Secure Access. For more information, see SASE in Meraki Integrations documentation.

Procedure

  1. In Secure Access, navigate to Admin > API Keys.

  2. Click Add at the top right.

  3. Configure the Add New API Key menu:

    The Sase Meraki 01 interface.
    1. Enter an API Key Name
    2. Enter a Description (optional).
    3. Under Key Scope, expand the Admin scope, then expand Integrations.
    4. Check the box for MSA. Ensure the Scope is set to the default, Read/Write.
      The Sase Meraki 02 interface.
    5. Click Create Key.
    6. Copy the API Key and Key Secret.
      The Sase Meraki 03 interface.
      Note
      For security reasons, the Key Secret is only displayed once. If lost, it cannot be retrieved.
    1. Click ACCEPT AND CLOSE.
    Note

    If your SD-WAN environment requires spoke-to-spoke communication over the hub, contact Meraki Support for assistance with the remaining integration steps.

  4. In the Meraki dashboard, navigate to Organization > Integrations (In the Configure section).

  5. Select Cisco Secure Access.

    The Sase Meraki 04 interface.
  6. Click + Connect at the top right.

  7. Enter the Secure Access API key and Key Secret pair that you created in Secure Access, then click Add integration.

    The Sase Meraki 05 interface.

    After completion, the page displays the user who added the integration, the integration date, and the organization ID from the Secure Access dashboard.

    The Sase Meraki 06 interface.

    For more information, see Cisco SASE: Onboarding/Offboarding Cisco SASE with Meraki SD-WAN.

Your Meraki dashboard will now include a SASE tab in the left navigation menu.

The Sase Meraki 07 interface.

Your Secure Access dashboard will now include a Return to Meraki tab in the left navigation menu.

The Sase Meraki 08 interface.

What to do next

Enroll your Sites

From your Meraki dashboard, connect Meraki sites to Secure Access regions. The SASE Auto-VPN feature will automatically establish primary and secondary IPsec tunnels between your Meraki sites and Secure Access data centers.

For more information, see Enroll Meraki SD-WAN Sites with Meraki Auto-VPN Tunnels in Secure Access documentation and Cisco SASE: Sites Connectivity in Meraki documentation.

Configure Access Policy

Once the Auto-VPN tunnels are connected, Meraki sites appear as network tunnel groups in Secure Access. Protect one or more Meraki sites by configuring Secure Access private and internet access rules.

For more information, see Manage the Access Policy in Secure Access documentation and Cisco SASE: Policy in Meraki documentation.