Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage User Authentication Profiles

Want to summarize with AI?

Log in

Describes Manage User Authentication Profiles in Cisco Secure Access. Cisco Secure Access supports the use of Security Assertion Markup Language (SAML) or OpenID Connect (OIDC) to authenticate users.


Cisco Secure Access supports the use of Security Assertion Markup Language (SAML) or OpenID Connect (OIDC) to authenticate users. Secure Access requires that users are authenticated before they can connect to internet-bound destinations through the Secure Access Secure Web Gateway (SWG) or connect with Secure Access Zero Trust Access (ZTA) to private destinations.

To get started, add a single sign-on (SSO) authentication profile in Secure Access for each user authentication IdP integration. You must associate one of the organization's configured provisioning profiles (user directory) with the SSO authentication profile.

Add User Authentication Profiles

When you configure a user authentication profile, associate a provisioning profile for a cloud IdP with the user authentication profile. You can only assign one unique provisioning IdP in the user authentication profile.

About Single Sign-On

View User Authentication Profiles

After you add a user authentication profile in Secure Access, you can view the list of configured user authentication profiles for the organization. For more information, see View SSO Authentication Profiles.

Edit a User Authentication Profile

After you add a user authentication profile, you can edit the profile in Secure Access. For more information, see Edit an SSO Authentication Profile.

Delete a User Authentication Profile

After you add a user authentication profile, you can remove the profile in Secure Access. For more information, see Delete an SSO Authentication Profile.


Requirements for Configuring SSO Authentication Profiles

When you add an SSO authentication profile in Secure Access, you must assign one of the user directories (integrated cloud provisioning IdPs) with the profile. You can associate a user directory that is not already assigned to an SSO authentication profile. For more information, see Manage User Directories.


About the Default Provisioning Profile

If you previously integrated an SSO IdP that supported SSO authentication but Secure Access did not have the option to assign a user directory to the integration, Secure Access will associate the Default Profile for this integration.

The Default Profile describes the integration of an existing IdP in Secure Access using the organization's ID and the SCIM token that you generated for the IdP integration.

The Duo SSO interface.

Add SSO Authentication Profiles

This guide describes how to add SSO authentication profiles for the integration of user authentication IdPs in Secure Access.

After you provision users and groups in Cisco Secure Access with a provisioning identity provider (IdP), you can configure the integration of a single sign-on (SSO) authentication identity provider (IdP). Secure Access supports Security Assertion Markup Language (SAML) and OpenID Connect (OIDC) to authenticate users.

When you add an SSO authentication profile in Secure Access, you must assign one of the user directories (integrated cloud provisioning IdPs) with the profile. You can associate a user directory that is not already assigned to an SSO authentication profile. For more information, see Manage User Directories.

Before you begin

  • Full Admin user role. For more information, see Manage Accounts.

  • Add the Cisco User Management Connector integration app. For more information see Add the Cisco User Management Connector App in Okta.

    Note
    When you add the Cisco User Management Connector application to your IdP, the connector app only suppports SAML. You cannot use OIDC to authenticate with the connector.

Procedure

  1. Navigate to Connect > Users and User Groups, and then click Configuration management.


    The Users and Groups Top Nav interface.
  2. Navigate to SSO authentication, and then click Add SSO authentication.

    The Duo SSO 1 interface.
  3. For SSO Authentication Name, enter a unique name for the SSO authentication profile.


    The SSO Auth Profile Add Name interface.
  4. For Authentication Method, click Security Assertion Markup Language (SAML) or OpenID Connect (OIDC).


    The User Auth SAML or Oidc interface.
  5. For User Directory, choose the directory for the cloud IdP that provisions the users and groups.


    The SSO Auth Choose Directory interface.
  6. Click Next.

  7. For IdP Authentication, follow the steps in the OIDC or SAML configuration guides to complete the integration of the SSO authentication IdP.

  8. We strongly recommend deploying a test configuration to ensure users can authenticate with the assigned IdP. For more information see Test SAML Identity Provider Integration.

  9. Click Done.


View SSO Authentication Profiles

Before you begin

Procedure

  1. Navigate to Connect > Users and User Groups, and then click Configuration management.


    The Users and Groups Top Nav interface.
  2. Navigate to SSO authentication. Secure Access lists the configured SSO authentication profiles.

    The SSO Authentication interface.