Provides instructions for completing the Unenroll Devices for Client-Based Zero Trust Access workflow in Cisco Secure Access. It explains the sequence of actions and relevant settings presented in the procedure.
After a user enrolls their device for zero trust access on the Cisco Secure Client, the device appears in Secure Access. The user's device can create secure zero trust sessions and connect to their organization's private resources.
If you need to remove a user device that has zero trust access enabled from the organization, you can unenroll the user's device on Secure Access. The unenroll administrative action has these consequences:
- Prevents new zero trust connections from the device.
- The user device cannot create any new zero trust sessions to private resources.
- Invalidates the device's zero trust certificate.
- Blocks all current active zero trust access (ZTA) sessions associated with the enrollment.
Before you begin
- Full Admin user role. For more information, see Manage Accounts.
- A user device that has enrolled in zero trust access on the Cisco Secure Client.