Set Up Users and Roles

As part of Secure Workload onboarding:

  • Create users and assign user roles

  • Configure licenses

  • Install software agents

Before you begin, ensure that:

  • The cluster is deployed and configured. For the initial deployment and configuration, contact Cisco Advanced Services.

  • You can login to the cluster.

  • Valid Cisco Secure Workload licenses are reflecting under the Smart Software Manager Virtual accounts. Cisco Secure Workload offers two modes for licensing–Connected mode and Air-Gapped mode.

    For more information, see Cisco Smart Licensing in the Secure Workload user guide.

Add a user

Adding users allows administrators to delegate access, ensure proper role assignments, and support multitenant environments in Secure Workload. Only users with Site Admin or Scope Owner permissions can add new user accounts.

Before you begin

  • When you set up the cluster, the system creates a default username with site administrator privileges. As a first-time user, you can log in using this default username, then click Forgot Password to create a password. After you log in, you are assigned site administrator privileges.

  • You must be a Scope Owner to add users in Secure Workload.

  • If a user is assigned a scope for multitenancy, only roles that are assigned to the same scope may be selected.


Note


This page shows information based on your selected scope preference in the page header.


Procedure


Step 1

If applicable, select the appropriate root scope from the page header.

Step 2

Navigate to Manage > User Access > Users.

Step 3

Click Create New User.

The User Details page appears.

Step 4

Enter the User Details:

Table 1. User Details Field Descriptions

Field

Description

Email or Username

Enter the email address of the user. The email addresses are non-case sensitive. If your email contains letters, we use the lowercase version of the letters.

Enter the username of the user; usernames are non-case sensitive and cannot contain @ or spaces.

First Name

Enter the user’s first name.

Last Name

Enter the user’s last name.

Scope

Select the root scope for multitenant assignment (available to Site Admins)

Step 5

Click Next.

Step 6

Under Assign Roles, add or remove assigned roles for the user.

  • Click Add Roles to assign new roles, and then click the Add check box.

    Figure 1. Assigned User Roles
    Assigned User Roles
  • Select the assigned roles, click Edit Assigned Roles, and then click the Remove icon.

  • You can filter the user roles using Name or Tenant.

    Figure 2. Filter User Roles
    Filter User Roles

Step 7

Click Next.

Step 8

Under User Review, confirm user details and the assigned roles. Click Create.

If external authentication is enabled, the authentication details are displayed.

After the user is added in Secure Workload, an activation email is sent to the registered email ID to set up the password.


Add a user when SMTP server is disabled

Add new users to the system without requiring email addresses, ensuring management access even when outgoing email is unavailable.

Before you begin

  • You must be a Scope Owner to add users in Secure Workload.

  • If a user is assigned a scope for multitenancy, only roles that are assigned to the same scope may be selected.


Note


This page is filtered by the scope preference that is selected on the page header.


Procedure


Step 1

If applicable, select the appropriate root scope from the page header.

Step 2

Navigate to Manage > User Access > Users.

Step 3

Click Create New User.

The User Details page appears.

Step 4

Update these fields under User Details.

Table 2. User Details Field Descriptions

Field

Description

Username

Enter a username without @ or spaces; usernames are not case-sensitive.

Note

 

If the SMTP server is configured as disabled, Site Admins can create users only with a username.

First Name

Enter the user’s first name.

Last Name

Enter the user’s last name.

Generate Temporary Password

Generate a temporary password for the user's username.

Note

 

Site Admins will need to share the temporary password with the user.

Scope

Root scope that is assigned to the user for multitenancy (available to Site Admins).

Step 5

Click Next.

Step 6

Under Assign Roles, add or remove assigned roles to the user.

  • Click Add Roles to assign new roles, and then click the Add check box.

    Figure 3. Assigned User Roles
    Assigned User Roles
  • Select the assigned roles, click Edit Assigned Roles, and then click the Remove icon.

  • You can filter the user roles using Name or Tenant.

    Figure 4. Filter User Roles
    Filter User Roles

Step 7

Click Next.

Step 8

Review the user details and the assigned roles in User Review.

Step 9

Click Create.


User Login

Securely activate a user account after creation and ensure a permanent password is set.

To login to Secure Workload, use the username and the temporary password provided by the Site Admin.

Procedure

  Command or Action Purpose

Step 1

After you login to Secure Workload, create a permanent password in the Reset password page.

Note

 

If SMTP is disabled for site configuration, the Forgot password button will be disabled for users at login.

Step 2

To secure the account, enter a new password on the Reset password page. After resetting the password, enter the username and the newly set password in the login page.

Note

 

New password must meet these conditions:

  • At least 8 characters long

  • At least one uppercase letter

  • At least one lowercase letter

  • At least one number

  • At least one special character: !@#$%^*&-_+={}[/}|\?:;",'

Note

 
  • If SMTP server configuration is disabled, existing users can keep logging in with their email addresses and current passwords.

  • In Secure Workload Release 3.10, when SMTP is disabled, only LDAP authentication is supported for external authentication but SSO authentication is unavailable in this configuration.

  • Existing users can change their email addresses to usernames using the User Edit page if they choose to, though this is not mandatory.

Edit user details or assign roles

Update a user’s profile information or role assignments to reflect current responsibilities and access requirements.

Before you begin

Editing user details or roles ensures accurate identity records and appropriate access control for your organization.

  • You must have Site Admin or Root Scope Owner privileges to edit users.

  • The Users page content may be filtered according to the selected scope preference in the page header.

Procedure


Step 1

If applicable, select the appropriate root scope from the page header.

Step 2

Go to Manage > User Access > Users.

Step 3

Locate the user account to modify. Under Actions, select Edit.

The User Details page appears.

Step 4

Update these fields under User Details as needed.

Table 3. User Details Field Descriptions

Field

Description

Email or Username

Update the email address of the user. Usernames are non-case sensitive and cannot contain "@" or spaces in the username.

Note

 

In case of users without an email ID, a Site Admin uses the username of the user. The maximum length of a username is 255 characters.

First Name

Update the user’s first name.

Last Name

Update the user’s last name.

Scope

Root scope assigned to the user for multitenancy (available to Site Admins).

Reset multifactor authentication (MFA)

If the user has lost their MFA device or is locked out of MFA, then click Reset MFA. MFA of the user is reset in a few minutes.

Resend Activation Email

If a user has not received an activation email or the activation email link has expired, then click Resend Activation Email.

Note

 

Users with a username can update their login ID from a username to an email address, or vice versa. After upgrade, existing users with an email address can update their login ID from email to username.

Step 5

Click Next.

Step 6

Under Assign Roles, add or remove assigned roles to the user.

  • Click Add Roles to assign new roles, and then click the Add check box.

  • Select the assigned roles, click Edit Assigned Roles, and then click the Remove icon.

Step 7

Under User Review, confirm the user details and the assigned roles. Click Update to update the user account.

If external authentication is enabled, the authentication details are displayed.

Step 8

Click Next.


Deactivate a user account

Only site administrators or Root Scope Owners can deactivate users. When you deactivate a user, you keep the change log audits consistent because the system never deletes users from the database.

Note


To maintain consistency of change log audits, users can only be deactivated, they are not deleted from the database.


Before you begin

You must be assigned Site Admin or Root Scope Owner role.


Note


This page is filtered by the scope preference that is selected on the page header.


Procedure


Step 1

Go to Manage > User Access > Users.

Step 2

If applicable, select the appropriate root scope from the top right of the page.

Step 3

In the row of the account you want to deactivate, click the Deactivate button in that column.

To view deactivated users, use the Hide Deleted Users toggle.


Reactivating a User Account

Use this task if a user no longer has access because their account was deactivated and you need to reinstate their permissions.

If a user has been deactivated, you can reactivate the user.

Before you begin

You must have the Site Admin or Root Scope Owner role.


Note


This page is filtered by the scope preference that is selected on the page header.


Procedure


Step 1

Go to Manage > User Access > Users.

Step 2

If needed, select the appropriate root scope from the top right of the page.

Step 3

Toggle Hide Deleted Users off to display all users, including deactivated accounts.

Step 4

Locate the deactivated user account and click Restore to reactivate the account.

The selected user regains access to the system.

Configure login page message

Site Administrators and Customer Support users can add or edit a custom message of up to 1600 characters that appears on the login page.

Follow these steps to configure the login page message:

  1. Go to Platform > Login Page Message.

  2. Enter or edit the message. The character limit is 1600 characters.

  3. Click Save.

Change logs

Site Admins can access the Change Log page under the Manage menu in the navigation bar at the left side of the window. This page displays the most recent changes that are made within Cisco Secure Workload.


Note


Change Log Retention Period: Secure Workload manages change logs for up to one year on both SaaS and On-premises clusters. An automated process deletes any log entries older than one year.


Figure 5. Change Log Page
Change Log Page

How to view change details:

  • Each change log entry provides a link in the Change At column.

    Figure 6. Change Log Details Page
    Change Log Details Page
  • Selecting this link shows detailed Before and After snapshots of the fields that were changed. Note that the field names may use technical terminology, which may appear differently elsewhere in Cisco Secure Workload.

  • To see the complete list of changes for an entity, click the Full log for this <entity type> button in the upper-right corner. This view displays all recorded changes and, when available, the current state of the entity.

Figure 7. Full Change Log for Entity
Full Change Log for Entity

Roles

You can restrict access to features and data using role-based access control (RBAC) model.

  • User - someone with login access to Cisco Secure Workload.

  • Role - user created set of capabilities that is assigned to a user.

  • Capability - scope + ability pair

  • Ability - collections of actions

  • Action - low-level user action such as “change workspace name”

Figure 8. Role Model

A user can have any number of roles. Roles can have any number of capabilities. For example, the “HR Search Engineer” role could have two capabilities: “Read on the HR Scope” to give visibility and context and “Execute on “HR:Search” capability to allow the engineers assigned this role to make specific changes that are related to their applications.

Use the Users page to assign users to the different roles. Roles have several capabilities and you can assign users to any number of roles.

System roles are defined to allow users to get started more quickly. They define different levels of access to all Scopes, that is, all data on the system. These system roles are defined below.

Role

Description

Agent Installer

Provide the ability to manage agents life cycle including install, monitor, upgrade, and convert, but cannot delete agents and access agent config profile.


Note


If required, you can create a SecOps user role to provide the ability to access flows, alerts, vulnerabilities, and forensics events within a specific scope.


Abilities and capabilities

A capability is a combination of an ability and a scope that

  • defines the set of allowed actions (abilities),

  • determines the area or dataset (scope) that the actions apply to, and

  • controls access for users based on assigned roles in the system.

Your role contains capabilities, each of which gives you a specific ability and defines where you can use it. For example, if you have (HR, Read) as a capability, you can read information in HR and all its sections.

Ability

Description

Installer

Install, monitor, and upgrade software agents.

Audit

Global appliance data read support and access to change logs.

Read

Read all data including flows, application, and inventory filters.

Write

Make changes to applications and inventory filters.

Execute

Automatically discover policies, run them, and publish policies for analysis.

Enforce

Enforce policies that are defined in application workspaces that are associated with the given scope.

SecOps Read

Read all flows, alerts, vulnerabilities, and forensics events for the assigned scope.


Important


Abilities are inherited, for example, the Execute ability allows all the Read, Write, and Execute actions.



Important


Abilities apply to the scope and all the scope’s children.


Component-specific Abilities and Capabilities

This table describes the abilities and capabilities specific to a component.

Table 4. Component-specific abilities and capabilities

Component Name

Installer

Read

Audit

Write

Execute

Enforce

Owner

Security Dashboard

Not Applicable

Yes

Yes

Yes

Yes

Yes

Yes

Scopes and Inventory

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

Label Management

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

Inventory Filters

Not Applicable

Read-only

Read-only

Yes

Yes

Yes

Yes

Segmentation

Not Applicable

Read-only

Read-only

Add policies, but cannot publish or enforce them or manage alerts

Add or publish policies, but cannot enforce or manage alerts

Yes

Yes

Enforcement Status

Not Applicable

Yes

Yes

Yes

Yes

Yes

Yes

Policy Templates

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

Forensic Rules

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

Traffic

Not Applicable

Yes

Yes

Yes

Yes

Yes

Yes

Alerts

Not Applicable

Yes

Yes

Yes

Yes

Yes

Yes

Vulnerabilities

Not Applicable

Yes

Yes

Yes

Yes

Yes

Yes

Forensics

Not Applicable

Yes

Yes

Yes

Yes

Yes

Yes

Reporting Dashboard

Not Applicable

Yes

Yes

Yes

Yes

Yes

Yes

Agent Install

Yes

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Agent Upgrade

Yes

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Agent convert to enforcement

Yes

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Agent Configure

Read-only

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Agent Monitor

Yes

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Agent Distribution

Yes

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Agent list

Only applicable to the deletion of agents and the generation of tokens for service protection

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Alert Config

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

Virtual Appliances

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

Connectors

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

Secure Connector

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

External Orchestrators

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

Kubernetes

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Roles

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Users

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Licenses

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Change Logs

Not Applicable

Not Applicable

No

Not Applicable

Not Applicable

Not Applicable

Yes

Session Configuration

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Data Tap Admin

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

Collection Rules

Not Applicable

Read-only

Read-only

Read-only

Read-only

Read-only

Yes

IP Addresses

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Not Applicable

Yes

API Key Capabilities

software_download

  • sensor_management

  • flow_inventory_query

  • user_role_scope_management

  • user_data_upload

  • app_policy_management

  • external_integration

  • software_download

  • flow_inventory_query

  • user_role_scope_management

  • user_data_upload

  • app_policy_management

  • external_integration

  • software_download

  • sensor_management

  • flow_inventory_query

  • user_role_scope_management

  • user_data_upload

  • app_policy_management

  • external_integration

  • software_download

  • sensor_management

  • flow_inventory_query

  • user_role_scope_management

  • user_data_upload

  • app_policy_management

  • external_integration

  • software_download

  • sensor_management

  • flow_inventory_query

  • user_role_scope_management

  • user_data_upload

  • app_policy_management

  • external_integration

  • software_download

  • sensor_management

  • flow_inventory_query

  • user_role_scope_management

  • user_data_upload

  • app_policy_management

  • external_integration

  • software_download

Menu Access by Role

The menu items that you see and use on the navigation pane depend on the assigned role:

Table 5. Overview Menu

Menu

Option

Tenant Owner

Agent Installer

Overview

Overview

Yes

No

Table 6. Organize Menu

Menu

Option

Tenant Owner

Agent Installer

Organize

Scopes and Inventory

Yes

No

Organize

Use Uploaded Labels

Yes

No

Organize

Inventory Filters

Yes

No

Table 7. Defend Menu

Menu

Option

Tenant Owner

Agent Installer

Defend

Segmentation

Yes

No

Defend

Enforcement Status

Yes

No

Defend

Policy Templates

Yes

No

Defend

Forensic Rules

Yes

No

Table 8. Investigate Menu

Menu

Option

Tenant Owner

Agent Installer

Investigate

Traffic

Yes

No

Alerts

Yes

No

Vulnerabilities

Yes

No

Forensics

Yes

No

Table 9. Reporting Menu

Menu

Option

Tenant Owner

Agent Installer

Reporting

Reporting Dashboard

Yes

No

Table 10. Manage Menu

Menu

Option

Tenant Owner

Agent Installer

Manage

Agents

Yes

Yes

Manage

Alerts Configs

Yes

No

Manage

Change Logs

Yes

No

Manage

Connectors

Yes

No

Manage

External Orchestrators

Yes

No

Manage

Secure Connector

Yes

No

Manage

Virtual Appliances

Yes

No

Manage

Users

Yes

No

Manage

Roles

Yes

No

Manage

Collection Rules

Yes

No

Manage

Session Configuration

Yes

No

Manage

Usage Analytics

Yes

No

Manage

Data Tap Admin

Yes

No

Create a Role

Before you begin

You must have a Site Admin or a Customer Support role.

  1. From the navigation pane, choose Manage > User Access > Roles.

  2. Click Create New Role. The Roles panel appears.

Creating a role using the Create Role Wizard is three-step process.

Procedure


Step 1

  1. Enter the appropriate values in the following fields:

    Field

    Description

    Name

    The name to identify the role.

    Description

    A short description to add context about the role.

  2. Click the Next button to move to the next step or Back to Roles Page to go back to Roles Page.

Step 2

  1. Click the Add Capability button to show the creation form in the top row.

  2. Select scope and ability.

  3. Click the Checkmark button to create a new capability or Cancel button to cancel.

  4. Click Next to review role details or Previous to go back and edit.

Figure 9. Capability Assignment
Capability Assignment

Step 3

  1. Review the role details and capabilities.

  2. Click Create to create role.

Figure 10. Role Review
Role Review

Edit a Role

Editing a role using the Edit Role Wizard is a three-step process. This section explains how Site Admins and Customer Support users can edit roles.

Before you begin

You must be Site Admin or Customer Support User.

  1. From the navigation pane, choose Manage > User Access > Roles.

  2. In the row of the role to edit, click the Edit button in the right-hand column. The Roles panel appears.

Procedure


Step 1

  1. Update the name or description if desired.

  2. Click the Next button to move to the next step or Back to Roles Page to go back to Roles Page.

Step 2

  1. Remove any capability as needed. In the row of the capability to delete, click the Delete icon in the right-hand column.

  2. To add, click the Add Capability button to show the creation form in the top row.

  3. Select scope and ability.

  4. Click Next to review role details or Previous to go back and edit.

Step 3

  1. Review the role details and capabilities.

  2. Click Update to create the role or Previous to go back and edit. Changes to role details and capability assignment are saved after Update.

Note

 

Capabilities cannot be edited, they must be deleted and recreated.


Change logs

Site Admins can access the Change Log page under the Manage menu in the navigation bar at the left side of the window. This page displays the most recent changes that are made within Cisco Secure Workload.


Note


Change Log Retention Period: Secure Workload manages change logs for up to one year on both SaaS and On-premises clusters. An automated process deletes any log entries older than one year.


Figure 11. Change Log Page
Change Log Page

How to view change details:

  • Each change log entry provides a link in the Change At column.

    Figure 12. Change Log Details Page
    Change Log Details Page
  • Selecting this link shows detailed Before and After snapshots of the fields that were changed. Note that the field names may use technical terminology, which may appear differently elsewhere in Cisco Secure Workload.

  • To see the complete list of changes for an entity, click the Full log for this <entity type> button in the upper-right corner. This view displays all recorded changes and, when available, the current state of the entity.

Figure 13. Full Change Log for Entity
Full Change Log for Entity

Collection Rules

Site Admins and Customer Support users can access the Collection Rules page under the Manage > Service Settings menu in the navigation bar at the left side of the window. This page displays the hardware collection rules by VRF that is used by switches running the Cisco Secure Workload agent. There is a row in the table for each VRF.

Rules

Click the Edit button on a VRF to modify its collection rules. By default, every VRF is configured with two default catch-all rules, one for IPv4 (0.0.0.0/0 INCLUDE) and one for IPv6 (::/0 INCLUDE). These default rules can be removed, but do so with caution.

Extra include and exclude rules can be added. Enter a valid subnet, select include or exclude, and click Add Rule. The priority of these rules can be adjusted via drag-and-drop. Click-and-hold on a rule in the list and drag it to adjust the order.

Changes may take several minutes to propagate to your switches. Click the Back button in the upper-right corner to return to the VRF list.

Priority

Collection Rules are ordered in decreasing order priority. No longest prefix match is done to determine the priority. The rule appearing first has higher priority over all the subsequent rules. Example:

  1. 1.1.0.0/16 INCLUDE

  2. 1.0.0.0/8 EXCLUDE

  3. 0.0.0.0/0 INCLUDE

In the earlier example, all addresses belonging to 1.0.0.0/8 subnet are excluded except subnet 1.1.0.0/16 which is included.

Another Example with changed order:

  1. 1.0.0.0/8 EXCLUDE

  2. 1.1.0.0/16 INCLUDE

  3. 0.0.0.0/0 INCLUDE

In the above example, all addresses belonging to 1.0.0.0/8 subnet are excluded. Rule number-2 does not get exercised here because of a higher-order rule already defined for its subnet.

Session Configuration

UI User Authentication idle session timeout can be configured here. This config applies to all the users of the appliance. The default idle session duration is 1 hour. The idle session duration can be set within the range of 5 minutes to 24 hours. The session timeout takes effect on a user’s authenticated session when this value is saved.

Site Admins and Customer Support users can access this setting. In the left navigation pane, click Manage > Service Settings > Session Configuration.

Idle Session

For those who are authenticating using a local database, this section explains how failed login attempts may lock the user account:

Procedure

Step 1

Five failed login attempts using email and password result in locking the account.

Note

 

As a security measure against probing, no specific message indicating the lock will be provided in the login interface when trying to sign in a locked account.

Step 2

Lock out interval is set at 30 minutes. After the account is unlocked, use the correct password to log in or initiate password recovery by clicking Forgot password?

Note

 

Once a user is successfully signed in, one hour of inactivity logs out the user. This timeout is configured from Manage > Service Settings > Session Configuration.


Preferences

The Preferences page displays your account details and enables you to update your display preferences, change your landing page, change your password, and configure two-factor authentication.

Change Your Landing Page Preference

To change the default page on the UI when you sign in:

Procedure

Step 1

On the top-right corner of the window, click the user icon and choose User Preferences.

Step 2

Choose a landing page from the drop-down menu. Your preference is saved as the default or home page when you log in. To see the change, click the Secure Workload logo at the top-left corner of the page.


Change a Password

Procedure

Step 1

Click on the user icon in the top-right corner.

Step 2

Select User Preferences.

Step 3

In the Change Password pane, enter your current password in the Old Password field.

Step 4

Enter your new password in the Password field.

Step 5

Re-enter your new password in the Confirm Password field.

Step 6

Click Change Password to submit the change.

Note

 

Password must be 8–128 characters and contain at least one of the each following:

  • Lower case letters ( a b c d . . . )

  • Upper case letters ( A B C D . . . )

  • Numbers (0 1 2 3 4 5 6 7 8 9 )

  • Special characters ( ! " # $ % & ’ ( ) * + , - . / : ; < = > ? @ [ \ ] ^ _ ‘ { | } ~ ), space included


Recovery Codes
Procedure
  Command or Action Purpose

Step 1

Download the recovery codes from the User Preferences page.​

Note

 

Only admins have the ability to generate recovery codes. Note that if external authentication is enabled, recovery code generation is not supported.​

Step 2

Each admin user will have to download their recovery codes after login and will be provided with six recovery codes.​

Step 3

At login, enter the recovery code in the password field. Recovery codes must be used during login in conjunction with the username.

Step 4

When logging in with the username and recovery code as the password, users will be redirected to the password reset screen to set a new password.

Note

 

The used recovery code will no longer be valid for subsequent logins.​ We suggest users regenerate their recovery codes before exhausting all available codes.​

Recover Password

This section explains how to reset your password if you have forgotten the password.

Before you begin

To reset a password, you must have an account. Only a Site Admin has the priviledge to create new accounts.

Procedure

Step 1

Point your browser to the Cisco Secure Workload URL and click the Forgot Password link. The Forgot your password? dialog box is displayed.

Step 2

Step 3

Enter the email ID to which the password must be sent.

Step 4

Click Reset Password.

Password reset instructions are sent to your email.

Note

 

The password recovery procedure using two-factor authentication requires contacting Cisco Technical Assurance Center for a temporary one-time password.


Reset Password

This section explains how to reset password for users without an email ID.


Note


If SMTP is disabled, at login, the Forgot Password button will be disabled for users.


Procedure

Step 1

As a Site Admin, log in to Secure Workload, and from the navigation pane, choose Manage > User Access > Users.

Step 2

Under the Actions column, click the Pencil icon. The User Details page is displayed.

Table 11. User Details Field Descriptions

Field

Description

Email or Username

Enter the username of the user; the usernames are non-case sensitive, but should not contain @ or spaces in the username.

Note

 

If the SMTP configuration is switched OFF, email-based authentication will be affected as you will not be able to send the password reset instructions to the users.

Note

 

As a Site Admin, you can use the username to generate temporary passwords for users who want to recover them.

The maximum length of a username cannot exceed 255 characters.

First Name

Enter the user’s first name.

Last Name

Enter the user’s last name.

Scope

Root scope that is assigned to the user for multitenancy. (Available to site admins)

SSH Public Key

(Optional) Click Import to import an SSH public key or you can import a key later.

Step 3

To generate a temporary password, click Generate Password. Copy the password and share it with users who request them.

Note

 

To reset the password, use the username and the temporary password to login to Secure Workload. After you login, create a permanent password in the Reset password page.

Figure 14. User Details

Step 4

To secure the account, enter the new password in the Reset password page. After resetting the password, enter the username and the newly set password in the login page.

Note

 

New password must meet the following conditions:

  • Length of the password must be at least 8 characters.

  • Password must contain at least one upper-case letter.

  • Password must contain at least one lower-case letter.

  • Password must contain at least number.

  • Password must contain at least one of the special characters: !@#$%^*&-_+={}[/}|\?:;",'