Manage Users, Groups, and Endpoint Devices
Cisco Secure Access supports the integration of users, groups, and endpoint devices through various identity providers (IdPs). Once integrated with Secure Access, you can protect and monitor the connections for the users and devices to internet and private destinations by configuring Access rules in the organization's policy.
- You can integrate multiple cloud IdPs with Secure Access.
- Endpoint device integration requires devices provisioned by an on-premise Active Directory domain controller (DC) and Cisco AD Connector version 1.14.4 or newer. For more information, see Connect Active Directory to Secure Access and Configure Updates on AD Connectors.
In addition to integrations with identity providers for provisioning users and groups, we recommend that you configure user authentication profiles. Authentication profiles describe integrations with single sign-on (SSO) IdPs. SSO IdPs authenticate users that connect through the Secure Access Secure Web Gateway (SWG) or with Secure Access Zero Trust Access.
- You can set up multiple authentication profiles in Secure Access.
- An authentication profile describes the association between a provisioning IdP and an SSO IdP.
After you add user directory integrations and set up user authentication profiles, Secure Access displays the users and groups that you provisioned in the organization.