Software Secure Access
Activity Manage

Prerequisites

  • On user devices:
    • Minimum device operating system version:
      • Windows 10
      • macOS version 11
      • Windows devices must support Trusted Platform Module (TPM) 2.0
      • Mac devices must support Secure Enclave
    • Cisco Secure Client must be installed on user endpoint devices. The Zero Trust Access module is integrated into the Cisco Secure Client.
    • Each device must have an identity certificate signed by your corporate certificate signing authority (CA). The identity certificate must be tied to a specific user, not to the device, so:
      • The certificate Subject Alternative Name (SAN) must include the user's RFC 822-compliant email address, or the User Principal Name (UPN) field must include the username.
      • The ZTA Client will evaluate certificates with an Issuer Common Name that matches any of the CA certificates enabled in the ZTA enrollment dashboard. If multiple identity certificates share the same Common Name, the client will select the first matching certificate.
      • The identity certificate must be installed in the machine or user-specific keystore on each device.
        • On Windows:
          C:\\ProgramData\\Cisco\\Cisco Secure Client\\ZTA\\enrollment_choices
          
        • On macOS:
          /opt/cisco/secureclient/zta/enrollment_choices