Cisco Secure Access Help Manage Virtual Private Networks Manage Machine Tunnels Provision a Machine Tunnel User

Last updated: Aug 22, 2025

Provision a Machine Tunnel User

This is done by provisioning a machine tunnel user with a specific email (machine@sse.com) from your organization's identity provider (IdP), such as Active Directory. Secure Access supports various methods to provision users and groups.


 
We recommend you use certificate-based authentication to register device identities with Active Directory. The method to associate machine tunnel and user identity via the manual upload of a CSV file, as described in this procedure, is scheduled to be phased out.