Software Secure Access
Activity Manage

Connect Active Directory to VAs

The Cisco Active Directory (AD) Connector integrates Cisco Secure Access with your instance of Microsoft AD. Before you can provision users and groups from Active Directory, connect your instance of AD to Secure Access by deploying an AD Connector.

Install the AD Connector in the same Site as your deployed Secure Access Virtual Appliances.

The Cisco Active Directory (AD) Connector monitors one or more domain controllers in your environment.

  • The AD Connector listens to user and computer logins through the security event logs, and then transmits IP-to-user and IP-to-computer mappings to your deployed Secure Access Virtual Appliances (VAs).
  • The AD Connector synchronizes user-to-group, computer-to-group and group-to-group memberships with Secure Access, which enables you to create and enforce group-based settings and view user, computer, and group-based reports.

The AD Connector helps import your Active Directory (AD) users, groups and computers to provide these mappings.

Note: Only one AD Connector is required for each Secure Access Site. For redundancy, add an optional second AD Connector. If you are onboarding multiple AD domains through domain controller integrations, one AD Connector is required per AD domain per Umbrella site, with an optional second connector for redundancy if required.

This guide describes the steps to install the Cisco AD Connector for LDAP or LDAPS, and provision users and groups from your instance of Microsoft AD to Secure Access.