Cisco

How search works in the Security Help Center:

  • The most relevant topics (based on weighting and matching to search terms) are listed first in the search results by default
  • Common Boolean operations are supported
  • Use double quotes to find a phrase (“specific phrase”)
  • Apply facets on the Search Results page to further scope search results by category
Login

Log In to the Cisco Security Documentation Portal

Search

Cisco Secure Access Help

  • Getting Started and Onboarding
    • Introduction to Secure Access
      • Welcome to Cisco Secure Access
      • Sign into Secure Access with Security Cloud Sign On
      • Find Your Organization ID
      • Determine Your Current Package
      • Limitations and range limits
        • Destinations for Client-Based Zero Trust Traffic
        • Domain Names
        • File Inspection and File Analysis
        • Internet Protocol Versions
        • IP Address Restrictions
        • Other Components
        • Reports
        • Resource Connectors and Resource Connector Groups
        • Service Connections
        • Users and Groups
      • Endpoint Data Center Selection
        • Roaming Web Protection (Secure Web Gateway)
        • Zero Trust Access (ZTA) for Private Applications
        • Trusted Internet Access (TIA) via the ZTA Client
        • Remote Access VPN (VPNaaS)
        • Regional and US Federal Government Deployments
        • Information to Gather Before Contacting Cisco Support
    • Secure Access Dashboards
      • Secure Access Overview Dashboard
        • Get Started Workflow
        • Experience Insights
        • Network Tunnel Group Usage
        • Connectivity
        • Data Transfer
        • Security
          • Security Activity
          • Top Security Categories
          • File Retrospective
        • Users and Groups
        • Private Resources
      • Service Analytics Dashboard
      • Security Insights Dashboard
        • Security Overview Tab
        • Data Security Tab
        • AI Governance Tab
        • Applications Tab
        • Users Tab
        • Threat Tab
      • Secure Access Status Portal
        • Interpreting Cloud Security Platform Service Status
        • Scheduled Maintenance
        • Service Status History
        • Manage Outage Notifications
    • Cisco Assistant for Secure Access
      • Get Started with the Cisco Assistant
        • Use the Cisco Assistant
        • Cisco Assistant Navigation
      • Add Rules with the Cisco Assistant
        • Enter a Natural Language Prompt to Generate Policy Rules
        • Cisco Assistant Rule Examples
        • Contextual Conversations
      • Find Documented Answers with the Cisco Assistant
        • Best Practices for Prompts
        • Contextual Conversations
      • Troubleshoot Access Issues with Private Resources
      • Optimize Access Policies
      • Messages Generated by the Cisco Assistant
      • Create Cisco Support Cases
    • Regions
      • Secure Access Regions
    • Network Requirements
      • Network requirements for Secure Access
      • DNS requirements
        • Secure Access DNS Resolvers
          • Best Practices
          • Cisco Secure Client
          • Cisco Secure Client and External DNS Resolution
        • Secure Access Encrypted DNS Queries
        • Secure Access DNS, Web, and Block Pages
        • Secure Access DNS and Web – Client Configuration Services
        • Secure Access DNS and Web – Client Sync Services
        • Secure Access DNS and Web – Client Certificate Revocation Services
      • Secure Client requirements
        • Cisco Secure Client and Captive Portal Detection
        • Cisco Secure Client and Device Hostnames
      • Transport layer security protocol requirements
        • TLS 1.2 Support in Windows
        • TLS 1.2 Support in macOS
      • Secure web gateway service requirements
        • Egress IP Addresses for the Secure Web Gateway
        • Ingress IP Addresses for the Secure Web Gateway
      • Realtime DLP secure ICAP requirements
      • SaaS tenant requirements
        • Microsoft 365
      • SAML identity provider requirements
        • Secure Access SAML Gateway Services
          • Active Directory Federation Service SAML Identity Provider
        • Secure Access SAML Identity Provider Domains
          • Azure AD SAML Identity Provider
        • Secure Access SAML Gateway Client Certificate Revocation Services
      • Virtual private network requirements
        • Secure Access VPN Services
        • Secure Access VPN Client Certificate Revocation Services
      • Zero trust access requirements
        • Secure Access Zero Trust Client-Based Enrollment Services
        • Secure Access Zero Trust Client-Based Proxy Services
          • Known Network Restrictions for Zero Trust Clients
        • Secure Access Zero Trust Client-Based Proxy – Client Certificate Revocation Services
        • Secure Access Zero Trust Proxy Services – Unmanaged Devices
        • Secure Access Zero Trust Services and Connector Groups
    • Secure Access Onboarding
      • Get Started
      • Secure Access Onboarding Workflow
        • Step 1 – Configure network connections
          • Task 1 – Add Network Connections
          • Task 2 – Provision Users and Groups
          • Task 3 – Configure Integrations with SAML Identity Providers
        • Step 2 – Configure access to resources
          • Task 1 – Set Up Private Resources
          • Task 2 – Configure Rule Defaults and Global Settings
          • Task 3 – Add a Policy Rule
        • Step 3 - Configure end user connectivity
        • Step 4 – Configure endpoints and network sources
      • Hybrid Private Access Workflow
        • Procedure
      • Quickstarts
        • Quickstart – Cisco Secure Client with Zero Trust Access
        • Quickstart – Cisco Secure Client with Virtual Private Network
        • Quickstart – Cisco Secure Client with Internet Security
        • Quickstart – Browser with SAML Authentication
        • Quickstart – Bring Your Own Device with Zero Trust
      • Additional Onboarding Resources
    • Basic Network Setup
      • Fully Qualified Domain Names for Network Connections
        • About Fully Qualified Domain Names (FQDNs)
        • Global FQDN
        • Regional FQDNs
        • VPN Headend FQDN
      • Manage Registered Networks
        • Add Network Resources
          • Step 1 – Select the Network
          • Step 2 – Configure the Network Resource
          • Step 3 – Change the DNS Settings on Your Relevant Network Device
          • Step 4 – Apply a Policy Rule to the Network Resource
          • Step 5 – Test Your Network
          • Update a Network Resource
            • Edit the Registered Network Resource Name
            • Update the Registered Network Resource
            • Delete a Network Resource
        • Point Your DNS to Cisco Secure Access
          • Cisco Secure Access DNS Resolvers – IP addresses
          • Cisco Secure Access DNS Resolvers – Anycast IP Addresses
          • Procedure for Pointing Your DNS to Cisco Secure Access
            • Step 1 – Identify Where Your Public DNS Server Addresses are Configured
            • Step 2 – Log Into the Server or Router Where DNS is Configured
            • Step 3 – Change Your DNS Server Addresses
              • Primary and Secondary Servers
            • Step 4 – Test Your New DNS Settings
      • Clear Your DNS Cache
        • Clear Your DNS Cache on Computers and Servers
          • Windows 7 and Earlier
          • Windows 8 and Newer
          • OS X 10.4 TIGER
          • OS X 10.5 and 10.6 LEOPARD
          • OS X 10.7 and 10.8 Lion
          • OS X 10.9 and 10.10
          • Linux
          • Ubuntu Linux
        • Clear Your DNS Cache on Browsers
          • Internet Explorer 8 and Newer – Windows
          • Mozilla Firefox – Windows
          • Apple Safari – macOS
          • Google Chrome – Windows
          • Google Chrome – macOS
      • Manage Internal Networks
        • Add Internal Network Resources
        • Update an Internal Network Resource
        • Delete an Internal Network Resource
      • Manage Sites
  • Core Platform Administration
    • Accounts
      • Accounts Overview
        • Add a New Account
        • Edit Account Settings
        • Delete an Account
      • Hide sources with de-identification
        • Enable De-identification
        • Disable De-identification
    • Network Infrastructure
      • Manage Network Devices
        • How to Add a Network Device in Secure Access
        • Procedure for Managing Network Devices
          • View the Network Devices in Secure Access
          • Edit a Network Device
          • Remove a Network Device
      • Secure Access NAT as a Service
        • Web Traffic and NATaaS
        • Non-Web Traffic and NATaaS
        • Best Practices for NATaaS
        • Reserved IP Addresses
          • Network Requirements for Reserved IPs
          • Best Practices for Reserved IPs
          • Known Limitations of Reserved IPs
          • Deployment of the Reserved IP
          • Reporting and Reserved IP
          • Calculate Your Maximum Sessions
          • Troubleshooting Reserved IPs
        • Reserved IP Supplemental Terms
      • Network Connections
        • Comparison of Network Connection Methods
        • Network Tunnels in Secure Access
        • Resource Connectors in Secure Access
      • Network Tunnel Groups
        • Add a Network Tunnel Group
        • Delete a Network Tunnel Group
        • Edit a Network Tunnel Group
        • View Network Tunnel Group Details
        • Manage Summary Subnets
        • Override Route Summarization for a Network Tunnel Group
        • View Global Routes
        • Establish an IPsec Tunnel
        • Supported IPsec Parameters
      • Routing Options and Guidelines for Network Tunnel Groups
        • NAT Mapping for Network Tunnel Groups
        • Static Routing
        • Dynamic Routing with BGP
        • Dynamic Routing with Multi-Region Backhaul
        • Global Routing
        • BGP Next-Hop Configuration
        • User VPN Pool Sizing and BGP Advertisement
        • Asymmetric Routes
        • Equal-Cost-Multi-Path (ECMP) Support
        • Route Summarization
    • Network Tunnels by Device
      • Best Practices for Configuring Network Tunnels by Device
      • Configure Tunnels with Cisco Catalyst SD-WAN
      • Configure Automatic Tunnels with Catalyst SD-WAN
        • Enable DNS resolution
        • Configure API credentials in SD-WAN Manager
        • Create the Cisco Secure Access policy to be configured in the SD-WAN branches
        • Deploy the Cisco SSE policy to be configured in SD-WAN branches
          • Route-Based Redirection (Using Service Routes in a VPN)
          • Policy-Based Redirection (Using Application Priority and SLA Policy)
          • Tunnel Status Verification Using CLI Commands
          • Verify the Tunnel Status in the SD-WAN Manager Console
          • Verify the Tunnel Status in Secure Access Dashboard
      • Configure Tunnels with Cisco ISR
      • Configure Tunnels with Cisco Adaptive Security Appliance
      • Configure Tunnels with AWS Virtual Private Clouds and Elastic Compute instances
        • Deploy a New AWS Transit Gateway
        • Configure Two VPN Site-to-Site Connections to the New Transit Gateway
          • Configure the Second VPN Site-to-Site Connection
          • Configure the VPC Route Table to use the AWS Transit Gateway
      • Configure Tunnels with VeloCloud SD-WAN
      • Configure Tunnels with Cisco Secure Firewall
        • Configure NAT Policy
        • Configure Access Policy
        • Configure Secure Firewall VTI, PBR, and Per Tunnel Identity
          • Configure Tunnels in Secure Access
          • Configure Site-to-Site VPN
          • Configure Policy-based Routing
          • Configure Access Policy
        • Troubleshooting
          • Enable Logging for Debugging
      • Configure Tunnels with Meraki MX
        • Prerequisites for Tunnels with Meraki MX
        • Caveats and Considerations
        • Supported Use Cases and Requirements
        • Step 1: Add a Network Tunnel Group in Secure Access
        • Step 2: Configure a Tunnel in Meraki MX
        • Verification and Troubleshooting
        • Optional Configurations
      • Enroll Meraki SD-WAN Sites with Meraki Auto-VPN Tunnels
      • Configure Tunnels with NEC IX2000 Series Router
      • Site-to-Site VPN tunnels with Microsoft Azure
        • Configure Azure S2S Tunnels with Static Routing
        • Configure Azure S2S Tunnels with Dynamic Routing with BGP
      • Configure a Site-to-Site VPN tunnel with Amazon Web Services
    • DNS and DDNS Servers
      • Manage DNS and DDNS Servers
      • Manage DNS Servers
        • Add a DNS Server
        • View DNS Servers
        • Edit a DNS Server
        • Delete a DNS Server
      • Map DNS Servers to Regions
      • Manage DDNS Servers
        • Add a DDNS Server Group
        • View DDNS Servers
        • Edit a DDNS Server
      • Map DDNS Servers to Regions
    • Resource Connectors and Connector Groups
      • Manage Resource Connectors and Connector Groups
        • Requirements and Prerequisites for Resource Connectors and Connector Groups
          • Guidelines for Connector Groups
          • Requirements and Guidelines for Connectors
          • Connectivity Requirements
          • Capacity Requirements
        • Allow Resource Connector Traffic to Secure Access
          • Region-Specific Destinations
          • Destinations For All Regions
        • Add Resource Connector Groups
        • Add Connectors to a Connector Group
          • Step 1 – Deploy Secure Access Resource Connectors
          • Step 2 – Confirm Connectors
          • Step 3 – Assign Private Resources to Connector Group
        • Obtain the Connector Image
          • Get the Connector Image for AWS
          • Get the Connector Image for Microsoft Azure
          • Download the Connector Image for VMware
          • Get the Connector Image for Docker
        • Provisioning Keys for Resource Connectors
          • Copy the Provisioning Key for a Connector Group
        • Deploy a Connector in VMware
          • Step 1 – Extract the Connector Image for VMware Tar File
          • Step 2 – Verify the Integrity of the Image
            • Validate the Signature
            • Verify the Checksum of the Signing Key
          • Step 3 – Deploy the OVF Template
          • Step 4 – Power on Connector Instances
          • Step 5 – Confirm Connectors
        • Deploy a Connector in AWS
          • Get Connector Images on the AWS Marketplace
          • Step 1 – Launch an Amazon Machine Image for the Connector Instance
          • Step 2 – Configure the Connector
          • Step 3 – Launch the Connector Instance
        • Deploy a Connector in Azure
          • Step 1 – Get Connector Images on Microsoft Azure Marketplace
          • Step 2 – Configure the Resource Connector Virtual Machine
          • Step 3 – Connect to the Resource Connector Instance
        • Deploy a Connector in Docker
          • Set Up the Resource Connector and Container
          • Launch the Resource Connector in the Docker Container
          • Troubleshoot Container Deployments
            • Setup Failures
            • Check the Container's Status
            • Get the Version of the Docker Container Image
            • Stop the Container
            • Restart the Container
            • Delete the Container
            • Run Diagnostic and Techsupport Scripts
        • Determine the Number of Connectors Needed in a Connector Group
        • Assign Private Resources to a Connector Group
          • Guidelines for Assigning a Private Resource to a Connector Group
          • Assign a Private Resource to a Connector Group
        • View a Connector Group's Connectors and Assigned Resources
        • Edit a Resource Connector Group
        • Disable, Revoke, or Delete Resource Connectors and Groups
          • Disable, Revoke, or Delete a Connector
          • Disable or Delete a Resource Connector Group
      • Maintain and Monitor Resource Connectors and Connector Groups
        • Monitor Connector Group Status
        • View Connector Groups in Secure Access
        • View Connectors in Secure Access
        • Monitor Connector Status
        • View a Connector's Status
        • Enable a Connector in Secure Access
        • Increase Connector Group Capacity
        • Check Connector CPU Load
      • Schedule Upgrade Windows or Delay for a Connector Group
        • Add Upgrade Windows for a Connector Group
        • Add Delay of Upgrades for a Connector Group
      • Troubleshoot Resource Connectors and Connector Groups
        • Throughput Capacity is Less Than Expected
        • Users Cannot Connect to Private Resources
        • Connector Software Auto-Upgrades
        • Connector Operating System (OS) Version has Security Vulnerabilities
        • Connector is Expired
        • Stop a Connector
        • Unable to Revoke or Delete a Connector
        • Unable to Sync
        • Connector-Related Status Graphs are not Current
        • (Container Only) Connector Troubleshooting Tools
        • (VM Only) Connector Diagnostics (CLI)
          • Run the Diagnostic Command on the Resource Connector
          • Supported Standard Linux Troubleshooting Commands
          • Run tcpdump on Resource Connectors
        • Diagnostic Codes
    • Roaming Devices
      • Manage Roaming Devices
      • View Internet Security Settings for Roaming Devices
        • Procedure
          • Host Information
          • Secure Web Gateway
          • Security Information – IPv4
          • Security Information – IPv6
      • Edit Internet Security Settings for Roaming Devices
        • Procedure
          • Edit the Auto-Delete Interval for Roaming Devices
          • Disable the Internet Security Settings
          • Enable the Internet Security Settings
          • Remove the Internet Security Override on Roaming Devices
      • Delete a Roaming Device
    • Private Resources
      • Manage Private Resources
        • Add a Private Resource
          • Define a Private Resource
          • Private Resource Address
          • Endpoint Connection Methods
            • Client-Based Zero-Trust Connections
            • Browser-Based Zero-Trust Connections
            • VPN Connections
          • Resource Connector Groups
          • Decryption
          • View Access Rules Associated with a Private Resource
          • What's Next
        • Discover Private Resources
        • Map a Discovered Resource to Existing Private Resources
        • Test Private Resource Reachability
        • Add a Private Resource Group
        • Private Resource Configuration Examples
    • Connections to Private Destinations
      • Manage Connections to Private Destinations
        • Using Private Resources for SaaS Internet Destinations
        • Comparison of Zero Trust Access and VPN
        • Timeout Intervals for Zero Trust Access Sessions
          • ZTA Connections to Private Resources
          • ZTA Connections to Private Resources with IPS or File Malware Scanning
          • ZTA Connections to Internet Destinations
        • Comparison of Client-Based and Browser-Based Zero Trust Access Connections
        • Requirements for Zero Trust Access
        • Configure Client-Based Zero Trust Access for Private Destinations
        • Configure Browser-Based Zero Trust Access to Private Resources
        • Network Authentication for Zero Trust Access
        • Connection Scenarios for Private Destinations
      • Manage Branch Connections
        • Endpoint Connection Methods
        • Branch Networks in Private Access Rules
          • Users and Groups Connections to Private Resources
          • Sources for Branch Network Connections
          • Destinations for Branch Network Connections
          • Source Connections to Destinations
        • Add an IPS Profile on Private Access Rules
        • Log Connections From Branch Networks to Private Resources
      • Allow SSH and RDP Access to Private Resources
        • Browser-Based Zero Trust Access
          • Configuration overview: Browser-based zero trust access using SSH or RDP
          • Notes for browser-based SSH and RDP access
          • Supported options for SSH access
        • Client-Based Zero Trust Access
      • Application Portal for Zero Trust Access Browser-Based User Access
        • Prerequisites
        • Configure an Application Portal for Zero Trust Access Browser-Based User Access
        • Filter Policies Based on Applications
        • (Optional) Modify Settings
    • Network and Service Objects
      • Get Started with Network and Service Objects
        • Quickstart: Network and Service Objects
        • Access Rules with Network and Service Objects
        • Combine Destinations with Boolean Logic
      • Manage Network Objects and Groups
        • Get Started with Network Objects
          • Add a Network Object
          • About Importing a CSV File of Network Objects
            • Upload CSV File with Network Objects
            • Examples of Valid CSV Files
          • Edit a Network Object
          • Duplicate a Network Object
          • Delete a Network Object
        • Get Started with Network Object Groups
          • Add a Network Object Group
          • View Objects, Groups and Values in a Network Object Group
          • Edit a Network Object Group
          • Duplicate a Network Object Group
          • Delete a Network Object Group
        • View Network Objects and Groups
      • Manage Service Objects and Groups
        • Get Started with Service Objects
          • Add a Service Object
          • About Importing a CSV File of Service Objects
            • Upload CSV File with Service Objects
            • Examples of Valid CSV Files
          • Edit a Service Object
          • Duplicate a Service Object
          • Delete a Service Object
        • Get Started with Service Object Groups
          • Add a Service Object Group
          • View Objects, Groups and Values in a Service Object Group
          • Edit a Service Object Group
          • Duplicate a Service Object Group
          • Delete a Service Object Group
        • View Service Objects and Groups
    • Manage API Keys
      • Manage API Keys
      • About Secure Access API Keys
        • Add an API Key
        • Refresh an API Key
        • Update an API Key
        • Delete an API Key
      • About Key Admin API Keys
        • Add a Key Admin API Key
        • Refresh a Key Admin API Key
        • Update a Key Admin API Key
        • Delete a Key Admin API Key
  • Identity and Access
    • Users, Groups, and Endpoint Devices
      • Manage Users, Groups, and Endpoint Devices
        • Manage End-User Connectivity
        • View Users Provisioned in Secure Access
          • View User Details
        • View Group and Organizational Unit Details
          • Group Details
          • Organizational Unit Details
        • View Details for Endpoint Devices
          • View a Configured AD Device
      • Unenroll Devices for Client-Based Zero Trust Access
        • Reenroll the User Device on the Secure Client
      • Disconnect Remote Access VPN Sessions
    • User Directories and Device Management
      • Manage User Directories and Device Management
      • Configure User Directory Integrations
        • View Directories
      • Manage Cloud Identity Providers
        • Add a Cloud Identity Provider
        • View an Integrated Cloud Provider
        • Edit an Identity Provider Integration
        • Delete an Identity Provider Integration
      • Manage API Keys for Provisioning Identities
        • Guidelines
        • Add the API Key for Managing Identities
        • Refresh the API Key for Managing Identities
        • Delete API Keys
        • View Details About Provisioned API Keys
        • View Details for Identities Provisioned with the API
        • View Endpoint Devices
      • Manage Active Directory Integration
        • Download the Active Directory Components
        • Edit the Active Directory Connector Auto-Upgrades
        • Edit Authentication Properties for the AD Integration
        • Enable DLP Email Notifications for Reporting Managers
        • View Active Directory Components
        • Manage Sites for AD Components
        • Delete Active Directory Integration
      • Manage Google Workspace Account
      • Manage Imported Users and Groups
        • Import Users and Groups from CSV File
          • CSV File Format
          • CSV File Fields
          • View Provisioned Users and Groups in Secure Access
        • Upload a New CSV File with Users and Groups
        • Delete an Imported CSV File
    • Advanced User Configuration Settings
      • Manage Advanced Configuration Settings
        • Set Up Authentication Preferences for Identity Providers
        • Set Up IP Surrogates for SSO User Authentication
        • Set Up API Authentication
      • Manage IP Surrogates for User Authentication
        • How HTTPS Inspection Works
        • Enable IP Surrogates for User Authentication
        • Add Internal Networks for Bypass
        • Delete Internal Networks for Bypass
      • Manage Behaviour Analytics Configuration
        • Configure Analytics for DLP Violation Spike
          • Procedure
        • Configure Analytics for File Operations with AI
        • Configure Analytics for File Operations Manually
        • Configure Analytics for High-Risk Country File Activities
        • Configure Analytics for Impossible Travel
        • Configure Analytics for Anomalous MCP Activities
        • Configure Analytics for Unseen Location Activities
        • Configure Analytics for Traffic Spike and Destination Monitoring
        • UEBA Scope
        • Known Issues
    • Identity Providers
      • Configure Identity Providers
      • Provision Users and Groups from Duo
        • Limits and Best Practices
        • Supported Features
        • Add the Duo IdP directory to Secure Access
        • View Provisioned Users and Groups in Secure Access
        • Refresh SCIM Token
        • Attribute Mapping (Mandatory)
      • Provision Users and Groups from Okta
        • Configure the Cisco User Management Connector App in Okta
          • Add the Cisco User Management Connector App in Okta
          • Enable In-App SAML SSO for the Cisco Management Connector in Okta
          • Add the Secure Access SCIM Token and URL in the App
          • Configure User Options in the App
        • (Optional) Add an objectGUID Attribute and Create the User Profile Mapping
          • Add the objectGUID Attribute
          • Create the User Profile Mappings
        • Customize the authName Attribute
        • Map the Custom authName Attribute to a User Profile
        • Assign Users or Groups in the App
        • Push Users or Groups from the App to Secure Access
        • View Logs in the App
      • Provision Users and Groups from Microsoft Entra ID
        • Configure Provisioning in Microsoft Entra ID
        • Configure Guest Users
    • Provision Users, Groups, and Endpoint Devices from Active Directory
      • Provision Users, Groups, and Endpoint Devices from Active Directory
        • Prerequisites for AD Connectors
        • Connect Multiple Active Directory Domains
        • Active Directory Components
          • Add AD Components
            • Verify Auditing of Logon Events on Domain Controllers
            • Download the Windows Configuration Script for Domain Controllers
            • Run the Windows Configuration Script for the Domain Controllers
            • Add a Domain Controller
            • Add a Domain
          • View AD Components
          • Assign a Load Balancing Group to AD Components
          • Edit Sites for AD Components
          • Delete AD Components
      • Manage AD Connectors
        • Configure Authentication for AD Connectors and VAs
          • How to Set Up Your API Credentials
            • Step 1 – Create the Key Admin API Key Credentials
            • Step 2 – Add the Key Admin API Key Credentials
          • Refresh Client API Key and Secret
          • Reset Client API Key
        • Configure Updates on AD Connectors
        • Connect Active Directory to Secure Access
          • Step 1 – Download the Active Directory Connector
          • Step 2 - Install the Active Directory Connector
        • (Optional) Specify AD Groups in Selective Sync File
          • Rename Selective Sync File After Upgrading to AD Connector v1.14.4
          • Create AD Groups in a Selective Sync File
        • Deploy LDIF Files for AD Connector
          • Step 1 – Download the Active Directory Connector
          • Step 2 – Install the Cisco AD Connector
          • Step 3 – Deploy the LDIF Source Files
          • Troubleshooting
        • Change the Connector Account Password
        • AD Connector Communication Flow and Troubleshooting
          • Communication Flow
          • Troubleshooting
      • Edit AD Authentication Properties
        • Best Practices: Configuring the AD Authentication Properties
      • Synchronize Active Directory Reporting Manager Email Addresses for DLP Notifications
      • AD Integration with Virtual Appliances
        • Network Diagram for VA Deployments
        • How to Set Up AD Components with VAs
        • Prerequisites for AD Connectors and VAs
        • Prepare Your AD Environment
          • About the AD Connector and Logon Events
          • Prerequisites
            • Additional Prerequisites for the Windows Event Log Collector
          • Integrate AD with Domain Controllers
            • Support for Multiple AD Domains and AD Forests
            • Verify Auditing of Logon Events on Domain Controllers
            • Download the Windows Configuration Script for Domain Controllers
            • Run the Windows Configuration Script for the Domain Controllers
            • Add a Domain Controller in Secure Access
            • View the Registered AD Components in Secure Access
          • Integrate AD with a Centralized Windows Event Log Collector
            • Step 1 – Add the Windows Event Log Collector in Secure Access
            • Step 2 – Add the AD Domains in Secure Access
        • Connect Active Directory to VAs
          • How to Configure the Setup of the AD Connector
          • (Optional) Specify AD Groups in Selective Sync File
            • Rename Selective Sync File After Upgrading to AD Connector v1.14.4
            • Create AD Groups in a Selective Sync File
          • Step 1 – Add the Windows Event Log Collector in Secure Access
          • Step 2 – Download the Active Directory Connector
          • Step 3 - Install the Active Directory Connector
          • Change Connector Account Password
          • Configure Updates to AD Connectors
        • Configure Active Directory User Exceptions in Secure Access
          • Set up an AD User Exception
          • Set up an AD Group Exception
          • Set up AD IP Address Exception
        • Multiple AD Domains with Secure Access Sites
          • Active Directory Sites and Secure Access Sites
          • Use Secure Access Sites
    • User Authentication Profiles
      • Manage User Authentication Profiles
        • Requirements for Configuring SSO Authentication Profiles
        • About the Default Provisioning Profile
        • Add SSO Authentication Profiles
        • View SSO Authentication Profiles
      • About Single Sign-On for Users
        • Sign-On for Provisioned Users
          • Scenario
          • Sample Sign-On Window
        • Sign-On for Non-Provisioned Users
          • Scenario
          • Sample Sign-On Window
      • Edit an SSO Authentication Profile
        • (OIDC Only) Get Metadata for OIDC Configuration URL
        • Edit SAML User Authentication Profile
        • Edit OIDC User Authentication Profile
      • Delete SSO Authentication Profile
        • Delete SAML User Authentication Profile
        • Delete OIDC User Authentication Profile
    • Integrations with Open ID Connect Identity Providers
      • Configure Integrations with OIDC Identity Providers
        • About Using OpenID Connect with Secure Access
        • Use Cases – SSO Authentication
      • Configure Duo for OpenID Connect
        • Configure Duo SSO authentication through OIDC in Secure Access
        • View Provisioned Users and Groups in Secure Access
      • Configure Okta for OpenID Connect
        • Verify the UPN and preferred_username Mapping
        • Step 1 – Choose an Authentication Method
        • Step 2 – Add an Identity Provider
        • Step 3 – Configure the Identity Provider's OIDC Metadata
          • Step 3a – Add the Secure Access Redirect URI in Okta
          • Step 3b – Configure the Core Grants in Okta
          • Step 3c – Get the Okta OIDC Client ID and Secret
          • Step 3d – Get the Okta OIDC Configuration URL
        • Step 4 – Add the OIDC Metadata in Secure Access
      • Configure Microsoft Entra ID for OpenID Connect
        • Step 1 – Choose an Authentication Method
        • Step 2 – Add an Identity Provider
        • Step 3 – Configure the Identity Provider's OIDC Metadata
          • Step 3a – Add the Secure Access Redirect URI in Entra ID
          • Step 3b – Get the Client ID and Secret for Entra ID OIDC
          • Step 3c – Get the Tenant ID for Entra ID OIDC
        • Step 4 – Add the OIDC Metadata in Secure Access
    • Integrations with SAML Identity Providers
      • Configure Integrations with SAML Identity Providers
        • Use Cases – SSO Authentication
        • Prerequisites for SAML Authentication
      • Configure Microsoft Entra ID for SAML
        • Step 1 – Add SSO Authentication Profile in Secure Access
        • Step 2 – Add SAML Identity Provider in Secure Access
        • Step 3 – Add the Identity Provider's SAML Metadata to Secure Access
          • Step 3a – Download the Secure Access Service Provider files
          • Step 3b – Add Secure Access Service Provider Metadata to Entra ID
          • Step 3c – Add the Entra ID SAML Metadata to Secure Access
      • Configure Okta for SAML
        • Step 1 – Add SSO Authentication Profile in Secure Access
        • Step 2 – Add Okta SAML Identity Provider in Secure Access
        • Step 3 – Download the Secure Access Service Provider Files
        • Step 4 – Configure Okta with the Secure Access SAML Metadata
        • Step 5 – Get Metadata from Okta App Integration
        • Step 6 – Add Okta Metadata in Secure Access
      • Configure AD FS for SAML
        • Step 1 – Add SSO Authentication Profile in Secure Access
        • Step 2 – Add AD FS Identity Provider in Secure Access
        • Step 3 – Add the Identity Provider's SAML Metadata to Secure Access
          • Step 3a – Download the Secure Access Service Provider files
          • Step 3b – Add the Secure Access Service Provider Metadata to AD FS
          • Step 3c – Add the SAML IdP Metadata to Secure Access
      • Configure Duo Security for SAML
        • Step 1 – Add SSO Authentication Profile in Secure Access
        • Step 2 – Add Duo Identity Provider in Secure Access
        • Step 3 – Add the Identity Provider's SAML Metadata to Secure Access
          • Step 3a – Download the Secure Access Service Provider files
          • Step 3b – Add Secure Access Service Provider Metadata to Duo Security
          • Step 3c – Add the Duo Security SAML Metadata to Secure Access
      • Configure Ping Identity for SAML
        • Step 1 – Add SSO Authentication Profile in Secure Access
        • Step 2 – Add Ping Identity Provider in Secure Access
        • Step 3 – Add the Identity Provider's SAML Metadata to Secure Access
          • Step 3a – Download the Secure Access Service Provider files
          • Step 3b – Add the Secure Access Service Provider Metadata to Ping Identity
          • Step 3c – Add the Ping Identity SAML Metadata to Secure Access
      • Configure OpenAM for SAML
        • Step 1 – Add SSO Authentication Profile in Secure Access
        • Step 2 – Add OpenAM Identity Provider in Secure Access
        • Step 3 – Add the Identity Provider's SAML Metadata to Secure Access
          • Step 3a – Download the Secure Access Service Provider files
          • Step 3b – Add Secure Access Service Provider Metadata to OpenAM
          • Step 3c – Add the OpenAM Metadata to Secure Access
      • SAML Certificate Renewal Options
      • Test SAML Identity Provider Integration
    • Access Policies
      • Manage the Access Policy
        • About the Access Policy
          • Control Options on an Access Rule
        • Rule Data
          • Show Additional Data on Your Access Rules
          • Edit the Order of the Rules in Your Access Policy
        • Default Access Rules in Your Policy
          • View or Edit Default Access Rules
      • Manage Global Settings for Access Rules
        • Display User Input Field on Warn Pages
        • Microsoft 365 Compatibility
        • Decryption
        • Client Resolved Domain Destination List
        • Disable Decryption for Specific Sources
        • Decryption Logging
        • Certificate Pinning
      • Rule Defaults: Default Settings for Access Rules
        • Zero Trust Access: Endpoint Posture Profiles
        • Zero Trust Access: User Authentication Interval
          • User Authentication Default Interval Settings
        • Intrusion Prevention (IPS)
        • Security Profile
        • Isolation Profile
        • Tenant Control Profile
      • Edit Rule Defaults and Global Settings
      • Using Wildcard Masks on Access Rules
        • Wildcard Masks in Composite Sources or Destinations
        • Guidelines
        • Examples of Wildcard Masks
      • View Related Activity for an Access Policy Rule
      • View Related Events for an Access Policy Rule
    • Internet Access Rules
      • Internet Access Rules
        • Default Settings for Internet Access Rules
        • Global Settings for Internet Access Rules
        • Components for Internet Access Rules
          • Sources
            • Reusable Sources in Internet Access Rules
            • Combining Reusable Sources in a Rule with Boolean Logic
            • Composite Sources in Internet Access Rules
          • Destinations
            • Reusable Destinations in Internet Access Rules
            • Composite Destinations in Internet Access Rules
            • Combining Multiple Destinations in a Rule (Boolean Logic)
          • Security Controls
            • Intrusion Prevention (IPS)
            • Security Profile
              • Set Up Certificates for Decrypting Internet Traffic
              • Configure Do Not Decrypt Lists
            • Tenant Controls
            • Advanced Security Controls
        • Control Egress IP Address for Select SaaS Internet Destinations
        • Ensure Rule Matching for Encrypted Internet Traffic
        • Block Internet Access to Geographic Locations
      • Add an Internet Access Rule
        • Access Criteria
          • Enable the Rule and Edit Your Logging Settings
          • Summary
          • Rule Name
          • Rule Order
          • Rule Action
          • Enable a Schedule on an Internet Access Rule
          • Pre-Configured Sources
          • Composite Sources
          • Pre-Configured Destinations
          • Select Applications with Objects or Groups on Rules
          • Select Application Protocols with Objects or Groups on Rules
          • Select Content Categories with Objects or Groups on Rules
          • Select Objects and Groups with Other Destinations on Rules
          • Add Reusable Network Objects on Rules
          • Edit Network Objects on Rules
          • Add Reusable Service Objects on Rules
          • Edit Service Objects on Rules
          • Add Composite Destinations on Rules
          • Edit Composite Destinations on Rules
          • Select Application Protocols with Composite Destinations on Rules
            • How Application Protocols Combine with Composite Destinations
          • App Risk Profiles
          • Advanced Application Controls
            • Applications with Advanced Controls
              • Cloud Storage
              • Collaboration
              • Content Management
              • Media
              • Office Productivity
              • P2P
              • Social Networking
            • Add Advanced Application Controls
            • Troubleshooting Advanced Application Controls
          • About Configuring Threat Categories on Internet Access Rules
          • Isolation Profile Configuration
        • Security Control Options
          • Manage Advanced Security Controls
      • Geolocation Sources and Internet Access Rules
        • Sources
        • Add Geolocation Sources on Internet Access Rules
        • View Events Report
        • Filter the Report by Firewall Requests
        • Filter the Report by Web Requests
      • Edit an Internet Access Rule
      • About Isolated Destinations
        • Secure Access Package Support for RBI and Isolation Rules
        • Verifying Isolation
        • Limitations of Isolation
        • Isolate Downgrade
          • Filter Isolate Rules
          • Duplicate a Downgraded Isolate Rule
      • Troubleshoot Internet Access Rules
    • Internet and SaaS Resources
      • Manage Internet and SaaS Resources
      • Manage Destination Lists
        • Add a Destination List
        • Upload Destinations From a File
        • Edit a Destination List
        • Search the Destination List
        • Delete a Destination List
        • Download Destinations to a CSV File
        • Control Access to Custom URLs
          • Block a URL
            • URL Normalization
            • URL Normalization for Destination Lists
            • Troubleshooting Unblocked URLs
            • Reporting for Blocked URLs
          • Examples
        • Control Access to Domains
        • About Client Resolved Domain Destination List
          • Add Domains in Client Resolved Domain Destination List
          • Download Domains in Client Resolved Destination List
          • Delete Domains in Client Resolved Domain Destination List
        • Troubleshoot Destination Lists
      • Manage Application Lists
        • Add an Application List
        • Application Categories
        • Edit an Application List
        • Delete an Application List
      • Manage Content Category Lists
        • Available Content Categories
        • Add a Content Category List
        • Delete a Content Category List
        • Request a Category for an Uncategorized Destination
        • Dispute a Content Category
        • View Content Categories in Reports
          • View Content Categories in Activity Search Report
          • View Content Categories in Top Threats Report
          • View Content Categories in Total Requests Report
          • View Content Categories in Activity Volume Report
          • View Content Categories in Top Destinations Report
          • View Content Categories in Top Categories Report
      • Manage Tenant Control Profiles
        • Control Cloud Access to Microsoft 365
        • Control Cloud Access to Google Workspace
        • Control Cloud Access to Slack
        • Control Cloud Access to Dropbox
        • Control Cloud Access to YouTube
        • Blocking Behavior for YouTube Tenant Control
        • Control Access to ChatGPT
        • Control Cloud Access to GitHub
        • Edit or Delete a Tenant Control Profile
        • Use Tenant Controls in Access Rules
        • Review Tenant Controls Through Reports
    • Private Access Rules
      • Get Started With Private Access Rules
        • Default Settings for Private Access Rules
        • Global Settings for Private Access Rules
        • Components for Private Access Rules
          • Sources
            • Reusable Sources in Private Access Rules
            • Combining Multiple Sources in a Rule with Boolean Logic
            • Composite Sources for Private Access Rules
          • Destinations
            • Reusable Destinations in Private Access Rules
            • Composite Destinations for Private Access Rules
            • Combining Multiple Destinations in a Rule with Boolean Logic
          • Endpoint Posture Profiles (for Endpoint Requirements)
          • Security Controls
            • Intrusion Prevention (IPS)
            • Security Profile, for File Inspection and File Type Controls
        • About Endpoint Requirements in Access Rules
      • Add a Private Access Rule
        • Geolocation Sources and Private Access Rules
          • About Geolocation Sources
          • Add Geolocation Sources on Private Access Rules
          • View Events Report
          • Filter the Report by Firewall Requests
          • Filter the Report by Web Requests
        • Set Up the Private Access Rule
          • Enable the Rule and Edit Your Logging Settings
          • Add a Rule Name
          • Summary
          • Choose a Rule Order
          • Rule Action
          • Enable a Schedule on a Private Access Rule
          • Pre-Configured Sources
          • Add Composite Sources
          • Pre-Configured Destinations
          • Add Composite Destinations
          • Select Network and Service Objects on Private Access Rules
          • Endpoint Requirements
          • User Authentication Requirements
        • Configure Security Control Options
      • Geolocation Sources and Private Access Rules
        • About Geolocation Sources
        • Add Geolocation Sources on Private Access Rules
        • View Events Report
        • Filter the Report by Firewall Requests
        • Filter the Report by Web Requests
      • Edit a Private Access Rule
      • About ZTA Private Access Enforcement
        • Most Specific Match Enforcement Mode
        • Multi-App Match Enforcement Mode
          • Scenario 1: Multiple matching IP/CIDR destinations in different resources
          • Scenario 2: Multiple matching FQDN destinations in different resources
          • Scenario 3: Multiple matching rules by source and destination – rule ordering priority in effect
          • Scenario 4: Tie-breaker scenarios for multiple valid resource destinations in matched rule
        • Multi-App with Resolved IP Match Enforcement Mode
          • Scenario 1: FQDN resource-based rule at higher priority than IP resource-based rule
          • Scenario 2: IP resource-based rule at higher priority than FQDN resource-based rule
          • Scenario 3: Tie-breaker scenario for FQDN-IP overlap within the same rule
      • Allowing Traffic from Users and Devices on the Network
      • Blocking Access to Private Destinations
      • Troubleshoot Private Access Rules
    • IPS Profiles
      • Manage IPS Profiles
        • How IPS Works
          • Hit Counts
          • Cisco-Provided IPS Signature Lists
        • Decryption is Required for Effective Intrusion Prevention
        • Exceptions for Traffic That Should Not be Decrypted
        • IPS is Used in Both Types of Access Rules
        • Add a Custom IPS Signature List
          • Procedure for Adding a Custom IPS Signature List
          • Reset a Signature's Action
    • Security Profiles
      • Manage Security Profiles
      • Security Profiles for Internet Access
        • Functionality Included in a Security Profile for Internet Access
        • Decryption
        • SSO Authentication
        • Security and Acceptable Use Controls
        • End-User Notifications
        • Get Started: Security Profiles for Internet Access
        • Add a Security Profile for Internet Access
          • Add a Security Profile
          • Enable or Disable Decryption
          • SSO Authentication
          • Configure Security and Acceptable Use Controls
            • Threat Categories
            • File Inspection
            • File Type Blocking
            • SafeSearch
            • AI Supply Chain Blocking
            • AI Semantic Inspection
          • Configure End-User Notifications
          • View Security Profiles
          • Configure Additional Security Options
          • Add a Security Profile on Internet Access Rules
          • Edit a Security Profile
          • Delete a Security Profile
      • Enable SafeSearch
        • Confirm That SafeSearch is Working
          • Google
          • YouTube
          • Yahoo
          • Bing
      • Security Profiles for Private Access
        • Add a Security Profile for Private Access
    • App Risk Profiles
      • Manage App Risk Profiles
        • App Risk Profile Attributes
        • Add an App Risk Profile
    • Threat Categories
      • Manage Threat Categories
        • Threat Category Descriptions
        • Add a Threat Category List
        • Dispute a Threat Categorization
          • How to Dispute a Threat Categorization
    • Traffic Decryption
      • Manage Traffic Decryption
        • Internet Access Features That Require Decryption
        • Internet Traffic That Should Not Be Decrypted
        • Decryption in Private Access Rules
        • Important Information About Do Not Decrypt Lists
        • Add a Do Not Decrypt List for Security Profiles and Internet Access
    • Schedules for Access Rules
      • Manage Schedules
        • Add a Schedule
        • View and Manage Schedules
          • View Schedules in Secure Access
          • Edit a Schedule
          • Delete a Schedule
    • Virtual Private Networks and Proxy Settings
      • Manage Virtual Private Networks
        • Manage Regions and IP Pools
          • Add a Region Configuration
          • Enable or Disable VPN Regions
          • Add an IP Pool
          • Assign an IP Pool
          • Modify IP Pools
          • Modify IP Pool Assignment
        • Manage RADIUS Servers and Groups
          • Add a RADIUS Group
          • Test a RADIUS Server Connection
        • Manage VPN Profiles
          • Add VPN Profiles Step 1 – General Settings
          • Add VPN Profiles Step 2 – Authentication, Authorization, and Accounting
            • Add VPN Profiles Step 2 - SAML
            • Add VPN Profiles Step 2 - RADIUS
            • Add VPN Profiles Step 2 - Certificates
          • Add VPN Profiles Step 3 – Traffic Steering (Split Tunnel)
            • Step 3a – Traffic Steering (Split Tunnel)
            • Step 3b – Proxy and DNS Steering Settings
          • Add VPN Profiles Step 4 – Cisco Secure Client Configuration
        • Import ASA Device Configuration Files for Remote Access VPN
          • Import an ASA Configuration to Secure Access Remote Access VPN Profile
            • Download an ASA Configuration File with ASDM
            • Download an ASA Configuration File with CLI
            • Download the ASA XML File
          • Manage VPN Settings
            • Manage Manual Host Entries for VPN Profiles
          • Manage IP Blocking for Remote Access VPN
            • Automatic Threat Detection
            • Enable Automatic Threat Detection
            • Combined ACL Enforcement
            • Manual IP Blocking
            • Manually Block an IP Address or Subnet
            • Import Blocked IP Addresses from a CSV File
            • Remove a Manually Blocked IP Address or Subnet
          • Manage Machine Tunnels
            • Add a Machine Tunnel and Configure General Settings
              • Configure Authentication for Machine Certificate
              • Configure Traffic Steering (Split Tunnel)
              • Define the Cisco Secure Client Configuration
            • Authenticate Device Identity with Active Directory
              • Configure Active Directory Endpoint Device Management
            • Migrate AD User for Machine Tunnel to Identity Endpoint
      • Manage Machine Tunnels
        • Add a Machine Tunnel and Configure General Settings
          • Configure Authentication for Machine Certificate
          • Configure Traffic Steering (Split Tunnel)
          • Define the Cisco Secure Client Configuration
        • Authenticate Device Identity with Active Directory
          • Configure Active Directory Endpoint Device Management
        • Migrate AD User for Machine Tunnel to Identity Endpoint
      • Manage Application-Based Remote Access VPN (Per App VPN)
        • Manage Custom Attributes
          • About Cisco Secure Client on Mobile Devices
            • Guidelines and Limitations for Secure Client AnyConnect on Android
            • Guidelines and Limitations for Secure Client AnyConnect on Apple iOS
          • Define Custom Attributes
            • Define Per App VPN Custom Attributes
              • Step 1 - Determine the Application IDs for Mobile Applications
              • Step 2 - Create a Base64 Encoded String for Each Mobile Application
              • Step 3 - Create a Custom Attribute Object
            • Define Bypass Virtual Subnets Custom Attributes
            • Edit Cisco Secure Client Settings
      • Manage Secure Client Scripts
        • Guidelines and Limitations
        • Enable Secure Client Scripts
        • Upload Secure Client Scripts
      • Manage VPN Connection Posture Profiles
        • Add a VPN Connection Posture Profile
      • Manage Proxy Chaining
        • Forwarded-For (XFF) Configuration
    • Zero Trust Access
      • Manage Client-Based Zero Trust Access in Secure Access
        • What is ZTA and How Does it Compare to VPN?
        • Zero Trust Access Use Cases
        • Block HTTPS Pages with Zero Trust Access
        • Regional Static IP for Client-based ZTA for Edgev2
        • Zero Trust Access with Captive Portal Detection
        • Zero Trust Access Logs
        • Zero Trust Access Requirements and Limitations
        • Post Zero Trust Access Enrollment Action Items
      • Traffic Steering for Zero Trust Access Client-Based Connections
        • Best Practices
        • Limits: Zero Trust Traffic Steering Rules
        • Manage the DNS Steering Rule in a Zero Trust Access Profile
        • Add a Zero Trust Access Profile
        • Edit a Zero Trust Traffic Rule
        • Delete a Zero Trust Traffic Rule
        • Enable Client-Based Zero Trust Access to Destinations
        • Using Wildcards to Configure Traffic Steering for Private Destinations
          • Procedure for Configuring Traffic Steering for Private Destinations Using Wildcards
        • Addresses That Never Use Zero Trust Access
        • Zero Trust Access to Internet Destinations
          • Zero Trust Access to Internet Destinations Overview
        • Trusted Networks for Zero Trust Access Connections
          • Add a Trusted Network
        • Manage Threat Defense Devices for Universal Zero Trust Network Access
          • View Threat Defense devices configured for Universal Zero Trust Network Access
            • Procedure
          • Associate Private Resources with Threat Defense Devices
            • Associate Private Resources with Firewall Threat Defense
          • Assign a Trusted Network to Threat Defense devices
            • Procedure
      • Get Started With Network Location Objects for Zero Trust Access
        • Add a Network Location Object for ZTA
        • Edit a Network Location Object
        • Delete a Network Location Object
      • Manage User Trust Profile Zero Trust Access
        • Enable User Trust Profile
        • Bypass Untrusted User
      • Manage Zero Trust Access Posture Profiles
        • Add a Client-Based Zero Trust Access Posture Profile
        • Add a Browser-based Zero Trust Access Posture Profile
        • View a Browser-based Zero Trust Access Posture Profile
    • Endpoint Security
      • Manage Endpoint Security
        • Endpoint Posture Assessment
        • Endpoint Attributes
          • Supported Operating Systems
          • Firewall Conditions
          • Endpoint Security Agents
          • System Password Enforcement
          • Disk Encryption
          • Supported Browsers
          • Windows Registry Conditions
          • Windows Domain Join
          • File Conditions
          • Process Conditions
          • Certificate Conditions
        • View a Endpoint Posture
  • Security Protection and Enforcement
    • Virtual Appliances
      • Get Started with Virtual Appliances
        • Supported Deployments
        • How Secure Access Virtual Appliances Work
        • Virtual Appliances and Granular Identity Information
          • Without Virtual Appliances
          • With Virtual Appliances
        • Active Directory Integration
        • Configure Granular Rules
        • Prerequisites for Virtual Appliances
          • Endpoint Software
          • Virtual Appliance Requirements and Prerequisites
          • Networking Requirements
            • Allow Connections to Secure Access Domains and Services
            • Network Time Protocol Servers
            • Intrusion Protection Systems (IPS) and Deep Packet Inspection (DPI)
            • Network Address Translation (NAT)
          • Encrypting Traffic with DNSCrypt
        • Virtual Appliance Deployment Guidelines
          • Deploy Virtual Appliances in Pairs
          • Multiple DNS Egresses
          • Single DNS Egress
          • Double NAT
        • Virtual Appliance Sizing Guide
          • High-Traffic Sites and Virtual Appliances
          • AD Connector Sizing Guidelines
          • Deployment Considerations
            • Overall Latency
            • Number of Secure Access Sites
            • Number of Users for a VA
      • Manage VAs in Secure Access
        • Configure Authentication for Virtual Appliances
          • How to Set Up Your API Credentials
          • Procedure for Configuring Authentication for Virtual Appliances
            • Step 1 – Create the Key Admin API Key Credentials
            • Step 2 – Add the Key Admin API Key Credentials
          • Refresh Client API Key and Secret
          • Reset Client API Key
        • Manage DNS Forwarders
          • Procedure for Managing DNS Forwarders
            • View the DNS Forwarders
            • Sync the Configuration Settings to Deployed VAs
            • Edit a Site
            • Upgrade a Virtual Appliance
            • Reset Password
            • Delete a Virtual Appliance
        • Manage Site for Virtual Appliance
          • Procedure for Managing Site for Virtual Appliance
            • Add a Site
            • Select a Site
            • Rename a Site
            • Delete a Site
        • Configure Updates for Virtual Appliances
          • How Secure Access Updates Your Virtual Appliance
          • Procedure for Configuring Updates for Virtual Appliances
            • Configure Automatic Updates of Virtual Appliances
            • Manually Configure Update of a Virtual Appliance
            • Postpone Updates to Virtual Appliances
        • Configure Failover to Third-Party Resolvers
          • Enable Third-Party Resolver Failover
          • Verify the Current Resolver on the Virtual Appliance
      • Deploy Virtual Appliances
        • Deploy VAs in Hyper-V for Windows 2012 or Higher
          • Procedure for Deploying VAs in Hyper-V for Windows 2012 or Higher
            • Step 1 – Download and Extract the Hyper-V Installer
            • Step 2 – Import the Virtual Appliance
            • Step 3 – Copy and Rename Image Files
            • Step 4 – Select Network Adapter
            • Step 5 – Select Hard Drive
            • Step 6 – Power on the Virtual Machine
            • Step 7 – Repeat for the Second Virtual Appliance
        • Deploy VAs in VMware
          • Procedure for Deploying VAs in VMware
            • Step 1 – Download OVF Template
            • Step 2 – Deploy OVF Template
            • Step 3 – Deploy a Second Virtual Appliance
            • Step 4 – Power on the Virtual Machines
        • Deploy VAs in Microsoft Azure
          • Procedure for Deploying VAs in Microsoft Azure
            • Step 1 – Prepare the Virtual Appliance Image on Azure
            • Step 2 – Launch the Virtual Appliance on Azure
        • Deploy VAs in Amazon Web Services
          • Procedure for Deploying VAs in Amazon Web Services
            • Step 1 – Prepare the Virtual Appliance Amazon Machine Image
            • Step 2 – Launch the Virtual Appliance on Amazon Web Services
        • Deploy VAs in Google Cloud Platform
          • Procedure
            • Step 1 – Prepare the Virtual Appliance Instance Template on GCP
            • Step 2 – Launch the Virtual Appliance on Google Cloud Platform
        • Deploy VAs in KVM
          • Procedure for Deploying VAs in KVM
            • Step 1 – Download and Extract the KVM Installer
            • Step 2 – Launch the Virtual Appliance on KVM
        • Deploy VAs in Nutanix
        • Deploy VAs in Alibaba Cloud
          • Procedure
            • Download and Extract the Hyper-V Installer
            • Alibaba Cloud Setup
            • Create an Alibaba Virtual Private Cloud (VPC)
            • Create a Bucket for the Secure Access VAs
            • Configure a ZIP Package Decompression Rule
            • Upload the Secure Access VHD Images to the OSS Bucket
          • Create a Custom Image
          • Deploy the Secure Access VAs from the Imported Custom Image
            • What's Next
          • First-time Login to Secure Access VA
            • Related Topics
              • Dual-NIC Support on the VA
              • IP Addressing
              • Anycast Configuration Support
              • DNS Performance on Alibaba ECS Instances
              • Extensions on Alibaba ECS Instances
      • Configure Virtual Appliances
        • Enter Configuration Mode on a VA Deployed on VMware, Hyper-V, or KVM
        • Enter Configuration Mode on a VA Deployed in Azure, AWS, or Google Cloud Platform
        • Configure the VA Through Configuration Mode
        • Configure a Second VA
        • Configure Settings on VAs
          • Configure Rate Limiting
          • Configure NTP Servers
          • Configure Secure Access Resolvers
          • Configure DNSSEC Support
          • Configure Logging to Remote Syslog Server
            • Configure the Destination of the Remote Syslog Server
            • Configure Log Export Internal DNS
            • Configure Log Export Enable Health
            • Configure Log Export Enable Admin
            • Configure Log Export Enable All
            • Configure Log Export Status
            • Turn Off Logging
          • Configure Dual-NIC Support on the VA
            • Configure an Existing VA to Support Dual-NIC
            • Deploy a New VA to Support Dual-NIC DMZ Mode
          • Configure Anycast
            • Configure Anycast over BGP on the VA
            • Configure Load Balancing
            • Configure Identity Association Timeouts
            • Configure API Key Credentials for Authentication
              • Configure the Client ID and Client Secret
      • Local DNS Forwarding
        • Manage Domains in the VA
          • Which domains should be added?
          • (Optional) Add A and PTR Records for the VAs
        • Configure Local DNS Servers on the VA
          • Examples
      • Test Virtual Appliance Deployments
        • Resolve Public and Local DNS Queries
        • Test with Endpoints
        • Transition Production Traffic
      • SNMP Monitoring for Virtual Appliances
        • Enable SNMP Monitoring
          • Configure SNMP in Secure Access Virtual Appliance
          • SNMP Command Syntax
        • Standard OIDs Supported by the Virtual Appliance
        • Extended OIDs Supported by the Virtual Appliance
      • Troubleshoot Virtual Appliances
        • Use Configuration Mode to Troubleshoot
        • Troubleshoot Intermittent DNS Resolution Failures on a VA Deployed on Azure
        • Troubleshoot DNS Resolution in Configuration Mode
        • Troubleshoot DNS Resolution Failures Behind a Firewall
    • File Inspection and Analysis
      • Manage File Inspection and File Analysis
        • Overview of Configuring File Inspection and Analysis
        • File Inspection Details
          • Cisco Advanced Malware Protection (AMP)
          • Antivirus Scanner
        • Cisco Secure Malware Analytics (formerly Threat Grid) Details
          • Supported Files and File Limitations
          • Secure Malware Analytics Sandbox
      • Enable File Inspection
        • Prerequisites for Enable File Inspection
        • Procedure for Enable File Inspection
      • Enable File Analysis by Cisco Secure Malware Analytics
        • Prerequisites for Enable File Analysis by Cisco Secure Malware Analytics
        • Procedure for Enable File Analysis by Cisco Secure Malware Analytics
      • Test File Inspection for Internet Access
        • Block Page Diagnostic Information
      • Monitor File Inspection and Analysis Activity
        • Monitor and Review Secure Malware Analytics
          • Monitor File Submission Limits
      • Troubleshoot File Inspection and Analysis
    • File Type Controls
      • Manage File Type Controls
        • File Types to Block
      • Enable File Type Controls
        • Enable File Type Blocking for Internet Access
        • Enable File Type Blocking for Private Access
        • Review File Type Controls Through Reports
    • Notification Pages
      • Manage Notification Pages
        • View Notification Pages Displayed to End Users
        • About Warn Pages for Internet Access Traffic
        • Warn Page: Enter Key Word and Continue to Destination
        • Preview Notification Pages
        • System-Provided Notification Pages for Firewall and Secure Web Gateway
        • Create Custom Block and Warn Pages
          • Create Custom Block and Warn Pages
          • Link a Custom Notification Page Appearance to a Security Profile
        • Allow Users to Contact an Administrator
          • Procedure for Allowing Users to Contact an Administrator
        • Block Page IP Addresses
    • Data Loss Prevention
      • Manage the Data Loss Prevention Policy
        • Best Practices for the Data Loss Protection Policy
        • Supported File and Form Types
        • Understand Exclusions in a Real Time Rule
        • Supported Applications
      • Add a Real Time Rule to the Data Loss Prevention Policy
        • Create a DLP Real Time Rule Step 1 — Establish General Settings
        • Create a DLP Real Time Rule Step 2 — Select Data Classifications
        • Create a DLP Real Time Rule Step 3 — Select Files Controls
        • Create a DLP Real Time Rule Step 4 — Select Identities
        • Create a DLP Real Time Rule Step 5 — Select Destinations for Inclusion
        • Create a DLP Real Time Rule Step 6 — Select Destinations for Exclusion
        • Create a DLP Real Time Rule Step 7 — Select the Rule Action
        • Create a DLP Real Time Rule Step 8 — Disable/Enable Payload Transmission for DLP Violations (ICAP Only)
        • Create a DLP Real Time Rule Step 9 — Enable and Configure Pop-Up Notifications for Violations
        • Create a DLP Real Time Rule Step 10 — Enable and Configure Email Notifications for Violations
      • Add a SaaS API Rule to the Data Loss Prevention Policy
        • Create a DLP SaaS API Rule Step 1 — Establish General Settings
        • Create a DLP SaaS API Rule Step 2 — Select Data Classifications
        • Create a DLP SaaS API Rule Step 3 — Select Files Controls
        • Create a DLP SaaS API Rule Step 4 — Select Platform and Tenant
        • Create a DLP SaaS API Rule Step 5 — Select Users
        • Create a DLP SaaS API Rule Step 6 — Select Resource Labels
        • Create a DLP SaaS API Rule Step 7 — Select Resources
        • Create a DLP SaaS API Rule Step 8 — Configure Exposure Settings
        • Create a DLP SaaS API Rule Step 9 — Select Action
        • Create a DLP SaaS API Rule Step 10 — Enable and Configure Email Notifications
      • Add an AI Guardrails Rule to the Data Loss Prevention Policy
        • Create a DLP AI Guardrails Rule Step 1 — Establish General Settings
        • Create a DLP AI Guardrails Rule Step 2 — Select Data Classifications
        • Create a DLP AI Guardrails Rule Step 3 — Select Files Controls
        • Create a DLP AI Guardrails Rule Step 4 — Select Identities
        • Create a DLP AI Guardrails Rule Step 5 — Select Destinations
        • Create a DLP AI Guardrails Rule Step 6 — Select the Rule Action
        • Create a DLP AI Guardrails Rule Step 7 — Enable and Configure Pop-Up Notifications for Violations
        • Create a DLP AI Guardrails Rule Step 8 — Enable and Configure Email Notifications for Violations
      • Integrate Email Threat Defense with Secure Access DLP
      • Add an Email Rule to the Data Loss Prevention Policy
        • Create a DLP Email Rule Step 1 — Establish General Settings
        • Create a DLP Email Rule Step 2 — Select Data Classifications
        • Create a DLP Email Rule Step 3 — Select Files Controls
        • Create a DLP Email Rule Step 4 — Select the Senders
        • Create a DLP Email Rule Step 5 — Select the Recipients
        • Create a DLP Email Rule Step 6 — Select the Rule Action
        • Create a DLP Email Rule Step 7 — Enable and Configure Pop-Up Notifications for Violations
        • Create a DLP Email Rule Step 8 — Enable and Configure Email Notifications for Violations
      • Discovery Scan
        • Initiate a Discovery Scan
        • Cancel a Discovery Scan
      • Edit a Data Loss Prevention Rule
      • Delete a Data Loss Prevention Rule
      • Enable or Disable a Data Loss Prevention Rule
        • Disable a Rule
        • Enable a Rule
      • Manage Global Settings
    • Data Classifications
      • Manage Data Classifications
      • Create a Data Classification
        • Procedure for Creating a Data Classification
      • Copy and Customize a Built-In Data Classification
        • HIPAA Data Classification
        • Procedure for Copy and Customize a Built-In Data Classification
      • Delete or Edit a Classification
        • Delete a Classification
        • Edit a Classification
      • Exact Data Match Identifiers
        • Prerequisites for Exact Data Match Identifiers
        • Create an Exact Data Match Identifier
        • Index Data for an EDM
          • Prerequisites for Index Data for an EDM
          • Run the DLP Indexer to Create an EDM Identifier
          • Update the Indexed Data Set Periodically
          • Troubleshooting
        • Exact Data Match Field Types
          • Supported EDM Types
      • Indexed Document Match Identifiers
        • Limitations
        • Create an Indexed Document Match Identifier
        • Monitor the Indexed Data Set and Re-Index as Needed
        • Troubleshooting
      • Built-In Data Classifications
    • Built-in Data Identifiers
      • Built-in Data Identifiers
        • Tolerances
        • Copy and Customize a Data Identifier
        • Create a Custom Identifier
        • Custom Regular Expression Patterns
        • Individual Data Identifiers
    • AI Guardrails Data Classifications
      • AI Guardrails Data Classifications
    • Secure ICAP
      • Manage Secure ICAP
        • Secure ICAP Integration
        • Modify an ICAP Server Connection
        • Disconnect from an ICAP Server
    • Requirements for Salesforce Tenants
      • Requirements for Salesforce Tenants for Cloud Malware and SaaS API DLP
        • Salesforce sObjects Supported for SaaS API DLP
        • Install or Update Node.js
        • Install the Salesforce CLI
        • Deploy the Salesforce Quarantine Package to your Salesforce Tenant
        • Log In to Your Salesforce Org
        • Set Permissions in Salesforce
    • SaaS API Data Loss Prevention
      • Manage SaaS API Data Loss Prevention
      • Enable SaaS API Data Loss Prevention for AWS Tenants
        • Enable CloudTrail Event Logging for S3 Buckets and Objects
        • Obtain Your AWS Account ID
        • Authorize an AWS Tenant
        • Create an AWS Stack
        • Revoke Authorization
      • Enable SaaS API Data Loss Prevention for Azure Tenants
        • Authorize an Azure Tenant
        • Run an Azure PowerShell Script to Obtain Account Information
        • Revoke Authorization
      • Enable SaaS API Data Loss Prevention for Box Tenants
        • Authorize a Tenant
        • Revoke Authorization
      • Enable SaaS API Data Loss Prevention for Confluence Tenants
      • Enable SaaS API Data Loss Prevention for Dropbox Tenants
        • Authorize a Tenant
        • Revoke Authorization
      • Enable SaaS API Data Loss Prevention for GitHub Tenants
        • Authorize a Tenant
        • Install the GitHub connector
        • Validation
        • Revoke Authorization
      • Enable SaaS API Data Loss Prevention for Google Drive Tenants
        • Validation
        • Authorize a Tenant
        • Revoke Authorization
      • Enable SaaS API Data Loss Prevention for Jira Tenants
      • Enable SaaS API Data Loss Prevention for Microsoft 365 Tenants
        • Prerequisites for Enable SaaS API Data Loss Prevention for Microsoft 365 Tenants
        • Authorize a Microsoft 365 Tenant
        • Revoke Authorization
      • Enable SaaS API Data Loss Prevention for Salesforce Tenants
      • Enable SaaS API Data Loss Prevention for Salesforce Commerce Tenants
      • Enable SaaS API Data Loss Prevention for ServiceNow Tenants
        • Find the Instance Name for your ServiceNow admin Account
        • Assign the oauth_user role to the ServiceNow admin Account
        • Add an OAuth Client to Your ServiceNow Deployment
        • Authorize a Tenant
        • Revoke Authorization
        • View the Cisco Quarantine Table in Service Now
      • Enable SaaS API Data Loss Prevention for Slack Tenants
        • Authorize a Tenant
        • Revoke Authorization
      • Enable SaaS API Data Loss Prevention for Webex Teams
        • Authorize a Tenant
        • Revoke Authorization
    • Cloud Malware Protection
      • Manage Cloud Malware Protection
      • Cloud Access Security Broker Protection for Google Drive and Microsoft 365
      • Enable Cloud Malware Protection
      • Revoke Authorization for a Platform
      • Enable Cloud Malware Protection for AWS Tenants
        • Enable CloudTrail Event Logging for S3 Buckets and Objects
        • Obtain Your AWS Account ID
        • Authorize an AWS Tenant
        • Create an AWS Stack
        • Revoke Authorization
      • Enable Cloud Malware Protection for Azure Tenants
        • Authorize an Azure Tenant
        • Run an Azure PowerShell Script to Obtain Account Information
        • Revoke Authorization
      • Enable Cloud Malware Protection for Box Tenants
        • Verify Box Application Settings
        • Authorize a Tenant
        • Edit a Tenant
        • Revoke Authorization
      • Enable Cloud Malware Protection for Confluence Tenants
      • Enable Cloud Malware Protection for Dropbox Tenants
        • Authorize a Tenant
        • Edit a Tenant
        • Revoke Authorization
      • Enable Cloud Malware Protection for GitHub
        • Authorize a Tenant
        • Revoke Authorization
      • Enable Cloud Access Security Broker Features for Google Drive
        • Authorize a Tenant
        • Edit a Tenant
        • Revoke Authorization
      • Enable Cloud Malware Protection for Jira Tenants
      • Enable Cloud Access Security Broker Protection for Microsoft 365 Tenants
        • Prerequisites for Enable Cloud Access Security Broker Protection for Microsoft 365 Tenants
        • Authorize a Tenant
        • Edit a Tenant
        • Revoke Authorization
      • Enable Cloud Malware Protection for Salesforce Tenants
        • Edit a Salesforce Cloud Malware Tenant
      • Enable Cloud Malware Protection for ServiceNow Tenants
        • Find the Instance Name for your ServiceNow admin Account
        • Assign the oauth_user role to the ServiceNow admin Account
        • Add an OAuth Client to Your ServiceNow Deployment
        • Authorize a Tenant
        • Edit a Tenant
        • Revoke Authorization
        • View the Cisco Quarantine Table in Service Now
      • Enable Cloud Malware Protection for Slack Tenants
        • Authorize a Tenant
        • Edit a Tenant
        • Revoke Authorization
      • Enable Cloud Malware Protection for Webex Teams
        • Authorize a Tenant
        • Revoke Authorization
    • Remote Browser Isolation
      • Get Started with Remote Browser Isolation
      • Manage Remote Browser Isolation Profiles
        • System Default Profile
        • Create a Remote Browser Isolation Profile
        • Edit or Delete a Remote Browser Isolation Profile
      • Remote Browser Isolation Advanced Isolation Controls Reference
        • Watermarking
        • Copy, Paste and Keyboard Control
        • Document Isolation
        • File Transfers
    • Internet Security
      • Manage Internet Security
        • Set Up Internet Security on User Devices
          • Procedure for Setting Up Internet Security on User Devices
            • Download the OrgInfo.json File
            • Copy the PAC File URL
        • Manage Internet Security Bypass
          • Add Destinations for Internet Security Bypass
          • View Destinations for Internet Security Bypass
          • Edit Destination for Internet Security Bypass
          • Delete Destinations for Internet Security Bypass
        • Configure Cisco Secure Client Settings
          • Procedure
          • Configure Security Settings
            • Configure DNS and Web Security
          • Configure Advanced Security Settings
            • Use Active Directory for Access Policy
            • Third Party VPN Compatibility
            • DNS Protection
            • Alternate Resolver IPs
            • DNS Backoff Settings
            • Secure Web Gateway Backoff Settings
    • PAC Files
      • Manage PAC Files
        • Requirements for Downloading PAC Files to User Devices
        • About Using the Secure Client with PAC Files
        • Managing PAC File Deployments
        • Deploy the Secure Access PAC File for Windows
          • Copy URL for Default PAC File or Custom PAC File
            • Copy URL for the the Secure Access PAC File
            • Copy URL for Custom PAC File
          • Procedure for Deploying Secure Access PAC File URL
            • Deploy the Secure Access PAC File URL for Chrome and Edge Browsers
            • Deploy the Secure Access PAC File URL for Firefox
        • Deploy the Secure Access PAC File for macOS
          • Copy URL for Default PAC File or Custom PAC File
            • Copy URL for Secure Access PAC File
            • Copy URL for Custom PAC File
          • Procedure
            • Deploy the Secure Access PAC File URL to Chrome
            • Deploy the Secure Access PAC File URL to Firefox
            • Deploy the Secure Access PAC File URL to Safari
        • Customize the Secure Access PAC File
          • Procedure for Customizing the Secure Access PAC File
            • Copy the Secure Access PAC File
            • Download the Secure Access PAC File
            • Edit the PAC File
        • Upload Custom PAC Files to Secure Access
        • Manage Uploaded Custom PAC Files
    • Certificates
      • Manage Certificates
        • Certificate Installation Methods
      • Certificates for Internet Decryption
        • Certificates for Decrypting Internet Traffic
          • Option 1: Distribute Self-Signed Certificates to End-User Devices
          • Option 2: Use a Signed Certificate for Decrypting Internet Traffic
      • Manage Certificates for Private Resource Decryption
        • Install a Certificate Authority Certificate on a Private Resource
        • Upload Private Resource Certificates
        • View Notifications About Expired Private Resource Certificates
        • View, Delete, or Replace a Private Resource Certificate
      • Install the Cisco Secure Access Root Certificate
        • Download the Cisco Secure Access Root Certificate
        • Automatically Install the Cisco Secure Access Root Certificate (For an Active Directory Network)
          • Install the Cisco Secure Access Root Certificate with Group Policy Using the Microsoft Management Console (MMC)
          • Install the Cisco Secure Access Root Certificate with Group Policy Using the Group Policy Management Console (GPMC)
        • Install the Cisco Secure Access Root Certificate in Firefox Using Group Policy
        • Install the Cisco Secure Access Root Certificate on Chromebooks Using the Google Admin Console
        • Manually Install the Cisco Secure Access Root Certificate (Single Computer)
          • Install the Cisco Secure Access Root Certificate in Edge or Chrome on Windows
          • Install the Cisco Secure Access Root Certificate in Firefox on Windows
          • Install the Cisco Secure Access Root Certificate in All Browsers on Mac OS X
          • Install the Cisco Secure Access Root Certificate on Mac OS X Through the Command Line
          • Install the Cisco Secure Access Root Certificate in Chromium or Chrome on Linux
      • Add Custom CA Signed Root Certificate
        • Certificate Requirements
        • Install Root Certificate in Browsers
        • Adding a Custom CA Signed Root Certificate
        • Renew the Custom CA Signed Root Certificate
      • View the Cisco Trusted Root Store
        • Extract the Certificates
        • View an Individual Certificate File
      • Certificates for SAML Authentication
        • Manage SAML Certificates for Service Providers
          • View Notifications About Expired Service Provider Certificates
          • Download Web Security and Zero Trust Service Provider Certificates
          • Download Virtual Private Network Service Provider Certificates
        • Manage SAML VPN Service Provider Certificate Rotation
          • View Notifications About Expired Service Provider Certificates
          • Activate a New VPN Service Provider Certificate
        • Manage SAML Certificates for Identity Providers
      • VPN Certificates for User and Device Authentication
      • Manage CA Certificates for VPN Connections and Zero Trust Access Enrollment
        • View Notifications About Expired CA Certificates for Client Authentication
        • Upload Certificate Authority (CA) Certificates for client authentication
        • View Uploaded CA Certificates
        • Manage Certificate Revocation Settings
        • View CA Certificate Details
        • Change the Purpose of an Uploaded CA Certificate
        • Delete a Client Authentication CA Certificate
    • Secure Access Investigate
      • Manage Secure Access Investigate
        • Getting Started with Investigate
          • Smart Search
          • Smart Search Best Practices
          • Pattern Search
          • Conduct a Pattern Search
            • About Pattern Search
              • Procedure
            • RegEx Examples
        • About Passive DNS
        • About Investigate View Types
      • About the Investigate Domain Summary
        • Domain Summary Details
        • Investigate Domain Risk Score
        • Keyword Score
        • Lexical Score
        • TLD Score
        • Geo Popularity
        • About Investigate Passive DNS Timeline
        • Dispute Content Categorization
        • About DNS Resolution in Investigate
        • About Associated Samples in Investigate
        • About the Subdomains Tab in Investigate
        • About Related Domains in Investigate
        • About the Geographic Distribution View in Investigate
        • About the Sample View in Investigate
        • About the IP Address View in Investigate
      • About WHOIS Record Information
        • About the WHOIS Nameserver View
        • FAQs
      • About the ASN View
        • Current Information
        • Current Routes
        • Research AS From IP Address View
  • Mobile Device Management
    • Client-based Zero Trust Access from Mobile Devices
      • Get Started and Manage Client-based Zero Trust Access from Mobile Devices
      • Set up the Zero Trust Access App for iOS Devices
        • Guidelines and Limitations
        • Configure iOS Settings
        • Install the App
        • Have End Users Enroll in Zero Trust Access
        • Notes for administrators
      • Set up the Zero Trust Access App for Android Devices
        • Configure Cisco Secure Access
        • Install the App
        • Notes for administrators
      • Set up the Zero Trust Access App for Android on Samsung Devices
        • Configure Android Settings in Secure Access
        • Install the App
        • (Optional) Set up the Android device for Zero Trust Access using MDM
          • Add the app to MDM
          • Set up the App on the Samsung Device
        • Enroll the Device in Zero Trust Access
        • Notes for administrators
      • Monitor and Troubleshoot the Zero Trust Access App from Mobile Devices
        • Troubleshoot iOS Devices
        • Troubleshoot Samsung Devices Running Android OS
        • Troubleshoot access issues
    • Cisco Secure Client on Windows, macOS, and Linux Devices
      • Get Started with Cisco Secure Client on Windows, macOS, and Linux Devices
      • Windows, macOS, and Linux Device Prerequisites
      • Download and Install Cisco Secure Client
        • ThousandEyes Endpoint Agent Module
      • Download the OrgInfo.json File
      • Manual Installation of Cisco Secure Client (Windows and macOS)
      • Mass Deployment Overview
        • Customization Options
      • Mass Deployment (Windows)
      • Customize Windows Installation of Cisco Secure Client
        • (Optional) OrgInfo.json Parameter Configurations
      • Mass Deployment (macOS)
      • Customize macOS Installation of Cisco Secure Client
        • Step 1 – Make the .dmg Package Writeable
        • Step 2 – Generate the Module Installation Configuration File
        • Step 3 – Copy OrgInfo.json to Cisco Secure Client Installation Directory
        • Step 4 – (Optional) Hide the VPN Module
        • Step 5 – Customize the Cisco Secure Client Installation Modules
        • Sample Customization
        • Step 6 – Set Up the Correct Extension Permission Settings
        • Step 7 – Install Secure Client with Selected Modules
      • Optional OrgInfo.json Parameter Configurations
      • VPN Headend Deployment
      • Secure Firewall Management Center and Secure Firewall Threat Defense
        • Procedure to enable Secure Client Secure Access Module in Management Center and Threat Defense
        • (OPTIONAL) VPN Local Authentication (Management Center 7.0 or later required)
      • Meraki Systems Manager (SM) Deployment
      • Migration from Secure Access Roaming Client
      • Install the Root Certificate for All Browsers
      • Cloud Management
        • Deploying Cisco Secure Client
        • Uploading the Orginfo.json profile
        • Create a Deployment
        • Post Deployment
      • Additional References
      • Manage Device Deployment
        • Prerequisites for Device Deployment Management
        • Add and Activate Deployment Key
        • Manage Deployment Key Compromise
        • Delete a Deployment Key
        • Reverting to Using Legacy Deployment Implementation
        • Backward Compatibility
    • Zero Trust Access using Cisco Secure Client
      • Manage Zero Trust Access using Cisco Secure Client
        • Enroll Devices in Zero Trust Access Using Certificates
          • Step 1 - Upload or choose a CA certificate
          • Step 2 - Download the enrollment configuration file
          • Step 3 - Install the enrollment configuration file on user devices
        • Enroll Devices in Zero Trust Access Using SSO Authentication Overview
          • Enroll Devices in Zero Trust Access Using SSO Authentication
        • Troubleshoot Client-Based Zero Trust Access
          • Pre-Enrollment Errors
          • Enrollment Errors
          • Post-Enrollment Errors
          • Requests to Reauthenticate
        • Unenroll a Device from Zero Trust Access
          • Unenroll from the user endpoint device (for enrollments using SSO Authentication only)
    • Endpoint Data Loss Prevention using Ciso Secure Client
      • Manage Endpoint Data Loss Prevention Using Cisco Secure Client for Windows, Mac and Linux
        • Prerequisites for Endpoint Data Loss Prevention
        • Enroll Devices in Endpoint Data Loss Prevention Using Certificates
          • Step 1 - Upload or Choose a CA Certificate
          • Step 2 - Centralized Deployment and Management of Endpoint Data Loss Prevention
          • Step 3 - Download the Enrollment Choice File
          • Step 4 - Install the User Certificate and Enrollment Choice File on User Devices for Windows
          • Step 4 - Install the User Certificate and Enrollment Choice File on User Devices for macOS
          • Step 4 - Install the User Certificate and Enrollment Choice File on User Devices for Linux
      • Troubleshoot Endpoint Data Loss Prevention for Windows
        • Pre-enrollment Errors
        • Enrollment Errors
        • Post-enrollment Errors
      • Troubleshoot Endpoint Data Loss Prevention for Mac
        • Extract and Stream Logs for Cisco Secure Client - Endpoint DLP on macOS
        • Logging with the Console Application
      • Troubleshoot Endpoint Data Loss Prevention for Linux
      • Deploying Cisco Secure Client – Endpoint DLP on macOS using a generic MDM
      • Grant Required Privacy Permissions Using MDM
      • Uninstall Cisco Secure Client - Endpoint DLP on macOS
      • Uninstall Cisco Secure Client - Endpoint DLP on Linux
    • Virtual Private Networks on Cisco Secure Client
      • Manage Virtual Private Networks on Cisco Secure Client
        • Prerequisites
        • Download the Virtual Private Network XML Profile
        • CA Certificates for VPN Connections
    • Internet Security on Cisco Secure Client
      • Manage Internet Security on Cisco Secure Client
        • Umbrella Roaming Security Module Requirements
          • System Requirements
          • Network Requirements
          • Transport Layer Security Protocol
          • Network Access
          • Roaming Security DNS Requirements
          • Internal Domains
        • Domain Management
          • Internal Domains List
          • DNS Suffixes
          • Operational Flow
          • Advanced Topics
      • Interpret Internet Security Diagnostics
        • Procedure
          • Generate the Diagnostic Report from the Cisco Secure Client
          • Generate the Diagnostic Report on the Command Line
      • DNS Protection Status
        • View DNS Protection Status
      • SWG Protection Status
        • View SWG Protection Status
    • Endpoint Diagnostic Tool
      • Cisco Endpoint Diagnostic Tool
        • Cisco Endpoint Diagnostic Tool
    • Managed iOS
      • Cisco Security Connector: Secure Access Setup Guide
        • Requirements
          • Optionally
        • Getting Started
        • Quick Start
          • 1. Install the Cisco Security Connector App
          • 2. Add an Organization Administrator's Email Address
          • 3. Register Your iOS Device Through Your MDM to Secure Access
          • Unregister a Mobile Device
        • Manage Device Deployment
          • Add and Activate Deployment Key
          • Manage Deployment Key Compromise
          • Delete a Deployment Key
          • Reverting to Using Legacy Deployment Implementation
          • Backward Compatibility
      • Meraki Registration
        • Anonymization
        • Register with Meraki
          • Verify Push of Profile Config
          • Anonymize Your Device
          • Verify Secure Access on Your Device
        • Verify Secure Access with Meraki
          • Procedure
            • Verify Local Operation on the iOS Device
            • Verify Secure Access
            • Verify Clarity
            • Upgrade the Cisco Security Connector
            • Uninstall the Cisco Security Connector
        • Meraki Documentation
      • Register an iOS Device Through Apple Configurator 2
        • Procedure for Registering an iOS Device Through Apple Configuration 2
        • Verify Secure Access on Your Device
      • IBM MaaS360 Registration
        • Procedure for Registering IBM MaaS360 MDM Solution
        • Verify Secure Access on Your iOS Device
      • Intune Registration
        • Procedure for Registering Intune MDM Solution
        • Verify Secure Access on Your iOS Device
      • Jamf Registration
        • Procedure for Registering Jamf MDM Solution
        • Anonymization
        • Verify Secure Access on Your iOS Device
      • MobileIron Registration
        • Procedure for Registering MobileIron MDM Solution
        • Verify Secure Access on Your iOS device
        • MobileIron Configuration
          • MobileIron Cloud Configuration
          • MobileIron On-Prem Configuration
      • MobiConnect Registration
        • Procedure for Registering MobiConnect MDM Solution
        • Verify Secure Access on Your iOS Device
      • Workspace ONE Registration
        • Procedure
        • Verify Secure Access on Your iOS Device
      • Register an iOS Device Through a Generic MDM System
        • Register the iOS Device Through a Generic MDM System
        • Verify That Your Device is Protected by Secure Access
      • Apply an Access Policy to Your Mobile Device
      • Add User Identity for Cisco Security Connector
        • Test Integration of User Identity With Cisco Security Connector
      • Anonymize Devices
      • Export Device Data to CSV
        • Procedure
        • DNS Protection Status in Exported Reports
        • SWG Protection Status in Exported Reports
      • Push the Cisco Root Certificate to Managed Devices
      • Configure Cellular and Wifi Domains
      • Configuring DNS Suffix Allow List
      • Troubleshooting
        • Generate Diagnostics and Email the Secure Access Reports
        • Generate Diagnostics and Share the Secure Access Reports
    • Managed Android
      • Secure Access Module for Cisco Secure Client (Android OS)
        • Device Security
        • Prerequisites
      • Deploy the Android Client
        • Android Configuration Download
          • Procedure
            • Fail Close/Open Scenario
        • Manage Device Deployment
          • Add and Activate Deployment Key
          • Manage Deployment Key Compromise
          • Delete a Deployment Key
          • Reverting to Using Legacy Deployment Implementation
          • Backward Compatibility
        • Cisco Meraki MDM
          • Add App to Cisco Meraki
          • Add Configuration for App
          • Push the App to Devices
          • Push the Cisco Root Certificate
        • MobileIron MDM
          • Configure the App
          • Push the App
          • Push User Identities
          • Push the Cisco Root Certificate
        • VMware Workspace ONE
          • Create Always On VPN Profile
          • Add and Publish the Cisco Secure Client Application
        • Microsoft Intune MDM
          • Publish the Cisco Secure Client - AnyConnect App to Managed Android Devices
          • Configure Secure Access
          • Push User Identities
          • Push the Cisco Root Certificate
        • Samsung Knox MDM
          • Enroll Android Devices
          • Push the App
          • Set Managed Configuration
          • Create Profile in Knox Manage
          • Push User Identities
          • Push the Cisco Root Certificate
        • Push the Cisco Root Certificate to Devices
          • Procedure
      • Manage Identities
        • Cisco Meraki Systems Manager
        • Microsoft Intune
        • Samsung Knox
        • VMWare WorkspaceOne
        • Access User Identities on the Secure Access Dashboard
      • Export Device Data to CSV
        • Procedure
        • DNS Protection Status in Exported Reports
        • SWG Protection Status in Exported Reports
      • Troubleshooting
        • Known Issues
        • First Launch of App
        • Is this a VPN to Secure Access?
        • An Internal Site Isn't Loading
        • Configuration Issues
        • Check for VPN Connection and Policy
        • Check Block Page
        • Get the Android ID
        • Fail Close/Open Scenario
        • Check Device Registration
        • Missing CA Certificate
        • Org ID on Policy Page is 0
        • App Installation is Blocked
        • Offboarding Users
      • Frequently Asked Questions about Managed Android
    • Unmanaged Mobile Devices
      • Unmanaged Mobile Device Protection
        • Administrator Actions
          • Enrolling Unmanaged Mobile Devices
        • End-user Actions
          • Android
            • Registration and Activation
          • iOS
            • Registration and Activation
  • Monitor and Report
    • Experience Insights
      • About Experience Insights
      • Onboard Experience Insights
      • Cisco AI Assistant for Experience Insights
        • How to Use the Cisco AI Assistant in Experience Insights
        • Prompt examples
        • Contextual Conversations
      • ThousandEyes Account Management in Experience Insights
        • Edit Default Test Target
        • Register ThousandEyes Agents
          • Automatic Registration of ThousandEyes Endpoint Agents
          • Manual Registration of ThousandEyes Endpoint Agents
      • Experience Insights Overview
      • Endpoints
      • Wi-Fi Descriptions
      • Experience Score
      • View SaaS Application Performance
      • View User Dashboard
        • View the User Dashboard
      • Configure Identity Providers for Experience Insights
      • About Endpoint Agent Tests
        • Manage endpoint tests in Secure Access
          • Endpoint license usage
          • Endpoint tests
          • Default Endpoint tests
        • Manage endpoint agents and tests in ThousandEyes
        • Limitations
        • Estimate Peak Traffic to Custom Targets for Default Endpoint Tests
          • Calculate Estimated Peak Throughput of Test Traffic
          • Mitigation Strategies
          • Recovery Options
        • Create HTTP Server Tests
          • Procedure
        • Create Network Tests
          • Procedure
        • View HTTP server test results
        • View Network Test Results
    • Logging
      • Manage Logging
        • Enable Logging on a Rule in Access Policy
        • Enable Logging to Your Own S3 Bucket
          • Configure Your Own S3 Bucket
          • Integrate AWS S3 Bucket with Splunk App
          • Download Files Locally From the S3 Bucket
        • Enable Logging of DLP Violation Evidence to Your Own S3 Bucket
          • Configure IAM Policy for S3 Bucket
          • Configure Your Own S3 Bucket
          • Integrate AWS S3 Bucket with Splunk App
          • Download Files Locally From the S3 Bucket
          • Troubleshooting
        • Enable Logging to a Cisco-Managed S3 Bucket
          • Best Practices for Rotating an S3 Bucket Key
          • Configure a Cisco-Managed S3 Bucket
          • Rotate Keys on a Cisco-Managed S3 Bucket
          • Get the S3 Bucket Data Path
          • Verify Your Access to an S3 Bucket
          • Download Files Locally From the Cisco-Managed S3 Bucket
          • Migrate From Cisco S3 Bucket to Your Own S3 Bucket
        • Change the Location of Event Data Logs
        • Log export failures to Amazon S3
        • Stop Logging
        • Delete Logs
      • Log Formats and Versioning
        • Log File Name Formats
          • Find Your Log Schema Version
            • View Your Log Schema Version and Last Sync Time
          • Include Headers
          • Log File Fields
          • Estimate the Size of a Log
          • Estimate the Size of an Exported Report
        • Reports and CSV Formats
          • Activity Search Report
            • Zero Trust Access Activity Search Fields
          • Top Categories Report
          • Top Destinations Report
          • Top Resources Report
        • Admin Audit Log Formats
        • Cloud Firewall Log Formats
        • Data Loss Prevention (DLP) Log Formats
        • DNS Log Formats
        • File Events Log Formats
        • IPS Log Formats
        • Network Connectivity Log Formats
        • Remote Access VPN Log Formats
        • Web Log Formats
        • Zero Trust Access Log Formats
        • Zero Trust Access Flow Log Formats
        • Zero Trust Access Enrollment Log Formats
    • Monitor with Alert Rules
      • Monitor Secure Access with Alert Rules
        • Manage Alert Rules
        • Add and Edit Alert Rules for API Anomalies
        • Add and Edit Alert Rules for Changes on Access Rules
        • Add and Edit Alert Rules for Behavior Analytics
        • Add and Edit Alert Rules for Tunnel Connectivity
        • Add and Edit User Access Alerts
        • Manage Alert Rules for Destination Lists
        • Monitor Alerts from Secure Access
        • Splunk Integration: Configure Alert Rules for Access Policy Changes
        • ServiceNow Integration: Configure Alert Rules for Access Policy Changes
    • Monitor with Reports
      • Monitor Secure Access with Reports
        • Available Reports
        • Export Report Data to CSV
        • Bookmark and Share Reports
      • Report Scheduling
        • Schedule a Report
        • Update a Scheduled Report
      • Report Search Window and Retention
        • Report Search Window
        • Report Retention
      • Assess and Monitor Configurations in Secure Access
    • Activity Reports
      • Activity Search Report
        • View and Customize the Activity Search Report
          • View the Activity Search Report
          • Customize the Activity Search Report
          • Save Activity Search Report columns and filters for future use
          • Customize and Manage Saved Searches
          • View an Access Policy Rule from the Activity Search Report
        • View Firewall Events in Activity Search Report
          • Filter the Report by Firewall Requests
        • View Web Events in Activity Search Report
          • Filter the Report by Web Requests
        • View Zero Trust Events in Activity Search Report
          • Procedure
            • Event Details
            • Access Details
            • Block Details
            • Endpoint Details
        • View AI Semantic Inspection Events in Activity Search Report
          • Filter the Report by Semantic Inspection for MCP Servers
        • View Activity Search Report Actions
          • See Full Details
            • View Isolated Event Details
          • Filter Views
        • Schedule an Activity Search Report
        • Use Search and Advanced Search
          • Search
          • Wildcards
            • Domains
            • URLs
            • File Names
          • Advanced Search
          • Inline Column Filtering
      • Security Activity Report
        • View Activity and Details by Filters
          • Procedure
        • View Activity and Details by Event Type or Security Category
          • Procedure
            • Group Security Categories
        • View an Event's Details
          • Procedure
        • Search for Security Activity
          • Prerequisites
          • Procedure
            • Advanced Search
      • Activity Volume Report
        • View Requests by Volume of Activity
        • View Activity Volume by Threat Categories
          • Prevent
          • Contain
        • View Activity Volume by Policy Traffic
        • View Trends
    • Admin Audit Log Report
      • Admin Audit Log Report
        • Generate Admin Audit Log Report
        • Export Admin Audit Log Report to an S3 Bucket
          • Procedure
    • AI Related Reports
      • AI Supply Chain Report
      • AI Semantic Inspection Report
        • View AI Semantic Inspection Report
    • App Related Reports
      • App Discovery Report
        • View the App Discovery Report
          • View the App Discovery Report
        • View the Highest Risk Apps
          • Procedure
        • Review Apps in the Apps Grid
          • Procedure
          • Configure Columns to Display
          • Change the Label of an App
        • View App Details
          • Procedure
        • Change App Details
          • Change the Risk Score for an App
          • Change the Label of an App
        • Control Apps
          • Procedure
          • Control Application Lists
        • Control Advanced Apps
          • Procedure
        • View Traffic Data Through SWG Service
          • View Traffic
          • View Traffic in the Apps Grid
          • View Traffic in the App Details
      • Third-Party Apps Report
        • View the Third-Party Apps Report
        • Search the Third-Party Apps Report
        • Export the Third-Party Apps Report
        • View App Details
          • Procedure
    • Cloud Malware Report
      • Cloud Malware Report
        • View the Cloud Malware Report
        • Use the Cloud Malware Report
          • View Detailed Information About a File
          • Quarantine a Malicious File
          • Restore a Quarantined File
          • Delete a Malicious File
          • Dismiss an Item from the Report
          • Export a Cloud Malware Report
    • Data Loss Prevention Report
      • Data Loss Prevention Report
        • View Events
          • View Event Details
          • Delete File
          • Quarantine File
          • Restore File from Quarantine
          • Use Advanced Search
        • Discovery
          • View a Discovery Scan
    • Data Security Posture Management Report
      • Data Security Posture Management
        • Overview
        • Data Catalogue
        • Insights
        • Analytics
    • Events Report
      • Events Report
        • Key Features of Events Report
        • View Events Report
        • Event Type Specific Details
        • Schedule an Events Report
        • Saving a Search in the Events Report
        • Customize and Manage Saved Searches
        • Filter Events Using Basic Search Options
        • Filter Events Using Advanced Search
        • Known Limitations
          • Data Retrieval Limit (10,000 Offset)
          • Understanding Data Availability (Missing Fields)
          • Protocol-Specific Correlation Behaviors
          • Known Issues and Ongoing Enhancements
    • Network Connectivity Log
      • Network Connectivity Log
        • Schedule a Network Connectivity Log Report
    • Network Tunnel Group Usage Report
      • Network Tunnel Group Usage
        • View Top Network Tunnel Groups by Traffic
    • Remote Access Log Report
      • About the Remote Access Log Report
        • View the Remote Access Log Report
          • View Event Details
        • View Zero Trust Access Events in the Remote Access Log
          • View Zero Trust Access Enrollment Logging Event Details
        • Schedule a Remote Access Log Report
    • Top Categories Report
      • Top Categories Report
        • View the Top Categories Report
        • Top Categories Quick View
        • View Category in Other Reports
        • Category Details
          • View a Category's Details Overview
          • View a Category's Traffic
            • View the Activity Breakdown
            • View the Traffic Bandwidth
          • View a Category's Identities
          • View the Category's Top Domains
    • Top Destinations Report
      • Top Destinations Report
        • View the Top Destinations Report
        • View Further Details
        • Destination Details
          • View the Destination Details
          • View the Request Traffic
            • View Requests by Blocked or Allowed
            • View Requests Through Global Traffic %
          • View the Access and Policy Details
          • View Recent Activity
          • View the Most Visited URL Paths
    • Total Requests Report
      • Total Requests Report
        • View Trends in the Total Requests Report
  • Integrations
    • Secure Access Integrations
      • Manage Third-Party Integrations
        • Additional Secure Access Integration Guides
      • Chrome Enterprise Browser
        • Configure the Chrome Enterprise Browser Third-Party Integration
      • Microsoft Intune Third-Party Integration
        • Configure the Microsoft Intune Third-Party Integration
      • Jamf Pro Third-Party Integration
        • Configure the Jamf Pro Third-Party Integration
      • Push Security Events Third-Party Integration
        • Add Third-Party Integrations for Push Security Events
        • View Third-Party Integrations for Push Security Events
        • Edit a Third-Party Integration for Push Security Events
        • Delete a Third-Party Integration for Push Security Events
        • Splunk Integration: Configure Push Security Events
        • ServiceNow Integration: Configure Push Security Events
      • Microsoft Edge for Business Third-Party Integration
        • Add Third-Party Integration for Microsoft Edge for Business
        • View Third-Party Integration for Microsoft Edge for Business
        • Edit a Third-Party Integration for Microsoft Edge for Business
      • Island Enterprise Browser Third Party Integration
        • Add a Third-Party Integration for Island Enterprise Browser
        • Edit a Third-Party Integration for Island Enterprise Browser
        • Delete a Third-Party Integration for Island Enterprise Browser
      • Threat Intelligence Feeds
        • Add Third-Party Integrations for Threat Intelligence Feeds
        • View Integrated Threat Intelligence Feeds
        • Edit or Delete a Threat Intelligence Feed
      • Manage Webhooks for Third-Party Integrations
        • Add a Webhook for a Third-Party Integration
        • View Details for Webhooks
        • Edit a Webhook for a Third-Party Integration
        • Delete a Webhook for a Third-Party Integration
      • Integrate ISE (Identity Services Engine) with Secure Access
        • Solution Overview
        • Security Group Tags
        • Components and Prerequisites
        • Solution Workflow
        • Connect Cisco ISE and Cisco pxGrid Cloud
          • Cisco pxGrid Cloud Terminology
          • Cisco pxGrid Cloud and Cisco ISE Integration Workflows
        • Enable Cisco Security Cloud Exchange
        • Integrate Cisco ISE with Secure Access
        • Verify and Monitor Context Sharing
          • Verify Context Sharing in Secure Access
          • Activity Search in Secure Access
      • Integrate Catalyst SD-WAN with Secure Access
        • Solution Overview
        • Components and Prerequisites
        • Solution Workflow
          • Related Information
        • Configure Context Sharing Between Catalyst SD-WAN and Secure Access
          • Generate API Key Pair for Context Sharing
          • Create Cisco Secure Access Credentials
          • Add Secure Service Edge (SSE) Policy Group
          • Enable Context Sharing
        • Verify and Monitor Context Sharing
          • Verify Context Sharing in Secure Access
          • Monitor Context Sharing in SD-WAN Manager
          • Monitor Secure Access Tunnels using the CLI
          • Activity Search in Secure Access
      • Integrate Cisco Identity Intelligence with Secure Access
        • Configure a New Duo and Cisco Identity Intelligence Tenant with Secure Access
        • Configure an Existing Duo and Cisco Identity Intelligence Tenant with Secure Access
        • After Integrating Cisco Identity Intelligence
          • Duo Directory Integration with Secure Access
        • Integrate Cisco SASE with Meraki SD-WAN
    • Cisco Security for Chromebook Client
      • About Cisco Security for Chromebooks
        • Key benefits
        • Prerequisites for Cisco Security for Chromebooks Client
        • Limitations for Cisco Security for Chromebooks
      • Integrate the Google Workspace Identity Service
        • Limitations
        • Integrate the Google Workspace Identity Service
      • Deploy the Cisco Security for Chromebooks Client
        • About DNS-Layer Protection
        • About SWG-Layer Protection
        • High-Level Steps for Deploying Cisco Security for Chromebook Client
          • Step 1: Deploying Cisco Security for Chromebook Client
          • Step 2: Deploying Cisco Security for Chromebook Client
        • Bypass Internal Domains from DNS-over-HTTPS (DoH)
          • Procedure
            • Verification
        • Enable Reporting for the Private IP Address of a Chromebook Device
          • Procedure
        • Verify Cisco Security for Chromebooks Client Deployment
          • Procedure
        • Export Device Data to CSV
          • Procedure
          • DNS Protection Status in Exported Reports
          • SWG Protection Status in Exported Reports
        • Manage Device Deployment
          • Add and Activate Deployment Key
          • Manage Deployment Key Compromise
          • Delete a Deployment Key
          • Revert to the Legacy Deployment Implementation
          • Backward Compatibility
        • Troubleshoot Cisco Security for Chromebooks Client Deployment
      • View Protection Status of Chromebook Devices
        • Procedure
      • Add Policies to a Chromebook Device
        • Procedure
      • Cisco Security for Chromebooks Client FAQ
      • Google Workspace Identity Service FAQ

Core Platform Administration Connections to Private Destinations

Last updated: Sep 15, 2026

Previous topic Private Resource Configuration Examples Next topic Manage Connections to Private Destinations
© 2026 Cisco System, Inc.
Privacy policyTerms of Service