Cisco Identity in Cloud Control
Cisco Identity in Cisco Cloud Control
Welcome to the Cisco Identity documentation for Cisco Cloud Control. This guide provides comprehensive information for understanding, configuring, and using Identity to bring identity context to your network.
Table of Contents
Overview
What is Cisco Identity?
Cisco Identity brings identity context to the network through Cisco Cloud Control. It's an analytics hub that aggregates identity, device, network, application, and agentic activity into one operational view.
Cisco Identity helps you:
See the actors behind access: Identify humans, devices, apps, workloads, service accounts, and AI agents
Evaluate posture and change: Use Trust Levels, anomaly signals, and timelines to understand risk
Investigate with context: Use AI Canvas to bring identity, device, network, and application context into guided investigations
Turn context into action: Use actor context to inform network policy, segmentation, and access decisions
Getting Started
Prerequisites
Before using Cisco Identity, ensure you have:
Access to Cisco Cloud Control: You must have Administrator or read-only role in Cisco Cloud Control
Tenant Full Admin is required to add, edit, test, or remove Cisco Identity integrations
Note: The Cisco Cloud Control Integration Admin role does not currently grant integration-management permissions within Cisco Identity
Tenant Read-Only users can view Cisco Identity data but cannot configure integrations or take any other actions
At least one connected product: Cisco Identity requires your org to have at least one product (e.g.: Secure Access, Meraki, Splunk, or more) already connected in Cisco Cloud Control - an emtpy Cisco Cloud Control tenant alone is not sufficient
License Requirements
All Customers: Can integrate Cisco Identity with Cisco product integrations (Duo, ISE, Secure Access, Webex, Splunk)
Duo Advantage+ or ISE Advantage+: Required to integrate external (non-Cisco) sources
To verify your edition for paid access, open a support case with Cisco Support.
Access & Roles
Cisco Identity uses Cisco Cloud Control roles to control access:
Tenant Full Admin: Can access Cisco Identity and configure integrations
Tenant Read-Only: Can view Cisco Identity data but cannot make configuration changes or take any other write actions
Integration Admin: This Cisco Cloud Control role is not currently supported for managing integrations within Cisco Identity
If you need to add or manage an integration, ask a Cisco Cloud Control Tenant Full Admin to assign you the Tenant Full Admin role through Admin Console > Users.
Accessing Identity
Log in to Cisco Cloud Control via any supported product
Navigate to Platform Services and select Identity
Your tenant will automatically be provisioned for you to start using Cisco Identity
Initial Configuration
Step 1: Review Integrations
In Identity, navigate to Settings > Integrations
Verify supported sources and targets:
Cisco: Duo, ISE, Secure Access, Webex, Splunk
External: Okta, Entra, Active Directory, Google, Slack, GitHub and more
Step 2: Configure Data Collection
For each integration:
Select Add Integration for the desired source from the Integrations list.
Integrations that are not available for your organization based on Licensing will be greyed out. Contact Support if you believe your organization should be entitled to these integrations per your licensing
Follow the integration configuration steps found in documentation article for the respective integration that you have selected
After you have completed the necessary steps, select Save to store your changes and to trigger the automated connectivity test. The connectivity test can take several minutes but you do not have to stay on this screen for it to continue processing
If the test completes successfully, the integration is configured and data collection will start automatically within the next ___. If the connectivity test fails (
Connectivity Status: Failed), review the errors in the system logs and the current configuration to resolve the issue
Step 3: Explore the Dashboard
The data ingestion process can take over 24 hours or up to a week to complete and stabilize as it collects historical data. In very large environments, this can even take up to 2 weeks. For this reason, we highly recommend not reviewing data before 7 days as it can still contain data inconsistencies.
Navigate to the Identity dashboard
Review key metrics such as:
Total actors and entities (humans, devices, apps, non-humans, agents)
Trust Level distribution
Posture Score
Top risk factors and insights
Drill into specific actors, entities, detections or trends
What's Next
Now that you've done your initial setup, learn more about how you can improve your identity security posture score and clean up identities.
Identity for AI Canvas
What is AI Canvas?
AI Canvas brings identity, device, network, and application context into guided investigations using natural language.
AI Canvas is an AI-powered investigation assistant that answers natural language questions about your Cisco Cloud Control products. For Cisco Identity, you can ask about identity and access, correlate data across identity sources, network telemetry, and application logs, receive guided investigation paths, and generate investigation summaries.
Using AI Canvas
AI Canvas provides guidance for common investigations including compromised credentials, suspicious access, and posture degradation. Start with broad questions, use actor identifiers, specify timeframes, and build on previous responses to deepen investigations.
Access AI Canvas by navigating to AI Canvas from the header in Cisco Cloud Control. Ask questions about:
Actors: High-risk users, service account status, access patterns, anomalies
Devices: Compliance status, unmanaged devices, device usage
Access: Resource access history, failed authentications, privilege assignments
AI Agents: Agent activity, service account usage, resource access patterns
For comprehensive AI Canvas documentation including detailed examples, investigation workflows, and best practices, see the Cisco Cloud Control Canvas guide.
Identity in Cisco Cloud Control Inventory
Cisco Cloud Control Inventory provides centralized visibility into networking devices, including ISE infrastructure nodes (Primary Admin Nodes, Secondary Admin Nodes, Policy Service Nodes, and Monitoring/Troubleshooting Nodes).
Once ISE is integrated with Cisco Identity, navigate to Inventory under Platform Services to view node information including hostname, type, software version, health status, and sync time. You can search, filter, and export inventory data.
For comprehensive Inventory documentation, see the Cisco Cloud Control Inventory documentation.
Additional Resources
Last updated