> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/how-to-guides/cisco-identity-in-cloud-control.md).

# Cisco Identity in Cloud Control

## Cisco Identity in Cisco Cloud Control

Welcome to the Cisco Identity documentation for Cisco Cloud Control. \
\
This guide provides comprehensive information for understanding, configuring, and using Identity to bring identity context to your network.

### Table of Contents

* [Overview](#overview)
* [Getting Started](#getting-started)
* [Identity for AI Canvas](#identity-for-ai-canvas)
* [Identity in Cisco Cloud Control Inventory](#identity-in-cloud-control-inventory)

***

### Overview

#### What is Cisco Identity?

Cisco Identity brings identity context to the network through Cisco Cloud Control. It's an analytics hub that aggregates identity, device, network, application, and agentic activity into one operational view.

Cisco Identity helps you:

* **See the actors behind access**: Identify humans, devices, apps, workloads, service accounts, and AI agents
* **Evaluate posture and change**: Use Trust Levels, anomaly signals, and timelines to understand risk
* **Investigate with context**: Use AI Canvas to bring identity, device, network, and application context into guided investigations
* **Turn context into action**: Use actor context to inform network policy, segmentation, and access decisions

***

### Getting Started

#### Prerequisites

Before using Cisco Identity, ensure you have:

1. **Access to Cisco Cloud Control**: You must have [Administrator or read-only role ](#access-and-roles)in Cisco Cloud Control
   * **Tenant Full Admin** is required to add, edit, test, or remove Cisco Identity integrations
     * **Note**: The Cisco Cloud Control *Integration Admin* role does not currently grant integration-management permissions within Cisco Identity
   * **Tenant Read-Only** users can view Cisco Identity data but cannot configure integrations or take any other actions
2. **At least one connected product:** Cisco Identity requires your org to have at least one product (e.g.**:** Secure Access, Meraki, Splunk, [or more](https://www.cisco.com/c/en/us/td/docs/ai/cisco-cloud-control/articles/cisco-cloud-control-getting-started.html)) already connected in Cisco Cloud Control - an emtpy Cisco Cloud Control tenant alone is not sufficient

#### License Requirements

* **All Customers**: Can integrate Cisco Identity with Cisco product integrations (Duo, ISE, Secure Access, Webex, Splunk)
* **Duo Advantage+ or ISE Advantage+**: Required to integrate external (non-Cisco) sources

To verify your edition for paid access, open a support case with Cisco Support.

#### Access & Roles

Cisco Identity uses Cisco Cloud Control roles to control access:

* **Tenant Full Admin**: Can access Cisco Identity and configure integrations
* **Tenant Read-Only**: Can view Cisco Identity data but cannot make configuration changes or take any other write actions
* **Integration Admin**: This Cisco Cloud Control role is **not** currently supported for managing integrations within Cisco Identity

If you need to add or manage an integration, ask a Cisco Cloud Control Tenant Full Admin to assign you the Tenant Full Admin role through **Admin Console > Users**.

#### Accessing Identity

1. Log in to **Cisco Cloud Control** via any supported product
2. Navigate to **Platform Services** and select **Identity**
3. Your tenant will automatically be provisioned for you to start using Cisco Identity

#### Initial Configuration

{% hint style="info" %}
The following configuration steps require the **Tenant Full Admin** role. Tenant Read-Only users can view integrations but **cannot** add or modify them. The Integration Admin role is not currently supported for these actions.
{% endhint %}

**Step 1: Review Integrations**

1. In **Identity**, navigate to **Settings** > **Integrations**
2. Verify supported sources and targets:
   * Cisco: Duo, ISE, Secure Access, Webex, Splunk
   * External: Okta, Entra, Active Directory, Google, Slack, GitHub and more

**Step 2: Configure Data Collection**

For each [integration](https://docs.oort.io/integrations):

1. Select **Add Integration** for the desired source from the Integrations list.
   1. Integrations that are not available for your organization based on Licensing will be greyed out. Contact Support if you believe your organization should be entitled to these integrations [per your licensing](#license-requirements)
2. Follow the integration configuration steps found in documentation article for the respective integration that you have selected
3. After you have completed the necessary steps, select **Save** to store your changes and to trigger the automated connectivity test. The connectivity test can take several minutes but you do not have to stay on this screen for it to continue processing
4. If the test completes successfully, the integration is configured and data collection will start automatically within the next \_\_\_. If the connectivity test fails (`Connectivity Status: Failed)` , review the errors in the system logs and the current configuration to resolve the issue

**Step 3: Explore the Dashboard**

{% hint style="warning" icon="triangle-exclamation" %}
The data ingestion process can take over 24 hours or up to a week to complete and stabilize as it collects historical data. In very large environments, this can even take up to 2 weeks. For this reason, we **highly recommend** not reviewing data before 7 days as it can still contain data inconsistencies.
{% endhint %}

1. Navigate to the **Identity** dashboard
2. Review key metrics such as:
   * Total actors and entities (humans, devices, apps, non-humans, agents)
   * Trust Level distribution
   * Posture Score
   * Top risk factors and insights
3. Drill into specific actors, entities, detections or trends

**What's Next**

Now that you've done your initial setup, [learn more about how you can improve your identity security posture score and clean up identities](https://docs.oort.io/best-practices/whats-next-how-to-use-identity-intelligence-effectively).&#x20;

***

### Identity for AI Canvas

#### What is AI Canvas?

AI Canvas brings identity, device, network, and application context into guided investigations using natural language.

AI Canvas is an AI-powered investigation assistant that answers natural language questions about your Cisco Cloud Control products.\
\
For Cisco Identity, you can ask about identity and access, correlate data across identity sources, network telemetry, and application logs, receive guided investigation paths, and generate investigation summaries.

#### Using AI Canvas

AI Canvas provides guidance for common investigations including compromised credentials, suspicious access, and posture degradation. Start with broad questions, use actor identifiers, specify timeframes, and build on previous responses to deepen investigations.

Access AI Canvas by navigating to **AI Canvas** from the header in Cisco Cloud Control. Ask questions about:

* **Actors**: High-risk users, service account status, access patterns, anomalies
* **Devices**: Compliance status, unmanaged devices, device usage
* **Access**: Resource access history, failed authentications, privilege assignments
* **AI Agents**: Agent activity, service account usage, resource access patterns

For comprehensive AI Canvas documentation including detailed examples, investigation workflows, and best practices, see the [Cisco Cloud Control Canvas guide](https://www.cisco.com/c/en/us/td/docs/ai/cisco-cloud-control/articles/cisco-cloud-control-canvas.html).

***

### Identity in Cisco Cloud Control Inventory

Cisco Cloud Control Inventory provides centralized visibility into networking devices, including [ISE](/integrations/cisco-identity-services-engine-ise.md) infrastructure nodes (Primary Admin Nodes, Secondary Admin Nodes, Policy Service Nodes, and Monitoring/Troubleshooting Nodes).

Once ISE is integrated with Cisco Identity, navigate to **Inventory** under **Platform Services** to view node information including hostname, type, software version, health status, and sync time. You can search, filter, and export inventory data.

For comprehensive Inventory documentation, see the [Cisco Cloud Control Inventory documentation](https://www.cisco.com/c/en/us/td/docs/ai/cisco-cloud-control/articles/cisco-cloud-control-inventory.html).

***

#### Additional Resources

* [Cisco Cloud Control Documentation](https://www.cisco.com/c/en/us/td/docs/ai/cisco-cloud-control/articles/cisco-cloud-control-getting-started.html)
* [Cisco Cloud Control Canvas User Guide](https://www.cisco.com/c/en/us/td/docs/ai/cisco-cloud-control/articles/cisco-cloud-control-canvas.html)
