For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cisco Secure Access Data Integration

Overview

Identity Intelligence integrates with Cisco Secure Access to ingest and display data associated with Application and User and Entity Behavior Analytics events (UEBA). For information on configuring Secure Access to consume Trust Level data from Identity Intelligence via Security Cloud Control (SCC), please refer to the Secure Access documentation guide, which contains information about connecting both an existing or new Identity Intelligence tenant to your Secure Access organization. If you already have an Identity Intelligence tenant via Duo, please follow the "Existing Tenant" set up steps.

Configuration Steps

Follow the instructions below in the order written

Generate an API Key in Secure Access

You will first need to generate an API key with the necessary permissions within Secure Access. To do so:

  1. Log in to your Secure Access org with a Full Admin or Security Administrator role

  2. Navigate to the Admin menu item and select API Keys

  1. Select Add, then enter a easily recognizable name and a description for the key

  2. Assign the key the required scopes by selecting the respective check boxes:

    1. Deployments (Identities and Networks)

    2. Reports

  3. Select Read-Only for each selected scope and resource

  4. For Expiry Date choose an expiration date or select Never Expire. Do NOT enter any information in the Network Restrictions area

  5. Select Create Key. Then copy and save your API Key and Key Secret in a secure location, as you will need this information to complete the integration steps within Identity Intelligence

  6. Select Accept and Close

Identity Intelligence Configuration Steps

  1. Sign in to Identity Intelligence with an Administrator role

  2. Navigate to Integrations and select Add Integration from the Secure Access tile

  3. Enter a name for the integration. This name will be reused through Identity Intelligence to identify the source

  4. Paste the API Key and Key Secret generated in Secure Access into their respective fields in the form

  1. Select Save to finish setting up the integration

  2. Your integration has been created! Identity Intelligence will test the connectivity automatically, and if there are no errors, will begin the data ingestion process

Last updated