> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/integrations/secure-access.md).

# Cisco Secure Access Data Integration

## Overview

Identity Intelligence integrates with Cisco Secure Access to ingest and display data associated with Application and User and Entity Behavior Analytics events (UEBA).\
\
For information on configuring Secure Access to consume Trust Level data from Identity Intelligence via Security Cloud Control (SCC), please refer to the [Secure Access documentation](https://securitydocs.cisco.com/docs/csa/olh/136576.dita) guide, which contains information about connecting both an existing or new Identity Intelligence tenant to your Secure Access organization. If you already have an Identity Intelligence tenant via Duo, **please** follow the "Existing Tenant" set up steps.&#x20;

### Configuration Steps&#x20;

Follow the instructions below in the order written

#### Generate an API Key in Secure Access

You will first need to generate an API key with the necessary permissions within Secure Access. To do so:

1. Log in to your Secure Access org with a **Full Admin** or **Security Administrator** role
2. Navigate to the **Admin** menu item and select **API Keys**

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FrBQwuCbFDfVS0N8pYxRm%2Fimage.png?alt=media&amp;token=85b85cf7-442f-44d8-891a-2bc857bfe9d8" alt="" width="375"><figcaption></figcaption></figure>

3. Select **Add**, then enter a easily recognizable name and a description for the key
4. Assign the key the required scopes by selecting the respective check boxes:

   1. Deployments (Identities and Networks)&#x20;
   2. Reports &#x20;

   <figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2F7REBmrocPGJOnCb3midz%2Fimage.png?alt=media&amp;token=66f44bb5-68e2-4cd0-bb09-ce4490c18269" alt=""><figcaption></figcaption></figure>
5. Select `Read-Only` for each selected scope and resource
6. For **Expiry Date** choose an expiration date or select **Never Expire.** Do NOT enter any information in the Network Restrictions area
7. Select **Create Key.** Then copy and save your API Key and Key Secret in a secure location, as you will need this information to complete the integration steps within Identity Intelligence
8. Select **Accept and Close**

#### Identity Intelligence Configuration Steps

1. Sign in to Identity Intelligence with an Administrator role
2. Navigate to **Integrations** and select **Add Integration** from the Secure Access tile
3. Enter a **name** for the integration. This name will be reused through Identity Intelligence to identify the source
4. Paste the **API Key** and **Key Secret** generated in Secure Access into their respective fields in the form

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FRkLtw6vvXx0b8xUDgfUN%2Fimage.png?alt=media&amp;token=20a795ae-374e-415c-a0c9-22d23644dcff" alt=""><figcaption></figcaption></figure>

5. Select **Save** to finish setting up the integration
6. Your integration has been created! Identity Intelligence will test the connectivity automatically, and if there are no errors, will begin the data ingestion process&#x20;
