
Overview
Beyond Identity Secure Access is the first Secure-by-Design IAM solution that defends against modern threats with security guarantees.
It delivers a security-first SSO, phishing-resistant MFA, visibility and control over managed and unmanaged devices, robust integrations, and protections over generative AI fraud.
For mid-sized organizations, Secure Access provides the unified platform you need to safeguard authentication and access with robust integrations that help you get more value out of your existing tooling.
For enterprise organizations, Secure Access delivers a modular platform to support your specific needs for authentication, device security, and SSO or supplant existing solutions that fall short on their security promise.
Please reach out for custom and volume-based pricing via Private Offer at https://www.beyondidentity.com/get-demo
Highlights
- Validates a user identity and its association with a verified device that meets security policy to deliver trusted authentication and enforces continuous, risk-based authentication.
- Enables password elimination. Replaces passwords with an authentication platform rooted in asymmetric cryptography leveraging proven standards (including x.509 certificates and the TLS protocol) without any certification management required.
- Provides zero friction, secure digital access for employees, contractors, and developers. It is the 1st foundational step toward today's Zero Trust Security strategy.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
- Small Market Bundle | Customizable SMB Bundle | $10,000.00 |
- Authentication Essentials | Includes: Phishing-Resistant MFA, Access360, Device 360, Premium Support for up to 1,000 users | $36,000.00 |
- Zero Trust Identity & Device | Includes: Zero Trust Authentication, Access360, Premium Support for up to 1,000 users | $96,000.00 |
- Secure Access Complete | Includes: Secure SSO, Zero Trust Authentication, Access360, Premium Support for up to 1,000 users | $144,000.00 |
Vendor refund policy
N/A
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Secure access has strengthened DNS protection and unified threat visibility for our environment
What is our primary use case?
I have been working with Cisco Secure Access for the past five years. We have multiple use cases for Cisco Secure Access , with most of them associated with DNS filtering security. We use it as a replacement for secure internet, providing web filtering. Instead of giving a web filtering or proxy solution, we provide it as a DNS filtering solution where it helps us to stop the traffic even before reaching the malicious server. In normal traditional proxy solutions, end user traffic generated from the system and endpoints reaches the malicious or unauthorized servers, and then while getting a response back to the end-user machine, the proxy blocks that particular request or response sent from the server. In this case, what Cisco is providing is a DNS security advantage license and a security gateway. They have a higher role where they can control the traffic when the traffic is generated from the end-user endpoint machine itself. That itself is an advantage for controlling our traffic to the public IP of the malicious and unauthorized servers. That is one key advantage which we have for this use case.
We also provide secure access for people who want to access the internal application from outside. We give AnyConnect, which checks whether they are connecting to the network from the proper device assigned to them. If not, we can block that particular device for a time interval if we see that the device is vulnerable. These are the kinds of use cases we are working with Cisco Secure Access.
What is most valuable?
Cisco Secure Access ZTNA feature helps in securing standard applications because it actually monitors every given interval as we configure. It checks for the security posture at every interval even after the device is connected. If a device gets connected and infected through some kind of malicious software or by using pen drives, it eventually gets isolated when Cisco Secure Access ZTNA finds that it does not fall under the given compliance. We have to give some security checks, and based on those checks, it will verify the security posture in ZTNA.
Cisco Talos influences threat detection and response capabilities in the organization because Cisco Talos is a threat intelligence machine for the Cisco brand. They have integrations with Talos in all the solutions, whether it is EDR, Umbrella , or SecureX. Basically, they provide integrations with each and every engine, and the point I want to make is that Talos intelligence is inbuilt within Cisco Secure Access itself.
SecureX incorporates all the other Cisco products. SecureX covers integration with all the Cisco solutions provided. For example, we can integrate SecureX with EDR, XDR , Cisco Secure Access, switches, routers, and Cisco firewalls, including email security solutions. In a Cisco environment, we can have full visibility, and this is what I see when protecting against threats such as phishing and ransomware—Cisco Secure Access is effective.
What needs improvement?
There is one particular disadvantage of Cisco Secure Access, and the main thing is pricing. Apart from that, I do not think it has any other disadvantage. One more thing adding to that is that in some cases, for some of our clients, we have issues with latency while they are accessing their internal resources from their home locations. However, we were able to address it partially with the help of Cisco documentation.
Managing Cisco Secure Access through a single cloud-managed console is neither very easy nor very complex. It is acceptable, but they can improve the simplicity of the console.
Pricing and simplicity could be improved, but I do not see any other main parts for improvement with Cisco Secure Access.
For how long have I used the solution?
I have been working with Cisco Secure Access for five years now. Overall in the business, I have eight years of experience.
What do I think about the scalability of the solution?
Cisco Secure Access is a cloud solution, so it is pretty much scalable.
How are customer service and support?
Cisco customer service is average. It is neither good nor bad. I would rate Cisco customer service five out of ten points. For the support, I would say they could be faster. Two or three years ago, Cisco support was very good, rated around eight or nine, but now the support engineers seem unaware of what their product is capable of. I have seen issues where I needed to explain use cases multiple times and escalate them multiple times to get solutions, leading me to rate them five now.
How was the initial setup?
Cisco Secure Access installation process is quite straightforward, but we do have to do some manual work such as preparing a script.
What was our ROI?
If you have a Cisco environment, it will give the best ROI. Everything must be of Cisco product family only, starting with EDR, XDR , mail security, switches, firewalls, and access through ZTNA. If you have every solution with Cisco, you can see a very good ROI because you do not need to invest much on staffing for analyzing each and every console separately. Everything will be monitored, and all those logs from various Cisco solutions will be coming under one console, which helps in clarifying what we have and any security loopholes in our environment that security teams need today.
I cannot quantify ROI specifically, such as ten percent or twenty percent, as it varies based on the environment. For a fully Cisco environment, it could be around sixty percent to seventy percent ROI or more, but if it is not a fully Cisco environment, it would be much less due to various integrations with other third-party solutions, which are not at a very granular level. Therefore, the ROI is greater with more Cisco solutions and less with fewer solutions.
Which other solutions did I evaluate?
While comparing Cisco Secure Access with competitors, Trend Micro would be an exact competitor. Trend Micro gives many solutions under a single console, such as Trend Vision One , and they have also incorporated AI security. However, when it comes to XDR solutions, there are several in the leader quadrant such as SentinelOne and CrowdStrike, but SecureX has not emerged as a leader in the XDR space. Cisco Secure Access itself is good, as we have not seen any attacks in Cisco environments, but as per compliance, we should not rely on a single vendor in our environment. Trend Micro is a leader quadrant product and has been a major provider for many enterprise banks, especially in large enterprises, making it one of the good competitors for Cisco Secure Access.
For the CASB functionality with Cisco Secure Access, I have not worked that much on CASB for Cisco Secure Access. When it comes to CASB , we have solutions such as Forcepoint, CloudSEK, Netskope , or Zscaler. With these products, we have plenty of CASB use cases. I have not worked with Cisco Secure Access on CASB.
What other advice do I have?
I mentioned both the advantages and the use cases of Cisco Secure Access. Usually, what we do is block QUIC traffic because the QUIC traffic is based out of UDP on port 443. By initially blocking QUIC protocol traffic, if the customer specifically asks, we will enable QUIC traffic for particular applications alone. Since it is part of best practice, we usually block it. However, in some use cases, we have enabled the QUIC protocol and provided bypassing instructions for those UDP protocols. The basic reason we block QUIC protocols is that it is a safe encrypted protocol. We cannot inspect QUIC traffic using inspection engines in web proxy or SecureX, as established with HTTPS and HTTP. That is why we prefer to block QUIC protocols, but it does work well when enabled. I give this product an overall review rating of eight.
Secure remote access has transformed hybrid work and supports a stronger zero trust strategy
What is our primary use case?
Cisco Secure Access serves as our primary solution for providing secure remote access to corporate applications and resources for a distributed workforce. We use it to enforce consistent security policies across users, devices, and locations, while enabling access to both cloud-based and on-premises applications.
A good example of this is supporting our hybrid workforce. Employees regularly work from home, at customer sites, and while traveling, and Cisco Secure Access provides secure connectivity to internal applications without requiring full network access. In one instance, a contractor needed access to a specific application hosted in our data center. Using Cisco Secure Access, we were able to grant application-level access based on identity and device posture rather than opening broad VPN access. This improved security while allowing the contractor to become productive immediately. The platform also provided visibility into access activity and automatically enforced policies, which reduced administrative effort and helped us maintain compliance requirements. The experience was seamless for the user and significantly reduced the risk associated with traditional remote access methods.
In addition to secure remote access, we leverage Cisco Secure Access to strengthen our zero trust security strategy across the organization. We use granular access controls to ensure users can only reach the applications and resources required for their roles, which helps reduce risk and simplify compliance efforts. The solution also provides valuable visibility into our users' activity, device posture, and potential security threats, allowing our security team to respond more quickly to unusual behavior. Another benefit has been the ability to provide secure access for third-party vendors and contractors without exposing the broader network. The centralized management, consistent policy enforcement, and seamless user experience have made Cisco Secure Access an important part of our overall security and hybrid workflow infrastructure.
What is most valuable?
Cisco Secure Access offers several features that stand out for our organization supporting modern hybrid work environments. One of the most valuable capabilities is its zero trust network access (ZTNA ), which provides secure identity-based access to applications without exposing the entire network. The platform also delivers strong security controls through continuous user and device verification, helping ensure that only authorized users can access sensitive resources. Another key feature is centralized policy management, which allows administrators to create and enforce consistently secure policies across users, devices, and locations.
The feature that has had the biggest impact for our team is zero trust network access (ZTNA ). Prior to implementing Cisco Secure Access, remote users often required broader network access through traditional VPN connections, which increased administrative overhead and security concerns. With ZTNA, access is granted at the application level based on user identity, device posture, and security policies rather than network location. This approach has significantly improved our security posture by reducing the attack surface and limiting lateral movement opportunities. It has also streamlined our workload because access requests are easier to manage and policies can be applied consistently across users and applications. Employees and contractors are able to securely connect to the resources they need from any location without sacrificing performance or user experience. The combination of stronger security, simplified access management, and improved visibility has made ZTNA the most valuable capability within Cisco Secure Access for our organization.
What needs improvement?
Overall, Cisco Secure Access has been a strong solution for secure remote access and zero trust security, but there are a few areas where it could be improved. The initial deployment and policy design process can be complex, particularly for organizations with a large number of applications, diverse user groups, and existing security integrations. Defining and fine-tuning access policies requires careful planning to avoid overly restrictive and overly permissive accesses. Another challenge is that troubleshooting access issues can sometimes require navigating multiple dashboards and logs, which can increase the time needed to diagnose problems. While the reporting and visibility features are useful, more streamlined and customizable reporting options would help security and operations teams gain insights faster. We have also encountered occasional learning curves for administrators who are new to zero trust concepts and Cisco policy framework. Additionally, guided information, configuration tools, and simplified policy recommendations could make onboarding easier. These challenges are relatively minor compared to the security, visibility, and management benefits the platform provides. With continued enhancements to usability, reporting, and policy management workflows, Cisco Secure Access could become even more effective for enterprise environments.
One improvement that would make a significant difference for our team would be more intelligent policy recommendation and automation capabilities. As our organization scales, managing access policies across multiple applications, user groups, and devices can become complex. Having AI-driven recommendations that suggest policy optimizations, identify potential misconfigurations, and highlight overly permissive access rules would help reduce administrative effort and improve security consistency. We would also like to see more unified troubleshooting and reporting capabilities. While the platform provides strong visibility, having a single view that correlates user activity, device posture, policy decisions, and access events would help administrators resolve issues more quickly.
For how long have I used the solution?
What do I think about the stability of the solution?
Cisco Secure Access has been a stable and reliable platform. In our experience, the service consistently provides secure connectivity for remote users, contractors, and hybrid environments with minimal disruption. Our day-to-day operations run smoothly, and the platform has effectively met access requirements across cloud and on-premises environments. From an availability perspective, we have experienced strong and dependable performance. Users generally access a high percentage of resources without connectivity issues, and the cloud-delivered architecture helps ensure consistent service regardless of user location. Overall, it has been a good experience and very stable.
What do I think about the scalability of the solution?
Cisco Secure Access has kept pace with our increased adoption of cloud-based applications without requiring significant infrastructure changes or adding complexity. One of the biggest advantages is the cloud-delivered architecture, which allows us to access applications quickly while maintaining security and user experience. Instead of deploying and managing additional hardware, we can scale through centralized management, which has significantly reduced operational effort. The platform has enabled us to respond to changing business needs, hybrid working conditions, cloud migration, and evolving security requirements. We have been able to enforce consistent access controls across both cloud-hosted and on-premises applications while maintaining visibility and compliance. Performance has remained consistent, usage has increased, and we have not experienced scalability-related limitations. From an administration perspective, the centralized management capability is easy to support without proportionally increasing workload. It has provided the flexibility needed to adapt to changing technology without significant redesign or additional infrastructure investments.
How are customer service and support?
Our experience with Cisco Secure Access customer support has generally been positive. Cisco provides multiple support channels, including a support document knowledge base and access to specialists when needed. For standard issues and configuration questions, response times have been reasonable, and support engineers have demonstrated strong technical knowledge of both the platform and Cisco Secure Access. Another strength of the support has been their ability to assist with our complex deployment involving zero trust implementation, integrations with hybrid environments, and security policy management. During the implementation and ongoing operations, we have been able to leverage Cisco documentation and support resources to use new features more effectively. The critical issues escalation process has worked well, helping minimize our impact. We have also found community resources, including guides and best practice documentation, to be valuable supplements to direct support interactions. While it can vary depending on the specific issue and the support team involved, our overall experience has been positive with Cisco Secure Access support.
Which solution did I use previously and why did I switch?
We previously relied heavily on traditional VPN connectivity for remote access, and Cisco Secure Access has played an important role in our transition toward the ZTNA model rather than providing broad network access through a VPN. ZTNA enables secure access to applications based on user identity, device posture, location, and security policies. The transition has significantly improved both security and user experience. With traditional VPNs, users often received access to a larger portion of the network than necessary, which increased risk and administrative complexity. Cisco Secure Access allows us to grant access only to the specific applications and resources required for the user's role, reducing the attack surface and supporting zero trust. From an operational perspective, the migration has simplified access management and reduced the number of VPN-related support issues. Users experience more seamless connectivity because they no longer need to establish a full VPN session for every task, and administrators can manage policies centrally through a unified platform. We still maintain limited VPN access for certain legacy systems and specialized use cases, but the majority of our remote access strategy now relies on ZTNA. Cisco Secure Access has made the transition from VPN to ZTNA smoother than expected by providing stronger security controls, better visibility into our user activity, simplified administration, and a more consistent experience for remote and hybrid workers.
How was the initial setup?
Our experience with Cisco Secure Access pricing and licensing has generally been positive. While the solution is not the lowest cost option in the market, we found that the value provided through security, scalable centralized management, and zero trust capabilities justifies the investment when evaluating the total cost of ownership. It helps reduce the need for multiple standalone security and remote access solutions, which simplified operations and improved overall efficiency. The initial setup and implementation costs were largely associated with planning, policy design, integration with identity providers, and migration from existing remote access technologies. Like most enterprise security platforms, deployment requires careful preparation and stakeholder involvement, but Cisco provided sufficient documentation and support resources to make the process manageable.
What was our ROI?
We have seen a measurable return on investment from Cisco Secure Access, both from a security and operational perspective. One of the biggest benefits has been the reduction in administrative effort through centralized policy management and automated access controls. We estimate that tasks related to user provisioning, access modifications, and policy administration require approximately twenty-five to thirty percent less effort compared to our previous approach. We have also seen a noticeable reduction in access-related support tickets as users experience more reliable and streamlined connectivity through the zero trust model. This has allowed IT and security teams to spend less time troubleshooting remote access issues and more time focusing on strategic initiatives. Incident investigations and resolution times have improved as well due to better visibility into user activity, application access, and network performance. From a financial perspective, Cisco Secure Access has helped us consolidate several security and remote access functions into a single platform, reducing operational complexity and minimizing the need for additional infrastructure. The cloud-delivered architecture also lowers maintenance requirements compared to managing traditional remote access solutions. Overall, the combination of improved security, faster onboarding, and reduced administrative workload, fewer support issues, and better operational efficiency has delivered a strong return on investment. While the exact savings vary by organization, the productivity gains and the risk reduction have more than justified the investment for us.
What's my experience with pricing, setup cost, and licensing?
Before adopting Cisco Secure Access, we primarily relied on traditional VPN-based remote access solutions combined with supporting security tools for web filtering, access control, and visibility. While the hub approach met basic remote access requirements, it became increasingly difficult to manage as our workforce became more distributed and our cloud adoption increased. We decided to move to Cisco Secure Access because we wanted a more modern, zero trust architecture that could provide secure identity-based access to applications rather than broader network-level connectivity. The previous solution required more manual management, offered limited visibility into user activity, and created additional complexity when supporting employees, contractors, and third-party partners. Cisco Secure Access stood out because it combined ZTNA, secure policy enforcement, threat protection, and centralized management with user experience monitoring within a unified platform. The ability to apply consistent policies across cloud and on-premises resources improved visibility and reduced reliance on traditional VPN infrastructure, making the transition compelling. Since making the switch, we have improved security, reduced administrative workload, enhanced our user experience, and gained better insight into application access and network activity. The move has also supported our broader zero trust and hybrid work initiatives, making Cisco Secure Access a better fit for our long-term security strategy.
Which other solutions did I evaluate?
We conducted a thorough evaluation of several secure access and zero trust solutions before selecting Cisco Secure Access. The products we considered included Zscaler Private Access, Alternate Network solutions, Netskope , Microsoft-based security, and remote access solutions that align with our existing cloud strategy. Our evaluation focused on several criteria, including zero trust capabilities, ease of deployment, visibility into applications and activity, integrations with existing security investments, scalability, reporting, and overall user experience. We also assessed each vendor's ability to support hybrid environments that include both cloud-hosted and on-premises applications. Ultimately, Cisco Secure Access stood out because of its strong combination of ZTNA functionality, unified policy management, cloud-delivered security services, AI-driven insights, Thousand Eyes integration for digital experience monitoring, and compatibility with broader security ecosystems. We also valued the ability to manage security policies consistently across remote users, branch locations, and private applications from a centralized platform. While the competing solutions offered strong features in specific areas, Cisco Secure Access provided the best overall security, visibility, operational simplicity, and long-term scalability for our requirements. The platform blended well with our zero trust strategy and offered a path for future required architectural changes.
What other advice do I have?
My biggest piece of advice is to approach Cisco Secure Access as a strategic, zero trust initiative rather than simply a replacement for traditional VPN technology. Organizations get the most value when they take the time to understand application requirements and security objectives prior to deployment. Having a sound access strategy and well-crafted policy creation makes it much easier to maximize both security and user experience. I would recommend starting with a phased rollout, beginning with a simpler group of users and application policies, gathering feedback, and then expanding gradually. This approach facilitates smoother implementation and wider adoption. Another key takeaway is to take advantage of the platform's features, including digital experience monitoring through Thousand Eyes and centralized policy management.
Overall, Cisco Secure Access has been a valuable component of our security strategy. The platform has modernized our approach to secure connections by supporting zero trust, improving user and application access, and reducing our dependence on traditional VPN-based remote access. We have benefited from centralized policy management, strong security controls, digital experience monitoring capabilities, and the ability to deliver a consistent experience for remote and third-party users. Continuous use of Cisco Secure Access has provided the flexibility and scalability needed to support changing business requirements without adding operational complexity. The overall benefits have far outweighed those challenges. If I were to summarize the platform in a few words, I would describe it as secure, highly reliable, and aligned with modern zero trust strategies. For organizations looking to strengthen security while managing a distributed workforce, Cisco Secure Access presents a strong option with both operational and security value. I would rate this solution a nine out of ten.
Hybrid access has unified secure cloud and data center connectivity for diverse client needs
What is our primary use case?
The major use cases for clients regarding Cisco Secure Access involve ZTNA , for when you require cloud services, like ZTNA , Secure Web Gateway, CASB , and Firewall as a Service. When you want to secure your on-premises equipment, on-premises data center, or services center, we provide the connectivity through the cloud, and at that moment, we use Cisco Secure Access .
The ZTNA part in Cisco is very important because it helps my customers to secure applications. When you configure your application or deploy your application on the on-premises data center and you want to access it where there is no trust on the inbound—whether you are an enterprise user, a remote user, or any other user coming through the cloud—then you will provide only the split tunnel or the tunnel between the cloud and your data center, which provides Cisco Secure Access.
CASB is also relevant when your services are deployed in many different cloud services, as you can use CASB in those scenarios.
What is most valuable?
The biggest benefit of Cisco Secure Access, compared to Fortinet or other solutions from Palo Alto or Prisma, is its adaptability to different network environments.
Customers appreciate the good features of Cisco Secure Access because it is a hybrid network solution. When there is a hybrid network, customers require Cisco Secure Access so they can access both cloud services and on-premises data center services.
I would say it is easy to manage Cisco Secure Access through this console. It is similar to managing a firewall, such as the FTD, and the console is straightforward.
What needs improvement?
I have seen that if the on-premises devices are Cisco devices, then we use Cisco SSE. However, when there are Fortinet devices, then we use FortiSSE, which indicates a potential area for improvement.
Cisco could add new features in the future, such as enhanced automation capabilities. They are providing automation in their technology, which is an improvement area. If you use automation tools like Red Hat, you can perform automation more effectively. Regarding AI, I think Cisco is doing well, though there is still room for improvement in AI capabilities.
For how long have I used the solution?
I started working with Cisco Secure Access relatively recently, but I understand how it works and how we submit proposals for Cisco Secure Access and Fortinet security solutions. When we require cloud security, then we provide Cisco Secure Access and SSE.
What do I think about the stability of the solution?
Cisco is stable and reliable.
What do I think about the scalability of the solution?
Scalability mostly depends on the architecture, not on the hardware or OEM. How you architect and define the network design determines scalability. If you do not have a good architecture, you cannot achieve scalability.
How are customer service and support?
I think Cisco's technical support is good. I believe that both Cisco technical support and Juniper technical support are very good.
What other advice do I have?
If the requirement is for Cisco equipment, then we propose Cisco Secure Access. If the requirement is for Fortinet, then we provide FortiSafety.
As a system implementer, I think the biggest advantage of the product is its usability in various scenarios.
I am not certain who is the leader when comparing Cisco with Fortinet and Palo Alto. Both are good at what they do, and sometimes we cannot use all the features of any product. We use specialized or customized features for our data center according to customer requirements, and all follow standard features and protocols, which are good.
The HTTP protocol is important for connecting through the cloud or establishing a tunnel. A VPN service and another tunnel between the cloud SSE and your on-premises data center are essential.
Cisco Secure Client provides the resource connector. There is a connector on the on-premises data center, so we establish a secure connection, mostly VPN or IPsec VPN, between the cloud and the data center.
I would say that Cisco Secure Access is effective in protection from ransomware and phishing attacks. It is a standard they are using, and when you are using Cisco devices, then you can rely on Cisco cloud.
Both deployment parts are not very difficult. It is straightforward.
I did not deploy Cisco Secure Access myself, but I understand from my team that it is not a big challenge.
Cisco could add new features in the future, such as enhanced automation capabilities. They are providing automation in their technology, which is an improvement area.
My experience is primarily with clients using a hybrid model.
We mostly integrate with Azure and AWS through the cloud.
I cannot say who is the leader when comparing Cisco with Fortinet and Palo Alto. Both are good at what they do, and sometimes we cannot use all the features of any product. We use specialized or customized features for our data center according to customer requirements, and all follow standard features and protocols, which are good.
I would rate Cisco support at an eight out of ten. The overall review rating for this product is nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Unified access security has simplified cloud architectures and reduced hardware dependency
What is our primary use case?
My role is to enable partners and customers in Cisco Secure Access and help them understand and design their architecture. When a client comes to me to understand the use case they have with Cisco Secure Access , I suggest how they could use it, such as securely accessing their AWS server via VPN.
What is most valuable?
Cisco Secure Access is distributed by distributors of Cisco, Palo Alto, and Checkpoint, along with other tech companies. All the basic features, including ZTNA , are part of Cisco Secure Access, which can be considered an upgraded version of Umbrella with advanced features of ZTNA and ThousandEyes integrated for Digital Experience Monitoring.
When comparing Cisco Secure Access with other vendors, Cisco approaches it differently because it allows the use of the QUIC protocol rather than blocking it. Cisco Secure Access has a Hybrid Mesh Firewall concept, giving the advantage of managing all firewall capabilities on a single portal. The manageability of Cisco Secure Access is on a single dashboard.
In comparison to Zscaler, with Cisco Secure Access, I can create a Private Access Tunnel with any vendor or routing device. For ZTNA in Cisco Secure Access, Cisco does it differently by allowing ZTNA on both client basis and browser level for contractor access. The integration with CASB is positive for Cisco Secure Access, and multiple applications such as Office 365 and Google Suite are being integrated.
The importance of Cisco Secure Access providing secure access via standard HTTP/2 and QUIC protocols is significant due to QUIC being faster than TCP. Cisco Talos is integrated with every other security product in Cisco, including Cisco Secure Access. For threat detection and response, that integration with Cisco Secure Access is important. Cisco is working on DLP with Cisco Secure Access, which they are continuously upgrading.
For how long have I used the solution?
I have used Cisco Secure Access for three years now.
What do I think about the stability of the solution?
Cisco Secure Access is more stable and reliable than Checkpoint.
What do I think about the scalability of the solution?
With Cisco Secure Access, I can scale it anytime, and licensing is quite easy.
How are customer service and support?
The customer service is good and great because Cisco has a large team of engineers providing support. I would rate the customer service support from Cisco at eight or nine.
Which solution did I use previously and why did I switch?
I started with Fortinet and Checkpoint, and then moved to Cisco regarding security products.
How was the initial setup?
Configuring Cisco Secure Access is straightforward; the dashboard clearly shows the steps needed.
What was our ROI?
ROI with Cisco Secure Access is quite good because it reduces hardware dependencies and offers many features.
What other advice do I have?
Checkpoint has much data latency when connecting to cloud compared to Cisco Secure Access, which has no such issues. Currently, Cisco is giving a very good discount to partners for Cisco Secure Access and providing feasibility in user size. Cisco Secure Access decreases the dependency on hardware while simplifying licensing. It is a cloud-based product. At the back end, Cisco is deploying Cisco Secure Access on AWS or some tenant, but we only see a subscription-based model. I have interacted with AWS Marketplace when deploying ISE, but Cisco SSE service is not available there. I would rate this product nine out of ten overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Zero trust access has strengthened posture management and secured cloud-based user connections
What is our primary use case?
The main use case for Cisco Secure Access is for posture management, managing network devices, guaranteeing guest access, BYOD, guest, and sponsor portal. I have used Cisco Secure Access from end to end.
What is most valuable?
I consider network segmentation as one of the most valuable functions of Cisco Secure Access.
I use the Zero Trust Network Access (ZTNA ) feature of Cisco Secure Access, and we have currently deployed it for ZTNA. I appreciate the identity management of devices where they are connecting to the network. The device needs to be trusted always, which is actually a good security best practice because it does not involve trusting a device once and then allowing it network access.
I have experience with the integration of CASB functionality in Cisco Secure Access. The cloud access broker has helped by providing a bridge between the user directory and functionality, allowing the system to enforce data control, compliance, and threat protection. This is good security practice as well.
What needs improvement?
How easy or difficult it is to manage Cisco Secure Access through the single cloud-managed console depends on who you talk to, but for me, with my experience, it has become very easy and really manageable. Much of the interface has been improved significantly, making management easier. The upgrade of the interface really has changed a lot, which makes it easier to remember.
Automation is something Cisco could improve for Cisco Secure Access. I have seen the way they have done this with SD-WAN, where you have automation of VPN through auto VPN tunneling and the creation of tunneling between SD-WAN. If Cisco could improve Cisco Secure Access in the same way, there should not be as much configuration needed, because companies are really keen when it comes to deployment these days. We need to automate deployment. If they could do that with Cisco Secure Access as well, especially with big branches, it would be great. I have worked with almost 200 branches, so configuration in all these branches is needed for security. If this could be integrated and automated exactly like the auto VPN that happens on SD-WAN, it would be excellent.
Regarding support, I do not know what happened to Cisco. I contact them, and the support has been a pain. The quality of support has dropped so drastically that it is not even funny.
For how long have I used the solution?
I have been working with Cisco Secure Access since 2012.
What do I think about the scalability of the solution?
Our deployment process is mixed. We are deploying for different clients, so it depends on what client they have.
How are customer service and support?
Regarding support, I do not know what happened to Cisco. I contact them, and the support has been a pain. The quality of support has dropped so drastically that it is not even funny.
How was the initial setup?
The setup process for Cisco Secure Access is very straightforward. Integrating with SD-WAN is really easy.
Which other solutions did I evaluate?
We are fighting internally with Zscaler because they are saying it is cheaper. Pricing is competitive between solutions. Palo Alto is coming very well as well. I am not sure if Cisco is also looking at that, but they are also coming with a lot of functionality within the Palo Alto space for the SASE function.
What other advice do I have?
Cisco Secure Access does help me protect my company from threats like phishing and ransomware. The fact that Cisco Secure Access integrates Zero Trust, the secure gateway, and data loss integration does a lot to help with email security because of the integration with Cisco Web Gateway. Training users is also necessary because security involves users as well.
I am satisfied with the functionality of Cisco Secure Access. One of the areas I have not investigated much time on is the integration with the segmentation within the SASE solution. I have been doing it on my side, but I still need to understand how it integrates and how it can work instead of using the NAC solution. The ICE function could be integrated within Cisco Secure Access. I think that would be better because Cisco has integrated firewall as a service, so why not also integrate the NAC solution as a service in that platform as well.
I have given this review a rating of 9.