
Overview
Beyond Identity Secure Access is the first Secure-by-Design IAM solution that defends against modern threats with security guarantees.
It delivers a security-first SSO, phishing-resistant MFA, visibility and control over managed and unmanaged devices, robust integrations, and protections over generative AI fraud.
For mid-sized organizations, Secure Access provides the unified platform you need to safeguard authentication and access with robust integrations that help you get more value out of your existing tooling.
For enterprise organizations, Secure Access delivers a modular platform to support your specific needs for authentication, device security, and SSO or supplant existing solutions that fall short on their security promise.
Please reach out for custom and volume-based pricing via Private Offer at https://www.beyondidentity.com/get-demo
Highlights
- Validates a user identity and its association with a verified device that meets security policy to deliver trusted authentication and enforces continuous, risk-based authentication.
- Enables password elimination. Replaces passwords with an authentication platform rooted in asymmetric cryptography leveraging proven standards (including x.509 certificates and the TLS protocol) without any certification management required.
- Provides zero friction, secure digital access for employees, contractors, and developers. It is the 1st foundational step toward today's Zero Trust Security strategy.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
- Small Market Bundle | Customizable SMB Bundle | $10,000.00 |
- Authentication Essentials | Includes: Phishing-Resistant MFA, Access360, Device 360, Premium Support for up to 1,000 users | $36,000.00 |
- Zero Trust Identity & Device | Includes: Zero Trust Authentication, Access360, Premium Support for up to 1,000 users | $96,000.00 |
- Secure Access Complete | Includes: Secure SSO, Zero Trust Authentication, Access360, Premium Support for up to 1,000 users | $144,000.00 |
Dimensions summary
Top-of-mind questions for buyers
Vendor refund policy
N/A
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Unified access control has strengthened zero trust while integration and automation still need work
What is our primary use case?
We use Cisco SD-WAN in our own company for our own needs, and we are also selling this to our customers while performing operations for customer networks. My personal customer scope is the large enterprise customer. We have integrated Cisco Identity Intelligence with Cisco Secure Access using Cisco ISE.
How has it helped my organization?
This integration has influenced our identity management and security measures significantly, as we use Cisco ISE to harmonize the access control, leading us towards a zero-trust network environment.
What is most valuable?
The advantages I see in Cisco Catalyst SD-WAN compared to their competitors is the seamless service scope, where I can have from Cisco the LAN, Wi-Fi environment, the SD-WAN environment, and the security environment, and as now announced from Cisco, all the management is combined in one orchestrator, which is the most beneficial aspect for me, not looking for the best of breed but more looking for the best fit.
I have used the policy verification to help reduce policy misconfigurations.
The multi-organization management capability of Cisco Secure Access in terms of usability and efficiency is quite good, as there is an RBAC system, allowing me to granularly define the access roles. I would rate this an eight.
What needs improvement?
For SD-WAN, I do not see any room for improvement, but for Cisco Secure Access, I think there is a lot to do for Cisco to integrate that in the Telco enterprise environment for seamless operation.
I am not talking about the integration with third-party solutions; you need to control the SD-WAN security policies in the same hand with the cloud security, and currently, both are managed by two different management systems, so you need to integrate that seamlessly.
It could be better from Cisco. The API interfaces, for example, Terraform integration, could be quite useful because there are some customers looking for full automation, and therefore it would be good to have a Terraform integration.
Some other companies are better on the market currently when it comes to the AI Access feature of Cisco Secure Access for providing deep visibility and control over AI applications, tools, and LLMs. If you compare it with the AI capability of Juniper Mist, Cisco needs to do a little bit more.
IPsec is a very old protocol, and sometimes it is good to see if there are some alternatives for VPNs in Cisco Secure Access.
I would like to see flexible access to the cloud in the next release to make it better. Currently, you set up one IPsec tunnel and that is all, which I think is not sufficient. There could be a better way, and what is missing are some virtualization services and security services in Cisco Secure Access cloud environment, especially for dedicated customers, such as governance and so on.
For how long have I used the solution?
I have been dealing with Cisco SD-WAN for ten to fifteen years.
How are customer service and support?
Technical support is perfect, and I find it fine. I would rate their support an eight out of ten.
There is still room for improvement when it comes to response time, especially if you need some response from the US. If you need support from the US side, you can see the different countries, and sometimes it takes very long to get an approval from the US side, which is something that could be better.
How was the initial setup?
The initial setup of Cisco Secure Access was not straightforward. There were a lot of discussions, especially with our customer about what the benefits are, particularly regarding the cost and the cost-benefits ratio, with discussions being more governance-driven or management-driven rather than technical, which meant it took a lot of time.
What's my experience with pricing, setup cost, and licensing?
In my experience with the Experience Insights feature or Digital Experience Monitoring of Cisco Secure Access, ThousandEyes is a fine tool, but currently, my experience with our customer is that it is too expensive just to have it. It is nice to have, but it is not business-critical, and therefore it is too expensive.
The overall pricing of Cisco Secure Access has changed dramatically in the last half year, and I would say it is too high.
I think Cisco should consider their licensing model, as anything could be improved.
What other advice do I have?
Currently, AI Supply Chain Risk Management is not really an issue for us today. I would rate Cisco Secure Access a seven out of ten overall.
Unified cloud security has simplified zero trust access and protected hybrid users
What is our primary use case?
My main use case for Cisco Secure Access is for one client, where I deployed DNS security. Previously, Cisco DNS security was part of Umbrella; now, it has been moved to Cisco Secure Access. I implemented DNS security, which provided the client with cloud-based DNS security and intelligent proxy features, so they are protected from day-zero attacks with policy management in place. That was one use case for Cisco Secure Access, and for another client, I have recently deployed ZTNA using Cisco Duo MFA.
For a specific example of how I used Cisco Secure Access for one of these clients, I will provide the example of one client where I deployed ZTNA through MFA. The client has around 1500 users working in a hybrid environment, so connecting every user on the VPN, whether hardware-hosted, VM-hosted, or anywhere else, causes unnecessary burden. SASE is the best use case of Cisco Secure Access in the hybrid environment, where if users want to access any of their private applications, they connect to Cisco Secure Cloud. From the cloud, the traffic is tunneled, providing zero-trust access and requiring MFA to access any internal application. This way, since it is cloud-based security, the routing and everything is taken care of in the cloud, avoiding dependency on hardware infrastructure or overusing the link in the data center itself.
What is most valuable?
The best feature that Cisco Secure Access offers is a single platform where DNS security, ZTNA, and everything are in one place, all managed through a single cloud dashboard.
Having everything in a single platform and dashboard has made things easier for me and my clients because everything is available for checking or troubleshooting.
Cisco Secure Access has positively impacted my organization because we are Cisco preferred partners. We deploy everything for our clients, so it is not just about deploying it in our organization. Since we are a preferred partner, many clients requiring Cisco Secure Access are routed to us from Cisco.
After deploying Cisco Secure Access, I received specific positive outcomes and feedback from my clients. For the use case concerning DNS security over the last three months, their AD integration with Cisco Secure Access allows them to create user-based policies for DNS security based on identity and username. They also receive a dashboard to monitor reports on threats and everything online in the cloud. The customer is very happy that they are able to overview their organization, seeing the number of users utilizing maximum applications, the top talkers, and everything.
Cisco Secure Access has greatly impacted protecting my organization and clients from threats such as phishing and ransomware. Because it has ZTNA and is cloud-based with VMs deployed inside the network, it creates best practice tunnels required for accessing applications from day one. Thus, we can deploy with peace of mind without juggling best practices or opening only specific ports.
What needs improvement?
Cisco Secure Access can be improved by providing information about the location of the PoPs where users are connected. The guidelines in KSA say it is mandatory for the PoPs to be regional, similar to how Fortinet SASE discloses its PoP locations.
In terms of needed improvements around documentation and support, the documentation has been good for me. Since I deployed for the first time, I went through Cisco documents, which helped me a lot, and their program on the T-Cloud labs also provided great support. Completing the lab gave me the confidence to deploy for the customer. The documentation and the labs provided by Cisco are very good.
For how long have I used the solution?
I have been using Cisco Secure Access for the last six months.
What other advice do I have?
For others looking into using Cisco Secure Access, my advice is that it is a good solution and they should experience it.
I chose eight out of ten primarily due to only the PoP presence. I would rate the ease of managing Cisco Secure Access through its single cloud-managed console an eight.
In my experience, it is easy to navigate and manage everything from the console, but compared to the FortiGate SASE platform, FortiGate has a unified platform for all their products, while Cisco has each platform operating differently.
I use the Zero Trust Network Access (ZTNA) feature of Cisco Secure Access, and it is a great feature. We do not need to worry about the security of accessing applications from outside the environment. With ZTNA, each application access requires authentication, which is a truly great feature.
This ZTNA approach has positively changed my client's security posture, and there are no significant challenges or surprises. I rate this product eight out of ten.
Zero trust access has strengthened identity-based segmentation and simplified multi-tenant management
What is our primary use case?
I am dealing with Cisco Secure Access products. As a consultant and reseller, I am using it myself with Cisco Secure Access.
You can have tenants with Cisco Secure Access. Tenancy is obviously part of it, so you can have multiple tenants on Secure Access. Especially if you're a managed service provider, you can have multiple tenants where you just have to flip the feature and specify which tenant you're working in. I've used that before to manage multiple infrastructures, and all you have to do is change the tenancy. That is quite useful. It used to be like that for Umbrella as well. Cisco basically just translated it back to Secure Access, so the same feature on Umbrella is on Secure Access as well. We have used it.
How has it helped my organization?
It's a best practice recommendation to have Cisco Secure Access integrated with Cisco ISE. With that integration, you can do your segmentation using security group tags and create a micro-segmentation setup with more security. We do that integration.
It's very useful because you can have visibility, especially in terms of logging and knowing who's doing what with Cisco Secure Access. If you have integration with Cisco ISE, then you have a name to traffic. You can have an identity that shows who is doing this, because it's integrated to your Azure network, your Google Cloud, or Active Directory. This makes investigation easier. Additionally, you can do your segmentation based on users and other criteria.
What is most valuable?
I think Zero Trust Access for application is the feature I find most valuable in Cisco Secure Access.
I only use Cisco Secure Access' AI Access feature for troubleshooting. It has a log feature, and there isn't really any AI element in that. The AI feature is more having an AI tool at the top where you can ask a question to get visibility. You can ask what a log means or ask a question that you want the AI to answer for you. There's an AI icon at the top of the bar, and then you can ask questions. That's basically where the AI feature is. There's no AI in terms of the telemetry unless you ask the AI feature to do it for you. If you want the AI element for that, there's another feature that Cisco has that you have to add as a feature add-on.
Cisco Secure Access has a VPN as a service feature. You have that Zero Trust as well because it's almost a VPN but just for applications. You access the application encrypted, but you don't need a VPN tool to connect. You can just access the application, which is what Zero Trust basically is. If you want VPN as a service, Secure Access has it. If you want to allow remote access for a certain application, then you do the Zero Trust setup, which is also a VPN but you don't need a VPN client to make it work.
Most of the time, I recommend my customers to use Cisco Secure Access' Experience Insights feature for Branch Access, which is basically when you want to tunnel all your traffic. You probably have a gateway in a branch and then you create a tunnel with Secure Access and then you send all clients through that tunnel to Secure Access. Everything including web traffic can be visible. You can also use it for VPN. You can use it to protect applications like I mentioned earlier about Zero Trust. You want to create an application that users can access remotely without using a VPN client, then you can do a Zero Trust setup. You can also do a proxy setup where you send all your internet traffic through Secure Access. These are the four features that I like about Secure Access.
I use Cisco Secure Access' Hybrid Private Access feature for varying the enforcement location for ZTNA private traffic. ZTNA is Zero Trust Networking, the private one.
The policy verification feature helps reduce policy misconfigurations in Cisco Secure Access where you can check to make sure that all your policies are intact. That is something we definitely use, especially if you have a lot of rules going on. You want to make sure that your rules are intact and you don't have any conflicts going on anywhere. That is a feature I always recommend.
What needs improvement?
I think the AI element of Cisco Secure Access is just asking logs, and I think the AI element can certainly be improved. The first question about how AI can enhance telemetry, that feature is not really there. You do have some kind of AI type element in it, but it's not advanced enough. That's where it's lacking. It's quite good because it's cloud-based. Pricing is also an area for improvement. It is really expensive.
For how long have I used the solution?
I have been dealing with Cisco Secure Access for about two years.
How are customer service and support?
If you log a ticket with Cisco, they usually come back really quick. I would say nine out of ten.
What's my experience with pricing, setup cost, and licensing?
The pricing is not too bad because it's per headcount with Cisco Secure Access. You check how many clients you have. If you have 500 users, then you base your pricing on that. It's still expensive though. It's an expensive tool to have. I think they can do better in price. There are companies with better pricing options.
Which other solutions did I evaluate?
FortiGate cloud solution is what I usually recommend instead of Cisco Secure Access. They have something similar as well. If a customer says that Secure Access is too expensive for themselves, I recommend FortiGate because they're not too bad in pricing.
What other advice do I have?
The AI element of Cisco Secure Access should have better guidance on the logs. To be honest, I can't think of anything else because it's quite a robust feature. My overall review rating for Cisco Secure Access is nine out of ten.
Granular access control has protected critical media workflows and now secures high‑stakes events
What is our primary use case?
My main use case for Cisco Secure Access is especially for our security purposes as it provides secure access to only the permitted applications. We work on many applications where different teams come together. They are responsible for different clusters, different domains, different applications, and we are always in a requirement to have the selected level of access to a particular set of people. For that, Cisco Secure Access is a super tool to work with.
Initially, VPNs were used, but the problem with VPNs was that it provides access all at once, and then we cannot continuously perform those verifications.
In my day-to-day operations, we in Synamedia have three business units responsible for three different things: one is control plane, we are into the data plane, and there is a network team as well. Collectively, we are supporting a customer called Astro. There are different applications hosted on the same Kubernetes cluster. The thing is these are different BUs, so we are bound with the responsibilities and our action should be very much limited. To have a better solution where we can ensure that the right set of people have the right set of privileges and access, we have created Cisco Secure Access for different users accordingly. If anything needs to be done on the control plane side of things, that particular team can do it. If it requires only access to the data plane into the Kubernetes clusters, then the people in my team have those accesses, so they cannot touch on the control plane side, and the control plane team cannot touch on the data plane.
The third team, which is on the network side, we don't want to expose our data plane and control plane to them and want to keep the network very much secure with them. So all of us are using the same platform, but we have limited or restricted access, and that's why we can collectively work better ensuring that we are not encroaching into different territories, and everything works very smoothly.
Recently, we conducted the Olympics, where we had teams from Synamedia, Alibaba, and their affiliates, Mina Tech, involved. Since a lot of revenue is involved, it was an Olympic thing, and we cannot risk security. That's why we went with our Cisco Secure Access. Initially, Synamedia was itself Cisco, and then it moved out as a media domain out of Cisco. To ensure that there is a good level of security and proper access, the particular teams which are supposed to perform necessary actions and need to put their scripts on the platform were taking care of that specific domain. The beauty of that is every time you enter into any platform, you have to go through a series of authentication that needs to be handled appropriately. If you fail, then that particular person cannot enter the platform, making it super secure. With events such as NBAs and Olympics, we want it to be very much secured as there are hackers looking for ways to access our system. In that scenario, it becomes very important that we keep all our clusters, platforms, and applications secured with a trusted solution, and that's why we have gone for Cisco Secure Access.
What is most valuable?
I rely on continuous verification and application access the most in my day-to-day work. There are hundreds and thousands of applications running that need to be safe. We cannot just provide access to people since it's a very secured environment; a small mistake can cause bigger problems. Specifically, we operate at three levels on the same platform: Tier 1, responsible for basic monitoring; SROs who are more advanced engineers performing routine actions; and SREs with root privileges. Now, we can create three layers of access: Tier 1 gets access for monitoring only; SROs have privileges for a certain number of applications; and SREs have full access to do whatever is required, ensuring the people with the correct skill set and knowledge have the right access level. With most people working from home, it is crucial to protect our secure data from hackers and malicious attacks because they can exploit systems to bring the entire chain down quickly. It helps that there is a defined process with a series of sequences that need to be followed for logging in, and even post-login, there is a second layer of control ensuring privileges are used correctly without allowing mistakes that could cause platform blunders.
There is a very common threat that happened three or four years back which was ransom. People were knocking into platforms using credentials and taking over servers. An incident happened at MediaKind where they had an attack from a ransom that froze the origin server. Origin server freezing means all data comes from there, and if hackers compromise that and stop streaming, it can collapse the entire media stream, resulting in huge losses for broadcasters and advertisers. MediaKind faced this for around 30-40 minutes because they used the normal VPN. We quickly realized that this wasn't going to work because VPN just uses credentials that anyone can exploit. Later, we moved to Cisco Secure Access, which goes through MFA. You log into a client, then enter Microsoft Entra ID, followed by MFA, and you authenticate through your phone and authenticator. There are policy engines and ZTNA, and only then you can log into applications and perform tasks.
In my opinion, Cisco Secure Access offers excellent features, starting with application-level access, not network access, where each time a particular application needs to be accessed, there is a provision for that instead of giving entire network access. The verification feature is nice as it doesn't work as a one-time authenticator, but a continuous verification process occurs. It's more into a zero-trust model, where if it identifies a deviation, it will not let you go in. Everything is centralized and very secure, considering it's on the cloud.
What needs improvement?
There are times when Cisco Secure Access feels slow; it takes multiple attempts to log in, which can definitely improve. Even using the same password, it may fail at times, and then you get logged out after some time. I would prefer a faster login experience. Also, it only allows connecting to one environment at a time, which can be a challenge during dynamic expansions. If a solution could allow logging into multiple environments simultaneously before disconnecting from one, it would be great. For example, if we handle ten customers and three have issues, we must connect, check, disconnect, and then repeat for the next, which could be streamlined.
The overall experience with Cisco Secure Access is good, but the UI could use some enhancements; it's simple and somewhat outdated. Additionally, having alerts for malicious login attempts that trigger on team channels could really help the team.
For how long have I used the solution?
I have been using Cisco Secure Access for almost eight years, six years here and two years in Ericsson.
What do I think about the stability of the solution?
Cisco Secure Access is quite stable.
What do I think about the scalability of the solution?
Its scalability is excellent, as it handles member logins instantaneously.
How are customer service and support?
Customer support for Cisco Secure Access is very good. After facing an issue recently, I would rate customer support an eight out of ten.
Which solution did I use previously and why did I switch?
Before Cisco Secure Access, we were using VPNs, but we switched because it wasn't very secure; any exposed username and password posed a security threat.
What was our ROI?
We haven't broken down to the level of measuring ROI yet, but in terms of investment, it's been decent. We save effort, not just money, as it simplifies control and management. Previously, we managed numerous licenses for the same set of tasks, whereas with one license from Cisco Secure Access, we can multitask, providing application-level access and proper authenticators, making it a super tool overall.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing for Cisco Secure Access are quite reasonable by market standards, considering the wealth of features we receive; this is a critical factor for us in ensuring security at a reasonable price.
Which other solutions did I evaluate?
We evaluated other options, including F5 and FortiClient, but found that they were not as good compared to Cisco Secure Access.
What other advice do I have?
For those looking into using Cisco Secure Access, I would say it's a very good solution that fulfills your security needs. Cisco Secure Access is a good tool. I would give this product a rating of nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized zero trust access has improved secure remote work while AI consistently strengthens oversight
What is our primary use case?
My main use case for Cisco Secure Access is providing secure remote access to internal applications while enforcing Zero Trust security policies. For example, in a lab environment, I used it to securely connect to internal web applications without exposing them directly to the internet. I also used its Secure Web Gateway to monitor and filter web traffic based on organizational policies. Day-to-day, it helps ensure that only authenticated and authorized users can access specific resources, improving security while maintaining a smooth user experience for remote users.
One thing I appreciated about my main use case and the authentication process with Cisco Secure Access was how it centralizes access management and security policies in a single platform. Once authentication and access rules were configured, day-to-day administration became much simpler. It also provided good visibility into user access and security events, making it easier to identify and investigate potential issues. Overall, it improved security without creating unnecessary friction for end-users, which was one of the biggest advantages.
What is most valuable?
The standout features of Cisco Secure Access are its Zero Trust Network Access, ZTNA, Secure Web Gateway, and multi-factor authentication, MFA, integration. I also appreciate its centralized policy management, which makes it easy to enforce consistent security rules across users and devices. The detailed visibility into user activity and security events helps with monitoring and troubleshooting. Additionally, its cloud-based architecture provides secure access for remote and hybrid users without relying on traditional VPNs, making it both scalable and easy to manage. Overall, these features significantly improve security while maintaining a smooth user experience.
Compared with similar secure access solutions, Cisco Secure Access stands out because of its tight integration with the Cisco security ecosystem and its unified cloud-native platform. Instead of managing multiple separate tools, administrators can enforce consistent security policies from a single console. I also found the Zero Trust approach and detailed visibility into user activity to be stronger than many traditional VPN solutions. These features make it easier to secure remote users while simplifying management, making the platform a good fit for organizations with hybrid or distributed workforces.
What needs improvement?
Cisco Secure Access is a strong platform, but there are a few areas that could be improved. The initial setup and policy configuration can be complex, especially for organizations new to Zero Trust architecture. The user interface could be more intuitive, making advanced features easier to locate and configure. Reporting and analytics could also provide more customizable dashboards and detailed insights. Providing broader integration and simpler troubleshooting guides would help administrators resolve issues more quickly and improve the overall management experience.
I think Cisco Secure Access could benefit from deeper integrations with a wider range of third-party identity providers, SIEM platforms, and endpoint security solutions to simplify deployment in mixed-vendor environments. I would also like to see more built-in troubleshooting tools and guided policy recommendations, which would reduce the learning curve for new administrators and make ongoing management more efficient.
The reporting tools and third-party integrations could be more flexible and user-friendly. These are areas for improvement, but they do not outweigh the platform's overall strengths and value.
For how long have I used the solution?
I have been using Cisco Secure Access for approximately six months.
How was the initial setup?
The authentication process for users in Cisco Secure Access was generally straightforward and easy to configure. Integrating it with an identity provider and enabling multi-factor authentication, MFA, was smooth, and the user onboarding experience was simple. The main challenge was configuring access policies correctly for different user groups during the initial setup, as it required careful planning and testing. Once those policies were in place, authentication became reliable and seamless. Overall, the setup was manageable, and the platform provided a secure, yet user-friendly login experience.
What other advice do I have?
I would confidently recommend Cisco Secure Access to organizations looking to modernize secure remote access.
Cisco Secure Access has a strong approach to AI governance and security. I appreciate that its AI-driven capabilities are supported by Zero Trust principles, identity-based access controls, and continuous monitoring. The platform provides good visibility into user activity and helps detect suspicious behavior while maintaining strict security policies. From a governance perspective, centralized policy management and detailed audit logs support compliance.
I believe there is still room for improvement.
I find the AI capabilities of Cisco Secure Access to be accurate and reliable for most security-related tasks. The platform consistently identifies potential threats, provides relevant security insights, and helps prioritize alerts, which reduces manual effort for administrators. In my experience, the recommendations are generally actionable and aligned with security best practices. While no AI system is perfect and some alerts may require manual verification, the overall accuracy is high enough to improve operational efficiency and support faster decision-making. I would consider its AI output trustworthy for day-to-day security operations. I gave this review a rating of 9.