Is Cisco Identity Intelligence the future of Zero Trust Network Access (ZTNA)?
With Cisco's recent focus on "Identity Intelligence" at Cisco Live, I’m curious how this changes the traditional SASE model. How does this new identity-centric approach integrate with existing Duo MFA and Cisco Secure Access to prevent identity-based attacks like session hijacking in a distributed workforce?
2025-03-25 in Cyber Security by Kevin Foster
| 17412 Views
All answers to this question.
Cisco Identity Intelligence acts as an analytics layer that sits on top of your existing identity stores (like AD or Okta). The goal is to move beyond static permissions and toward "continuous trusted access." By analyzing behavior across the network, it can detect if a valid user's session has been hijacked—even if they passed the MFA check. It bridges the gap between the identity provider and the network fabric. When integrated with Cisco Secure Access (the SASE component), it can automatically revoke a session or trigger a re-authentication if it notices the user is suddenly accessing sensitive data from an unusual location.
Answered 2025-03-27 by Dorothy Young
How much latency does this behavioral analysis add to the initial login process, and can it be tuned for different user roles within the organization?
Answered 2025-03-29 by Kenneth Hill
-
Kenneth, the beauty of this system is that it’s asynchronous. The heavy lifting of the behavioral analysis happens in the background, so it doesn't slow down the actual login "handshake." It continuously scores the risk of the session after the user is in. You can definitely tune the policies so that an engineer accessing the core routers has a much stricter "risk tolerance" than an HR employee accessing a public-facing portal. It’s all about contextual awareness without ruining the user experience.
Commented 2025-03-30 by Brian Scott
This is definitely the way forward. Most breaches today start with compromised credentials, so shifting the focus from the perimeter to the identity is a logical step.
Answered 2025-03-31 by Nancy Adams
-
Well said, Nancy. The "perimeter" is effectively gone in 2024. If the identity is the new perimeter, we need tools like this to monitor it 24/7, not just at the moment of login.
Commented 2025-04-01 by Kevin Foster
Write a Comment
Your email address will not be published. Required fields are marked (*)

