Set up a Cisco Secure Access Device Trust and DLP Connector

Microsoft Edge for Business partnered with Cisco Secure Access to create an advanced enterprise browser integration that brings the capabilities of Cisco Secure Access Trusted Endpoints and Cisco Secure Access DLP into the browser. The Trusted Endpoints integration attests that the Edge for Business browser is enrolled in enterprise device management, up to date with the latest and most secure version of Edge, and compliant with organizational policies before providing secure, browser-based access to private applications. Then, Secure Access DLP enables admins to block potential leak vectors for sensitive data, such as copy, paste, and print.

Learn more about this integration here.

Configuring the Cisco Secure Access connector

Prerequisites

This section assumes that you have a fully configured and deployed Cisco Secure Access organization. For additional instructions on setting up private resources and private resource policies, please see below:

  • Configure Private Resources: Private resources include private subnets and applications deployed and managed by your organization. Detailed instructions on setting up private resources, see documentation here.
  • Configure Private Access Policies: Private access policies allow you to define granular user-based access to private resources. Detailed configuration instructions are available here.
  • The Edge management service uses configuration policies to assign settings to the whole tenant or specific user groups. If no Edge configuration policy exists, create one first using these instructions.

Setting Up Microsoft Edge for Business integration with Cisco Secure Access

Configuring Cisco Secure Access Trusted Endpoints Connector

Step 1: Add Edge for Business Integration in Cisco Secure Access

  1. In the Cisco Secure Access dashboard, navigate to Admin > Third-party integrations and add a new Microsoft Edge for Business integration.
  2. Note the redirect URI displayed, as it will be required during Microsoft registration, click Copy.

Step 2: Retrieve Tenant ID from Microsoft Entra

  1. Navigate to the Entra admin portal at https://entra.microsoft.com/. On the Entra Admin Center overview card, copy the Tenant ID and keep it available for later use.
  2. Navigate to Entra ID > App Registrations, and create a new registration. Set the supported account type to single tenant only, set the redirect URI platform to Web, and paste the URI copied from the Secure Access dashboard, then click Register.
  3. After the app is created, copy the Application (client) ID from the Overview page. This is the second required value for Cisco Secure Access.
  4. Next go to Certificates and Secrets > Client Secrets, and add a new client secret with a name and expiration matching your rotation policy. Copy the secret value immediately after creation, as it cannot be retrieved again, this is the third value required.
  5. Next, open API permissions. Add a permission for Microsoft Edge Management Service.
  6. Before selecting it, copy its Application ID (the resource app ID for Secure Access).
  7. Select Application permissions, choose Device Trust Read All, and grant admin consent for the organization and click Add permissions.

Step 3: Configure Cisco Device Trust Connector in the Edge management service

  1. Navigate to https://admin.cloud.microsoft/?#/Edge/Connectors.
  2. Find the Cisco Secure Access Device Trust connector, and click Set up.
  3. Select the desired configuration policy and set the URL pattern to the redirect URI from the Secure Access dashboard.
  4. Click Save configuration.

Step 4: Enter Collected Values in Secure Access Dashboard

  1. Return to the Cisco Secure Access dashboard and fill in the four collected values under Admin > Third-party integrations > Edge for Business:
    • Tenant ID
    • App Client ID
    • Microsoft Edge Services Application ID
    • The client secret from the app registration
  2. Enter an Integration name and click Integrate.

Step 5: Add posture profile

  1. In Secure Access, navigate to Secure > Endpoint Posture Profiles add a new posture profile and select browser-based.
  2. Name the profile, choose Edge for Business from the browser list, and optionally configure additional criteria such as OS version, firewall state, or disk encryption.

Step 6: Apply Posture Profile to Access Policy Rule

  1. Edit an existing rule, or, create a new access policy and select the newly created under Zero Trust Browser-based Posture Profile, then click Next then Save.

Configuring Cisco Secure Access DLP connector

Step 7: Configure Cisco DLP in Secure Access

  1. In the Secure Access dashboard, add a new API key by selecting Admin > API Keys. Click Add.
  2. For the scope choose DLP > DLP As A Service > Read-Only then click Create Key.
  3. Generate the key and immediately copy both the key and the secret, as the secret cannot be retrieved after leaving the page.

Step 8: Configure Cisco DLP Connector in the Edge management service

  1. Navigate to https://admin.cloud.microsoft/?#/Edge/Connectors.
  2. Find the Cisco Secure Access Data Loss Prevention connector, and click Set up.
  3. Select the desired configuration policy.
  4. Paste in the API key and secret from Secure Access and set the URL pattern to the redirect URI from the Secure Access dashboard.
  5. Enable desired DLP actions and set fail behavior.
  6. Click Save configuration to activate the connector.

Step 9: Validation - Create Real-Time DLP Policy Rule in Secure Access

  1. To validate, in the Cisco Secure Access dashboard, go to Secure > DLP Policy, and add a real-time rule and choose a template (for example, the PII template).
  2. Select any additional rule criteria like Identity and Action, then save the rule to complete DLP configuration.

Congratulations! The advanced enterprise browser integration is now complete. Cisco Secure Access Trusted Endpoints and Cisco Secure Access DLP are successfully enabled in the Edge for Business browser.