Client type: Public sector
Industry: Education
Solutions: Cisco SD-Access Fabric
The education sector, from school service centres to university campuses, presents a complex challenge of access rights, devices and multiple identities. With teachers and students often using their own devices (BYOD) as well as classroom equipment, how can organizations strengthen security without making account and access management more cumbersome?
The challenge: managing permissions without complications
Legacy segmentation limits agility.
Today’s solutions make it possible to segment as close as possible to the source: the user.
Our solution: replacing the IP address with identity through SD-Access Fabric
With Cisco Identity Services Engine (ISE), permissions are based on identity, regardless of who is moving, where they are on campus, or whether they connect through a wired or wireless network. Users are added to a virtual network with access rights.
Since ISE integrates natively with other tools, identities are aligned with existing profiles in another user database, such as Active Directory or Microsoft Entra ID. It is therefore a simple solution to implement with the infrastructure already in place by importing all groups and using them as a point of definition for identities.
Result: effective micro-segmentation, without added complexity
With SD-Access Fabric and micro-segmentation, security is enabled by default without having to define any security policy. Permissions are granted based on what has been assigned to identity types, such as student or teacher.
As a result, the same person keeps the same permissions no matter where they connect from or which device they use. For example, a teacher can move from their tablet to the computer in their lab. Micro-segmentation, through SGT identity (Secure Group Tag), defines access rules within the same virtual network.
Benefit: stable and secure access, regardless of location or device
SD-Access Fabric enables
Cisco’s modern security approach is particularly well suited to education environments, where a wide variety of managed and unmanaged devices (BYOD) coexist. Users need to access educational and administrative resources from multiple campuses, remote sites or off-site locations, while benefiting from a simple and seamless experience. Through an architecture based on Zero Trust principles, identity-based access control, network segmentation and application visibility, Cisco makes it possible to apply consistent and granular security policies while ensuring a smooth user experience, regardless of the device used, the network accessed or the user’s location.
Also: the same simplicity and fluidity for connected devices
With SD-Access Fabric, devices and IoT objects (Internet of Things) can also be authenticated and authorized, just like users.
Think of different types of equipment connected to the network, such as:
- Cameras
- Building access control systems
- Fire safety devices
- Sensors and thermostats
- HVAC controllers
- Etc.
Each device has specific connectivity needs depending on the solution associated with it. Some require Layer 2 extension across the entire campus, while others support older protocols. Very often, the solutions behind these devices must be managed and operated by external providers.
SD-Access Fabric therefore offers the same mobility and built-in security benefits as it does for users, while also making it easier to isolate connections for external providers.
From a technical standpoint, there is no longer any static port configuration; everything is dynamic. This brings significant operational efficiency gains for IT teams.