Cisco Identity Intelligence (CII) Overview: What It Is and How to Choose a Relevant Cisco Path
Cisco Identity Intelligence (CII) is a Cisco security capability, not a certification tier or exam pathway in the supplied official material. Cisco describes it as an AI-powered solution connecting authentication with access, while related documentation explains its use with Duo, Secure Access, Security Cloud Control, and Cisco XDR. This overview helps readers avoid choosing a credential based on an acronym alone. It explains what CII covers, which security audiences may need related knowledge, what the official sources do and do not establish about certification, and how to select a sensible Cisco learning or certification direction.
Start by identifying what CII means
CII refers here to Cisco Identity Intelligence, a Cisco security solution rather than a named certification level. Cisco describes Identity Intelligence as an AI-powered solution intended to bridge the gap between authentication and access. Its purpose is to give organizations broader identity context when assessing access activity and risk. [https://www.cisco.com/site/us/en/solutions/security/identity-intelligence/index.html]
The distinction matters because a product name, integration, or feature area does not automatically represent an exam, badge, or credential. The supplied official sources describe product capabilities, activation, configuration, licensing, and integrations. They do not identify a CII certification, exam code, certification level, prerequisite, renewal policy, delivery method, or passing requirement.
Readers searching for a CII certification should therefore verify whether they mean Cisco Identity Intelligence or a different organization, credential, or acronym. Treating CII as a Cisco product area is the evidence-supported interpretation for this overview.
What Identity Intelligence is designed to address
Cisco says fragmented identities can make it harder to assess user trust consistently, apply policy, and detect breaches. The documented sources describe identity fragmentation across traditional identity providers such as Entra ID, Duo, and Okta; other sources such as GitHub, Google, and Salesforce; and HR systems such as Workday. [https://securitydocs.cisco.com/docs/csa/olh/136576.dita]
Cisco’s product description defines an identity as one user listed in the Cisco Identity Intelligence interface. The product documentation also says that associating an identity source with Identity Intelligence provides user and device risk ratings to Security Cloud Control. [https://www.cisco.com/c/dam/en_us/about/doing_business/legal/OfferDescriptions/duo-product-description.pdf] [https://securitydocs.cisco.com/docs/scc-fw/ftd/manage/160887.dita]
In practical terms, CII is concerned with bringing identity-related information together so security teams can examine activity, account exposure, privileges, and access risk in a wider context. Cisco says the intended outcomes include identifying identity activity, cleaning up vulnerable accounts, eliminating risky privileges, and blocking high-risk access attempts. [https://www.cisco.com/site/us/en/solutions/security/identity-intelligence/index.html]
Understand the surrounding Cisco ecosystem before choosing a learning path
The most relevant preparation direction depends on which Cisco platform your work touches. The official material places Identity Intelligence alongside Duo, Security Cloud Control, Secure Access, Secure Firewall management, and Cisco XDR, so readers should select a path based on their operational responsibility rather than on the CII acronym alone.
A learner who administers identity sources may need to understand how identity data is connected and how risk information is used. A Secure Access administrator may need to focus on the integration workflow and the configuration choices that follow it. A security operations practitioner may be more concerned with how CII context appears in Cisco XDR investigations. A firewall administrator may encounter Identity Intelligence through Security Cloud Control and risk ratings associated with identity sources.
These are practical audience distinctions, not official Cisco certification tracks. The supplied sources do not map any of these responsibilities to a particular Cisco credential. They do, however, provide enough product context to help a reader decide which documentation and hands-on area should come first.
Identity and access administrators
This audience should begin with the relationship between identity sources, user records, device context, and access decisions. Cisco’s documentation presents Identity Intelligence as a way to bring together fragmented identity information and make that information available for trust and risk assessment. [https://securitydocs.cisco.com/docs/csa/olh/136576.dita]
A useful readiness indicator is the ability to explain where an organization’s identities originate, how duplicate or fragmented records affect investigations, and which administrator owns each source. Product familiarity should include Duo and the identity providers relevant to the organization, but the supplied evidence does not prescribe a training sequence or credential requirement.
Secure Access administrators
Secure Access administrators should concentrate on the integration lifecycle. Cisco’s guidance describes integrating Cisco Identity Intelligence with Secure Access and separately provides follow-up guidance for what to do after the integration. [https://securitydocs.cisco.com/docs/csa/olh/136576.dita] [https://securitydocs.cisco.com/docs/csa/olh/136579.dita]
Cisco recommends integrating available third-party products and identity providers after integrating Cisco Identity Intelligence, with particular emphasis on Duo Directory. That recommendation makes source planning an important preparation topic: an administrator should know which identity providers exist, which are authoritative, and how the organization will validate the resulting identity context. [https://securitydocs.cisco.com/docs/csa/olh/136579.dita]
Security operations and XDR users
Security operations teams should examine how CII information supports triage and investigation. Cisco says the Cisco XDR integration connects Identity Intelligence through Cisco Security Cloud Control and exposes CII-known users and identities in XDR User Insights. Cisco also says that this context can populate account information in incidents and investigations. [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence]
The XDR source also lists a workflow for ingesting critical threat checks and notes that an older workflow has been replaced by a version using XDR Detection Findings. Anyone preparing around this integration should use the current Cisco documentation and interface rather than relying on older workflow descriptions. [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence]
Firewall and Security Cloud Control administrators
Firewall administrators may encounter Identity Intelligence through Cisco Security Cloud Control rather than through a standalone identity project. Cisco documents configuring Identity Intelligence in the Security Cloud Control firewall-management documentation and states that associating an identity source provides user and device risk ratings to Security Cloud Control. [https://securitydocs.cisco.com/docs/scc-fw/ftd/manage/160887.dita]
This audience should first determine whether the role includes identity-source administration, firewall policy, cloud-delivered management, or incident investigation. Those responsibilities overlap, but the supplied sources do not establish a single CII credential covering all of them.
Do not mistake product documentation for certification requirements
No official certification structure is established in the supplied sources for Cisco Identity Intelligence. They do not list CII credential levels, exam objectives, eligibility rules, prerequisites, registration steps, renewal terms, prices, delivery options, or score policies. Those details should not be inferred from the product documentation.
This limitation is especially important for readers comparing certification paths. A product overview can explain what a technology does, but it cannot prove that the vendor offers a certification for that technology. Before paying for an exam or preparation resource, confirm the credential’s exact name and status on an official Cisco certification page or certification catalog. That official certification evidence was not included in the supplied source set.
If a third-party page labels CII as a certification, compare its claim against Cisco’s own credential information. Look for an official exam page, an official certification page, an exam topic outline, or a Cisco learning reference that explicitly connects the credential to Identity Intelligence. Without that connection, treat the claim as unverified rather than as a program fact.
Facts that can be confirmed from the supplied Cisco sources
Cisco describes Identity Intelligence as an AI-powered solution connecting authentication and access. It is intended to provide visibility into identities and support work such as identifying activity, addressing vulnerable accounts, reducing risky privileges, and blocking high-risk access attempts. [https://www.cisco.com/site/us/en/solutions/security/identity-intelligence/index.html]
Cisco documents integrations involving Security Cloud Control, Secure Access, Duo, and Cisco XDR. The XDR integration can show CII-known users and identities in User Insights. [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence]
Cisco documents commercial and activation conditions that affect implementation, including Duo identity allocation and the relationship between a Duo instance and a Security Cloud Control organization. These are product and subscription considerations, not certification requirements. [https://www.cisco.com/c/dam/en_us/about/doing_business/legal/OfferDescriptions/duo-product-description.pdf] [https://securitydocs.cisco.com/docs/scc/gsg/new/160090.dita]
Claims that should remain unconfirmed
The supplied sources do not confirm that CII has beginner, associate, professional, or expert certification levels. They also do not confirm that a Cisco security certification requires CII knowledge.
They do not confirm a CII exam, a CII practice test, a CII badge, a CII renewal cycle, or a CII-specific training course. Readers should not use an unsupported exam code, price, date, duration, or pass-rate claim when evaluating this area.
They also do not establish that learning CII alone qualifies someone for a job, produces a salary outcome, or guarantees success in any Cisco exam. A sensible preparation decision must be based on the actual credential requirements and the learner’s intended role.
Use the official product workflow as a practical readiness framework
For product learning, the strongest preparation approach is to follow the documented implementation sequence and connect each step to an operational decision. This is a practical recommendation based on Cisco’s product guidance, not an official certification syllabus.
Begin with identity inventory. List the providers and business systems that contain user or identity information, then identify where fragmentation could affect trust assessment, policy consistency, or breach detection. Cisco’s documentation explicitly names a range of traditional, non-traditional, and HR sources, so preparation should reflect the organization’s actual environment rather than assume a single directory. [https://securitydocs.cisco.com/docs/csa/olh/136576.dita]
Next, clarify ownership and access. Decide who will administer the Cisco organization, who controls Duo, who manages identity providers, and who reviews risk information. This preparation step is particularly important because Cisco’s activation guide warns that selecting the wrong initial Duo administrator can stop activation and require an activation reset. [https://securitydocs.cisco.com/docs/scc/gsg/new/160090.dita]
Then study the integration points relevant to the role. Secure Access administrators should work through the Identity Intelligence integration and the documented actions after integration. Security operations teams should review how CII-known identities appear in XDR User Insights. Firewall administrators should understand how identity-source association supplies risk ratings to Security Cloud Control. [https://securitydocs.cisco.com/docs/csa/olh/136576.dita] [https://securitydocs.cisco.com/docs/csa/olh/136579.dita] [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence] [https://securitydocs.cisco.com/docs/scc-fw/ftd/manage/160887.dita]
Finally, validate the result. Check whether the expected identities are visible, whether risk context is available where the team needs it, and whether XDR or Secure Access workflows reflect the intended data. Use the current Cisco configuration documentation for interface details and availability because product behavior and documentation can change.
A study plan for administrators
A role-based study plan should answer four questions: what sources are connected, what identity data is represented, where risk ratings are consumed, and which team responds to a high-risk access signal. Write the answers down before attempting configuration. This turns a broad product topic into a manageable set of operational decisions.
Use Cisco’s activation and integration documentation as the primary reading. Recreate the terminology in a controlled environment where possible, but do not assume that a test configuration proves production readiness. Document administrator ownership, source mappings, permissions, and rollback considerations separately from the product’s conceptual features.
Avoid preparing through memorized interface labels alone. Identity Intelligence depends on relationships among sources, identities, devices, access, and investigation context. Understanding those relationships is more durable than remembering an isolated screen sequence.
A study plan for security operations teams
Security operations learners should start with the investigation question: what additional identity context would help an analyst decide whether activity is trusted, risky, or in need of escalation? Then trace how that context reaches Cisco XDR through Security Cloud Control and where it appears in User Insights or an incident. [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence]
Review current workflows carefully. Cisco’s XDR integration page distinguishes a current workflow based on XDR Detection Findings from a legacy workflow. That distinction is a reminder to verify the current implementation before building procedures or study notes around an older workflow name. [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence]
A useful exercise is to create an investigation checklist that records the identity source, associated user or identity, device context, access activity, and relevant risk information. The checklist is a practical recommendation, not a Cisco exam objective.
Review licensing and activation boundaries separately from learning goals
Product licensing and activation can affect an organization’s implementation, but they should not be confused with credential eligibility. Cisco’s Duo product description says that each Duo Advantage or Duo Premier user license allocates up to five identities in Cisco Identity Intelligence. It also says that exceeding the allocation may require the customer to purchase additional Duo user licenses after good-faith efforts to resolve the excess usage. [https://www.cisco.com/c/dam/en_us/about/doing_business/legal/OfferDescriptions/duo-product-description.pdf]
The same product description defines an identity as one user listed in the Cisco Identity Intelligence interface. A team estimating implementation scope should therefore clarify how the organization’s user populations will be represented and what its subscription terms cover. Do not reuse these product-allocation facts as a statement about exam capacity, learner counts, or certification limits.
Cisco also states that the Identity Intelligence integration through Security Cloud Control is included at no additional charge with any Secure Access subscription, but that inclusion does not include the standalone Identity Intelligence dashboard. This is a subscription interpretation, not a general statement that all CII capabilities are free or that a certification is included. [https://securitydocs.cisco.com/api/v0/apps?appId=SecureAccess&topic=integrate-cisco-identity-intelligence]
Activation decisions deserve separate attention. Cisco documents that once a Duo instance is activated in a Security Cloud Control organization, it cannot be reused or attached to a different organization. The activation guide also warns about choosing the wrong initial Duo administrator. These constraints make administrative planning part of implementation readiness. [https://securitydocs.cisco.com/docs/scc/gsg/new/160090.dita]
Questions for a purchasing or platform team
Before enabling the service, ask which Security Cloud Control organization should own the Duo instance, who should be the initial administrator, which Secure Access subscription is in place, and whether the organization needs the standalone Identity Intelligence dashboard.
Also ask how identities will be counted under the applicable Duo terms, how excess usage will be handled, and which support or account team should resolve subscription questions. Cisco’s official product description is the appropriate source for the contractual details; the supplied facts should not be extended beyond their stated scope. [https://www.cisco.com/c/dam/en_us/about/doing_business/legal/OfferDescriptions/duo-product-description.pdf]
Questions for a learner comparing credentials
Ask whether the target role is identity administration, secure access, security operations, firewall management, or a broader Cisco security function. Then identify the official Cisco credential whose published objectives match that role. The supplied CII sources do not provide that credential mapping.
Check the official credential’s current exam name, objectives, prerequisites, delivery, renewal, and cost before selecting preparation material. If those details are absent from an official Cisco certification source, do not treat a third-party summary as definitive.
Finally, separate product familiarity from certification readiness. A learner may need to understand CII for a job or implementation without there being a CII-specific exam. Conversely, a Cisco security exam may cover broader domains than Identity Intelligence. Only the official exam objectives can establish the relationship.
Choose a path by responsibility, not by the acronym
The sensible next step is to match your work to the product area and then verify any formal Cisco credential independently. CII itself should not be presented as a hierarchy of certifications when the supplied official evidence describes only Cisco Identity Intelligence and its integrations.
Choose an identity-focused learning direction if your responsibility is to understand fragmented identities, identity sources, user and device risk, and access context. Choose a Secure Access direction if you configure or operate the integration and its surrounding access controls. Choose a Cisco XDR direction if your work is investigation, incident context, or automation using CII information in XDR. Choose a Security Cloud Control or firewall-management direction if Identity Intelligence appears in your cloud-delivered firewall administration.
These choices can overlap. An administrator responsible for both access and investigations may need more than one area of knowledge. That does not mean the vendor has published a combined CII certification; it means the operational environment crosses product boundaries.
Readers who specifically need a Cisco certification should start from the official Cisco certification catalog, locate the credential that matches the intended role, and compare its published objectives with the CII responsibilities described here. Because no certification catalog or exam page was supplied for this article, exact credential names, levels, requirements, prices, dates, and renewal rules are intentionally not stated.
A decision checklist
Use this checklist before committing to a course, exam, or practice resource:
• What does CII mean in the target job or project? Confirm that it means Cisco Identity Intelligence.
• Which Cisco platform will you administer or use: Duo, Secure Access, Security Cloud Control, Cisco XDR, or firewall management?
• Which identity providers and business systems must the organization connect? Cisco documentation identifies sources including Entra ID, Duo, Okta, GitHub, Google, Salesforce, and Workday, but the relevant set varies by environment. [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence]
• Do you need product implementation skill, incident-investigation skill, or a formal Cisco certification? These are related but different goals.
• What official Cisco source confirms the credential’s objectives and current requirements?
• Have you checked subscription, activation, organization ownership, and identity-allocation implications separately from your learning plan?
• Are your study materials based on current Cisco documentation, especially where a source identifies a legacy workflow or changing product interface?
Readiness indicators that are actually useful
You are better positioned for product-focused work when you can explain the organization’s identity sources, identify likely fragmentation, describe who owns activation and administration, and trace how identity context reaches the platform used by your team.
For Secure Access work, you should be able to discuss the integration sequence and the follow-up integration of available third-party products and identity providers. For XDR work, you should be able to explain how CII-known users and identities support User Insights and investigations. For firewall-management work, you should understand the role of identity-source association and risk ratings in Security Cloud Control. [https://securitydocs.cisco.com/docs/csa/olh/136579.dita] [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence] [https://securitydocs.cisco.com/docs/scc-fw/ftd/manage/160887.dita]
These indicators assess practical understanding, not exam readiness. Exam readiness requires the objectives and policies for the specific official Cisco credential selected by the reader.
How to use Cisco sources without overreading them
Use the product page for the high-level purpose, the Security Cloud Control guide for activation and organization decisions, the Secure Access documentation for integration steps, the XDR integration page for investigation context, and the Duo product description for subscription terms. Each source answers a different question.
The Cisco Identity Intelligence product page explains the problem space and intended outcomes. [https://www.cisco.com/site/us/en/solutions/security/identity-intelligence/index.html] The Secure Access documentation explains the integration and the recommended actions after integration. [https://securitydocs.cisco.com/docs/csa/olh/136576.dita] [https://securitydocs.cisco.com/docs/csa/olh/136579.dita] The Security Cloud Control guide explains activation boundaries and administrator considerations. [https://securitydocs.cisco.com/docs/scc/gsg/new/160090.dita] The XDR page explains how CII connects to XDR and how identity context is exposed. [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence]
Do not use a configuration guide as proof of an exam syllabus. Do not use a commercial product description as proof of a certification rule. Do not use a product integration page as proof of a credential level. Keeping those evidence types separate is the most reliable way to compare a genuine certification path with product-specific training.
Why current-source checking matters
Cisco’s XDR integration material identifies a legacy workflow and says it has been replaced by a workflow using XDR Detection Findings. That example shows why readers should check the current official page before relying on a copied workflow name or older course description. [https://connect.xdr.security.cisco.com/integration/cisco-identity-intelligence]
The supplied Security Cloud Control guide also carries a dated documentation context, while product availability, interfaces, and commercial terms can change. This article therefore avoids unsupported time-sensitive certification claims and directs readers back to official Cisco sources for current decisions.
Conclusion
Cisco Identity Intelligence is best understood as a Cisco security product area that connects identity information with access and investigation context, not as a verified standalone certification ecosystem in the supplied evidence. Readers should choose their next step by role: identity and access administration, Secure Access integration, Cisco XDR operations, or Security Cloud Control and firewall management. After identifying that responsibility, verify the relevant Cisco certification separately through an official credential source. Keep product capability, implementation readiness, licensing, and formal certification requirements distinct; that separation leads to a more accurate and defensible learning plan.
Related exams
- Insurance Legal and Regulatory (IF1) Exam
- E05 exam — Examination element of M05 Insurance law
- M92 exam — Insurance Business and Finance (IBF)
- M05 exam — Insurance law (IL) Exam