NEWFlows V2 has been releasedSee what shipped
INTEGRATIONSSECURITY
BS
Broadcom Secure Access Cloud28 OF 28 CAPABILITIES ASSESSED

Who can reach your private apps through Secure Access Cloud

Secure Access Cloud users, groups and access policies across every identity provider, with users blocked, removed and bound to policies from Ploy.

TYPE · SECURITYAUTH · OAUTH CLIENT CREDENTIALSDOMAIN · LUMINATESEC.COM
Broadcom Secure Access Cloud connectorHOURLY SYNCCAPABILITIES
WHAT PLOY DOES
Sync users from every identity providerEvery user in every identity provider on the tenant arrives in Ploy as an identity, the local directory included.
READ
Read blocked and deleted usersA blocked or deleted user shows as blocked and loses their Secure Access Cloud access in Ploy on the scan that sees it.
READ
Read last sign-in and MFAWhen each user last signed in, and whether a local directory user has set up a second factor.
READ
Map groups and their membersGroups from every identity provider land as resources, with the direct members of each.
READ
Map access policiesAccess policies, which grant access to your published applications, land as resources with the people bound to each one.
READ
Block and unblock usersPloy blocks a user, which ends their active sessions and stops further sign-ins, and unblocks them again.
WRITE
Delete usersPloy deletes a user from the local directory or a Generic SAML provider.
WRITE
Grant and revoke policy accessPloy binds a person to an access policy and unbinds them, from the policy's own page in Ploy.
WRITE
Add and remove local group membersPloy adds a local user to a local group and removes them again.
WRITE
2.1WHAT IT UNLOCKS

Three jobs this connector does on day one

ACCESS

A policy is granted from Ploy

A request for an access policy goes to its owner. The approval binds the person to the policy, and the grant can carry an expiry that unbinds them.

REVIEWS

Zero trust access in the same campaign

Policies and groups sit beside the rest of the estate, so a reviewer sees who can reach each private app and who has not signed in for months.

LEAVERS

Blocked on the last day

Offboarding blocks the user, which ends their sessions at once. A local or SAML user can then be deleted.

2.3

SETUP

TYPICALLY 10 MINUTES
STEP 01

Create an API client

In the Secure Access Cloud admin portal, create an API client. Give it the Tenant Admin role through a tenant role binding.

STEP 02

Connect the tenant

Enter the tenant name from your admin portal address, then the client ID and client secret.

STEP 03

Watch the first sync

Ploy tests the client against the tenant, then users, groups and access policies land in the graph.

2.4OFTEN CONNECTED TOGETHER
TailscaleCLOUD INFRASTRUCTUREOktaIDENTITY SOURCESlackAPPROVALS
BROWSE ALL 93 INTEGRATIONS

Connect Broadcom Secure Access Cloud, see it in 10 minutes.