# SonicWall Cloud Secure Edge (CSE) Documentation > Cloud Secure Edge (CSE) is SonicWall's Zero Trust Network Access (ZTNA) and Security Service Edge (SSE) platform (formerly Banyan Security). This documentation helps administrators set up, configure, deploy, and manage CSE components; secure private resources, public applications, networks, and internet traffic; manage users and devices; and automate CSE through its REST API. ## Getting started - [What is Cloud Secure Edge?](https://cse-docs.sonicwall.com/docs/intro/welcome/) - [Quickstart](https://cse-docs.sonicwall.com/docs/quickstart/) - [API Guide](https://cse-docs.sonicwall.com/docs/api-guide/) - [API specification (OpenAPI / Swagger)](https://cse-docs.sonicwall.com/docs/api-guide/spec/) - [Release notes](https://cse-docs.sonicwall.com/docs/release-notes/) ## Documentation - [Access Policies](https://cse-docs.sonicwall.com/docs/access-policies/) - [Notes on Policy Enforcement](https://cse-docs.sonicwall.com/docs/access-policies/notes/): Details on how SonicWall Cloud Secure Edge (CSE) ensures policy requirements are met before entities are granted access to resources - [Access Policy Examples](https://cse-docs.sonicwall.com/docs/access-policies/policy-examples/): Tunnel Policy Configuration Scenarios - [Manage Roles](https://cse-docs.sonicwall.com/docs/access-policies/roles/) - [Services](https://cse-docs.sonicwall.com/docs/access-policies/services/) - [Manage Services](https://cse-docs.sonicwall.com/docs/access-policies/services/manage-services/) - [Introduction to the Command Center API](https://cse-docs.sonicwall.com/docs/api-guide/): Authenticate and configure the Cloud Secure Edge (CSE) via the API - [API Objects](https://cse-docs.sonicwall.com/docs/api-guide/objects/): Understand how CSE objects are represented in the CSE API, and how to express them in JSON - [API Object - access_tier](https://cse-docs.sonicwall.com/docs/api-guide/objects/access_tier/) - [API Object - access_tier_local_config](https://cse-docs.sonicwall.com/docs/api-guide/objects/access_tier_local_config/) - [API Object - connector](https://cse-docs.sonicwall.com/docs/api-guide/objects/connector/) - [API Object - policy](https://cse-docs.sonicwall.com/docs/api-guide/objects/policy/) - [API Object - registered_service](https://cse-docs.sonicwall.com/docs/api-guide/objects/registered_service/) - [API Object - role](https://cse-docs.sonicwall.com/docs/api-guide/objects/role/) - [API Object - saas_app](https://cse-docs.sonicwall.com/docs/api-guide/objects/saas_app/) - [API Object - service_tunnel](https://cse-docs.sonicwall.com/docs/api-guide/objects/service_tunnel/) - [pybanyan - CSE Python Library and CLI tool](https://cse-docs.sonicwall.com/docs/api-guide/pybanyan/) - [API Specifications](https://cse-docs.sonicwall.com/docs/api-guide/spec/): Explore CSE's RESTful APIs using the OpenAPI (Swagger) interface - [CSE Terraform Import Tool](https://cse-docs.sonicwall.com/docs/api-guide/terraform-import-tool/) - [CSE Terraform Provider](https://cse-docs.sonicwall.com/docs/api-guide/terraform/) - [SonicWall Cloud Secure Edge (CSE) Components](https://cse-docs.sonicwall.com/docs/banyan-components/) - [Access Tier](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/) - [Deploy Access Tier](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/deploy/): This section covers fundamental concepts (such as public and private DNS, network configurations, etc) used in deploying Access Tiers - [Datacenter Deployments](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/deploy/datacenter/) - [IaaS Integrated Deployments](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/deploy/iaas/) - [Simple Deployments](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/deploy/simple/) - [Install an Access Tier](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/install/): Installs and configure the Cloud Secure Edge (CSE) Access Tier in your environment - [Install an Access Tier Using AWS CloudFormation](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/install/cloudformation/): Install the Access Tier on an EC2 instance via CloudFormation stack - [Install an Access Tier using Docker](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/install/docker/): Install the Access Tier on a server running Docker - [Install an Access Tier using Debian Packages](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/install/packages/): Install the Access Tier on virtual or physical 64-bit Linux servers, on-prem or cloud - [Install an Access Tier using Tarball](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/install/tarball/): Install the Access Tier on virtual or physical 64-bit Linux servers, on-prem or cloud - [Install an Access Tier Using Terraform](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/install/terraform/) - [Manage Access Tier](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/manage/) - [Monitoring Netagent](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/manage/monitor/): Aggregate and summarize networking metrics for the Access Tier - [Access Tier Status Reporting](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/manage/status-reporting/): Review real-time Access Tier status and service configuration in the Command Center - [Access Tier Support Bundle](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/manage/support-bundle/) - [Access Tier Troubleshooting](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/manage/troubleshoot/): Common issues and best practices to troubleshoot your Access Tier deployments - [Netagent Binary](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/netagent/) - [Key Capabilities and Features of the Access Tier](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/netagent/capabilities/) - [Production Tuning](https://cse-docs.sonicwall.com/docs/banyan-components/accesstier/netagent/vm-tuning/): How to configure VMs running Netagent for high throughput production traffic - [Chrome Extension](https://cse-docs.sonicwall.com/docs/banyan-components/chrome-xtn/): Clientless access to Hosted Websites and ITP enforcement, straight from the browser - [Cloud Secure Edge (CSE) Cloud Command Center](https://cse-docs.sonicwall.com/docs/banyan-components/command-center/) - [Cloud Secure Edge (CSE) Cluster and Private PKI](https://cse-docs.sonicwall.com/docs/banyan-components/command-center/cluster/) - [Shield Changelog](https://cse-docs.sonicwall.com/docs/banyan-components/command-center/cluster/changelog/) - [Cluster Deployment](https://cse-docs.sonicwall.com/docs/banyan-components/command-center/cluster/deployment/): Details on the Shield component and how PKI is managed by Cloud Secure Edge - [Manage Cryptographic Tokens and Certificates](https://cse-docs.sonicwall.com/docs/banyan-components/command-center/manage-tokens-certs/) - [Connector](https://cse-docs.sonicwall.com/docs/banyan-components/connector/) - [Install the Connector](https://cse-docs.sonicwall.com/docs/banyan-components/connector/install/): This section installs and configures the Connector in your environment. - [Install SonicWall Cloud Secure Edge Connector using Docker](https://cse-docs.sonicwall.com/docs/banyan-components/connector/install/docker/): Install the Connector on a server running Docker - [Install Connector using Open Virtual Appliance (VMware)](https://cse-docs.sonicwall.com/docs/banyan-components/connector/install/esxi/): Install the Connector on a virtual image - [Install an Open Virtual Appliance (OVA) Connector](https://cse-docs.sonicwall.com/docs/banyan-components/connector/install/ova/): Deploy the Connector as a virtual machine for your end users - [Configure a SonicOS firewall as a Cloud Secure Edge Connector](https://cse-docs.sonicwall.com/docs/banyan-components/connector/install/sonicos-firewall-setup/): End-to-end setup for using a Gen7+ SonicWall firewall as a CSE Connector, from firmware prerequisites through user testing - [Install CSE Connector using the Tarball Installer](https://cse-docs.sonicwall.com/docs/banyan-components/connector/install/tarball/): Install the Connector on virtual or physical 64-bit Linux Servers, on-Prem or cloud - [Install Connector using Windows Executable](https://cse-docs.sonicwall.com/docs/banyan-components/connector/install/windows-executable/): Install the Connector on Windows devices - [Manage Connector](https://cse-docs.sonicwall.com/docs/banyan-components/connector/manage/) - [Configure High Availability (HA) for your CSE Connector](https://cse-docs.sonicwall.com/docs/banyan-components/connector/manage/high-availability/): How to achieve HA with on-premise firewalls or Connectors on VMs to ensure infrastructure resilience - [Monitoring and Troubleshooting the OVA Connector](https://cse-docs.sonicwall.com/docs/banyan-components/connector/manage/monitor-and-troubleshoot-ova/): Commands for managing and troubleshooting the OVA Connector - [Cloud Secure Edge Desktop App](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/) - [Desktop App Capabilities and Components](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/desktop-capabilities/) - [Troubleshooting the Desktop App](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/desktop-troubleshooting/) - [Walk-through of the Desktop App](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/desktop-walkthrough/) - [Device Certificates - Management and Expiration](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/device-cert/) - [Event Hooks for Post-Connection Scripts](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/event-hook/): How users can use CSE-generated events as hooks to run scripts for macOS and Windows devices - [Event Hooks Implementation Guide](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/event-hook/event-hook-implementation/): Step-by-step setup for Windows and macOS, plus fleet rollout via any RMM or MDM tool - [Register the Desktop App & Supported OSs](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/installation-registration/) - [SonicWall Cloud Secure Edge (CSE) Apps - Data Privacy and Security Considerations](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/privacy/) - [Uninstall the desktop app on multiple devices](https://cse-docs.sonicwall.com/docs/banyan-components/desktop-app/uninstall/): How admins can uninstall the desktop app for mac, Windows, and Linux devices - [Cloud Secure Edge (CSE) Global Edge Network](https://cse-docs.sonicwall.com/docs/banyan-components/edge-network/) - [Global Edge Network Architecture](https://cse-docs.sonicwall.com/docs/banyan-components/edge-network/architecture/): This article describes how Cloud Secure Edge hosts and manages Access Tiers for your organization in a global deployment model - [Register Custom Domains](https://cse-docs.sonicwall.com/docs/banyan-components/edge-network/custom-domains/): Configure DNS so you can use your organization's domains to publish Cloud Secure Edge services - [Global Edge Network IP Ranges](https://cse-docs.sonicwall.com/docs/banyan-components/edge-network/ip-ranges/): Ingress and Egress IP addresses used by the Global Edge Network - [Managing Points of Presence (PoP) in Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/banyan-components/edge-network/managing-pops/): How to add or remove PoPs in Cloud Secure Edge (CSE) orgs - [Points of Presence (PoPs) used by the Global Edge Network](https://cse-docs.sonicwall.com/docs/banyan-components/edge-network/pops/) - [Cloud Secure Edge (CSE) Mobile App](https://cse-docs.sonicwall.com/docs/banyan-components/mobile-app/) - [Accessing Services and Networks via the Mobile App](https://cse-docs.sonicwall.com/docs/banyan-components/mobile-app/accessing-services-and-networks/): Using Cloud Secure Edge's mobile app to access hosted web services and Service Tunnels - [Register the Mobile App & Supported OSs](https://cse-docs.sonicwall.com/docs/banyan-components/mobile-app/installation-registration/) - [Troubleshooting Cloud Secure Edge's Mobile App](https://cse-docs.sonicwall.com/docs/banyan-components/mobile-app/mobile-troubleshooting/) - [SonicWall Cloud Secure Edge Labs (formerly Banyan Labs)](https://cse-docs.sonicwall.com/docs/banyan-labs/): We built some cool stuff and are looking for customers to test it out and provide feedback! - [Certificate Authentication for Databases](https://cse-docs.sonicwall.com/docs/banyan-labs/databases/) - [Certificate Authentication for MySQL](https://cse-docs.sonicwall.com/docs/banyan-labs/databases/cert-auth-mysql/): Leverage SonicWall Cloud Secure Edge (CSE) short-lived x509 Certificates to manage end user access to MySQL servers, including access control and audit logging - [Certificate Authentication for PostgreSQL](https://cse-docs.sonicwall.com/docs/banyan-labs/databases/cert-auth-postgresql/): Leverage SonicWall Cloud Secure Edge (CSE) short-lived x509 Certificates to manage end user access to PostgreSQL servers, including access control and audit logging - [Configure Full Tunnel](https://cse-docs.sonicwall.com/docs/banyan-labs/full-tunnel/): How to set up full tunnel in CSE - [Just-In-Time SSH User (JITSU) for Advanced SSH Capabilities](https://cse-docs.sonicwall.com/docs/banyan-labs/jitsu/): Advanced OpenSSH configurations, such as improved auditing, remote user creation, root user checking, and PAM integration - [Use SAML proxy to secure a single SaaS Application in Okta](https://cse-docs.sonicwall.com/docs/banyan-labs/okta-saml-proxy/): Use a SAML proxy technique in Okta to enforce device posture checks on specific SaaS applications - [Block Malicious Content](https://cse-docs.sonicwall.com/docs/block-malicious-content/): Use Cloud Secure Edge to block users in your org from encountering malicious internet content - [Check Devices' Security Posture](https://cse-docs.sonicwall.com/docs/check-devices-security-posture/): Use Cloud Secure Edge to provide users in your org with granular access to protected services - [Content Policies](https://cse-docs.sonicwall.com/docs/content-policies/) - [Internet Threat Protection (ITP) Policies](https://cse-docs.sonicwall.com/docs/content-policies/itp/) - [Feature Guides](https://cse-docs.sonicwall.com/docs/feature-guides/): Configuration and administration docs for Cloud Secure Edge (CSE) features - [What is SonicWall Cloud Secure Edge (CSE)?](https://cse-docs.sonicwall.com/docs/intro/) - [Connection Methods](https://cse-docs.sonicwall.com/docs/intro/client-scenarios/): How to enable zero-trust security across your entire workforce, covering both client-based and clientless connection methods - [Edge Deployment Model for Private Access](https://cse-docs.sonicwall.com/docs/intro/edge-deployment/): Selecting the best deployment model for access your organization's private resources - [Glossary of SonicWall Cloud Secure Edge (CSE) Terms](https://cse-docs.sonicwall.com/docs/intro/glossary/): Terminology SonicWall uses to represent and secure users, devices, or applications running in any type of environment - [How SonicWall Cloud Secure Edge (CSE) Works](https://cse-docs.sonicwall.com/docs/intro/how-banyan-works/) - [Zero Trust Policies](https://cse-docs.sonicwall.com/docs/intro/policies/): Learn about Cloud Secure Edge's human-readable policy framework designed for admins to implement zero-trust security controls - [How Traffic Is Routed](https://cse-docs.sonicwall.com/docs/intro/routing/): How SonicWall Cloud Secure Edge automatically selects the appropriate mechanism to securely connect a user to the resource they need to access - [Cloud Secure Edge (CSE) Licenses](https://cse-docs.sonicwall.com/docs/licenses/): License types and license distribution to end users in Cloud Secure Edge - [Cloud Secure Edge (CSE) Editions-based Licenses](https://cse-docs.sonicwall.com/docs/licenses/editions-licenses/): Editions-based licenses for legacy customers (SonicWall Cloud Secure Edge users) - [Manage Users & Devices Inventory](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/) - [Configure Microsoft's Active Directory to manage your directory of users](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/active-directory/): Connect your Windows server to CSE using LDAP - [Enable Certificate-based MFA for LDAP users](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/active-directory/enable-cert-based-mfa/): Send a One-Time Passcode (OTP) to users' emails to install CSE's certificate - [Allow the CSE app in your Anti-Virus (AV) or Endpoint Detection Response (EDR) Solutions](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/allowlist-app-for-av-and-edr/): Configure your AV or EDR solutions to allowlist the CSE app - [App Auto Update](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/app-auto-update/): How to enable or disable auto update for the CSE desktop apps in your org - [Set Up Auto-Configuration for Entra ID (Azure AD)](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/azure-ad/): Manage your directory of users by setting up an API auto-configuration for authentication - [Grant CSE Access to External Guest Users Using Entra ID B2B](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/azure-ad/entra-b2b/) - [Configure Entra ID Device Registration to manage your directory of users](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/azure-ad/entra-id-device-registration/) - [Enabling System for Cross-domain Identity Management (SCIM) for end users that use Entra ID](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/azure-ad/entra-id-scim/): How to automate updates to user identity information in SonicWall Cloud Secure Edge (CSE) - [Using Cloud Secure Edge with Microsoft 365](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/azure-ad/entra-licensing-for-cse/): Learn which Microsoft licenses are required for CSE security features - [Configure Entra ID (Azure AD) to manage your directory of users](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/azure-ad/manual-config/) - [De-register, Ban and Unban Devices](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/ban-devices/): How to manage misplaced or decommissioned devices in your organization - [Certificate-based Multi-Factor Authentication (MFA)](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/cert-based-mfa/): Manage MFA vulnerabilities using CSE's built-in certificate-based authentication method - [Branding and Message Customization](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/customization/): Add in-app or in-browser help messaging for your end users - [Archive and Delete Users](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/delete-users/): How to manage user archival and deletion in your organization. - [Integrate SonicWall Cloud Secure Edge (CSE) with your Device Manager](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/): Create and manage an inventory of known devices that can be used to access your CSE-protected Services - [Clientless Access Using Device Manager–Installed Certificates](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/cert-only/): Configure Cloud Secure Edge to trust device certificates issued by your enterprise CA and distributed by your device manager, so managed devices get zero trust access to hosted websites with no CSE app installed - [Distribute Cloud Secure Edge's Chrome Browser Extension using Google Workspace](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/distribute-chrome-extension/) - [Installing the CSE Desktop App via Zero Touch Script (EXE)](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/distribute-desktopapp/) - [Intune - Zero Touch Installation of the Desktop App](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/intune-zero-touch/): How to configure Intune zero touch deployment of the desktop app - [Jamf Pro - Zero Touch Installation of the Desktop App](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/jamf-pro-zero-touch/): How to configure Jamf Pro zero touch deployment of the desktop app - [JumpCloud - Zero Touch Installation of the Desktop App](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/jumpcloud-zero-touch/): How to to silently deploy the desktop app using JumpCloud - [Kandji - Zero Touch Installation of the Desktop App](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/kandji-zero-touch/): How to to silently deploy the desktop app using Kandji - [Installing the CSE Desktop App for Windows (MSI)](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/windows-msi-install/) - [Workspace ONE UEM - Device Identity & Enhanced Trust Scoring](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-managers/workspace-one-cert-api/): Configure Cloud Secure Edge to leverage VMware Workspace ONE UEM for Device Identity using pre-installed device certs and for Enhanced Trust Scoring via API integrations - [Device Trust Verification](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/device-trust-verification/): Leverage SonicWall Cloud Secure Edge (CSE) app to establish Device Trust on mobile devices as well as apps whose authentication WebViews are unable to use the CSE device certificate - [Configure Duo to manage your directory of users in Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/duo/): Use Duo Single Sign-On (SSO) as your SAML IdP for CSE - [Event Geolocation](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/event-geolocation/): How Cloud Secure Edge provides visibility into user devices' geolocation - [Configure Google Workspace to manage your directory of users in Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/gsuite/) - [Grant CSE Access to 3rd-Party Contractors Using Google Workspace](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/gsuite/google-workspace-contractors/) - [Set up a directory of users](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/identity-providers/): Integrate SonicWall Cloud Secure Edge (CSE) with your Identity Provider to create a directory of users that can access your Services - [Configure JumpCloud to manage your directory of users in SonicWall Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/identity-providers/jumpcloud/) - [Configure OneLogin to manage your directory of users in SonicWall Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/identity-providers/onelogin/) - [Configure a SAML 2.0 Identity Provider to manage your directory of users in SonicWall Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/identity-providers/saml/) - [Invite Code and Device Enrollment](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/invite-code/): How the CSE Invite Code is used, and what happens to already-enrolled devices when you rotate it - [Managed, Registered, and Unregistered Devices](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/managed-registered-unregistered/): Configure access for Managed, Registered, and Unregistered Devices within the Command Center - [Configure Okta to manage your directory of users in SonicWall Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/okta/) - [Enabling System for Cross-domain Identity Management (SCIM) for end users that use Okta](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/okta/scim/): How to automate updates to user identity information in SonicWall Cloud Secure Edge (CSE) - [Passwordless Authentication](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/passwordless/): Enable users to log in via your Identity Provider without entering a username/password - [Remote Diagnostics](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/remote-diagnostics/): Fetch log data directly from the Command Center to help debug end users' devices - [Service Bundles](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/service-bundles/): Deploying pre-configured sets of services to your end users - [Silent Certificate Authentication for User Sessions in Okta](https://cse-docs.sonicwall.com/docs/manage-users-and-devices/silent-certificate-authentication/): How to authenticate users (using OIDC) without end users needing to interact with prompts - [MySonicWall](https://cse-docs.sonicwall.com/docs/mysonicwall/): Manage CSE Admins via MySonicWall - [Activate Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/mysonicwall/activate-cse-mysonicwall/): Register and Activate Cloud Secure Edge in MySonicWall - [Protect your SaaS Apps](https://cse-docs.sonicwall.com/docs/protect-saas-apps/): Use Cloud Secure Edge provide protected access to your org's SaaS apps - [Quickstart](https://cse-docs.sonicwall.com/docs/quickstart/): Helpful guide to get you up and running quickly with SonicWall Cloud Secure Edge (formerly Banyan Security) - [Connect your Network](https://cse-docs.sonicwall.com/docs/quickstart/connect-network/): Install an Access Tier or Connector in your private network. - [Signing Up for SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/quickstart/onboarding-signup/) - [Onboarding with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/quickstart/onboarding/) - [Set up Directory](https://cse-docs.sonicwall.com/docs/quickstart/set-up-directory/): Add users so they can authenticate and access private resources. - [Changelog](https://cse-docs.sonicwall.com/docs/release-notes/): Updates to the SonicWall Cloud Secure Edge platform and clients. - [Known Issues](https://cse-docs.sonicwall.com/docs/release-notes/known-issues/): This section lists the current known limitations (and available workarounds) of SonicWall Cloud Secure Edge (formerly Banyan Security) - [Important Notices](https://cse-docs.sonicwall.com/docs/release-notes/notices/): This section lists important notices regarding SonicWall Cloud Secure Edge (CSE) - [Release Notes Archive - 2019](https://cse-docs.sonicwall.com/docs/release-notes/release-notes-2019/): This article lists the features, enhancements, bug fixes, and components of SonicWall Cloud Secure Edge (formerly Banyan) released in 2019 - [Release Notes Archive - 2020](https://cse-docs.sonicwall.com/docs/release-notes/release-notes-2020/): This article lists the features, enhancements, bug fixes, and components of SonicWall Cloud Secure Edge (formerly Banyan) released in 2020 - [Release Notes Archive - 2021](https://cse-docs.sonicwall.com/docs/release-notes/release-notes-2021/): This article lists the features, enhancements, bug fixes, and components of SonicWall Cloud Secure Edge (formerly Banyan) released in 2021 - [Release Notes Archive - 2022](https://cse-docs.sonicwall.com/docs/release-notes/release-notes-2022/): This article lists the features, enhancements, bug fixes, and components of SonicWall Cloud Secure Edge (formerly Banyan) released in 2022 - [Release Notes Archive - 2023](https://cse-docs.sonicwall.com/docs/release-notes/release-notes-2023/): This article lists the features, enhancements, bug fixes, and components of SonicWall Cloud Secure Edge (formerly Banyan) released in 2023 - [Release Notes Archive - 2024](https://cse-docs.sonicwall.com/docs/release-notes/release-notes-2024/): This article lists the features, enhancements, bug fixes, and components of SonicWall Cloud Secure Edge (formerly Banyan) released in 2024 - [Release Notes Archive - 2025](https://cse-docs.sonicwall.com/docs/release-notes/release-notes-2025/): This article lists the features, enhancements, bug fixes, and components of SonicWall Cloud Secure Edge (formerly Banyan) released in 2025 - [Release Notes Archive](https://cse-docs.sonicwall.com/docs/release-notes/release-notes-archive/): This section lists the features, enhancements, bug fixes, and components available in the past versions of SonicWall Cloud Secure Edge (formerly Banyan) - [Release Process](https://cse-docs.sonicwall.com/docs/release-notes/release-process/): An overview of SonicWall Cloud Secure Edge (CSE) feature release phases - [Securing Internet Traffic with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-internet-traffic/): Protect users from unsafe internet resources via CSE's Secure Web Gateway (SWG) - [Internet Threat Protection (ITP) Architecture](https://cse-docs.sonicwall.com/docs/securing-internet-traffic/dns-architecture/): How core components and DNS resolution work in ITP - [Manage Internet Threat Protection (ITP) Policies](https://cse-docs.sonicwall.com/docs/securing-internet-traffic/itp-policies/): Creating, editing, and prioritizing ITP policies in SonicWall Cloud Secure Edge (CSE) - [Internet Threat Protection (ITP) Troubleshooting Guide](https://cse-docs.sonicwall.com/docs/securing-internet-traffic/itp-troubleshooting/): A step-by-step troubleshooting procedure admins can follow to resolve general ITP issues - [Blocked access to websites when using Microsoft Edge and Risk-Based URL Filtering](https://cse-docs.sonicwall.com/docs/securing-internet-traffic/itp-troubleshooting/ie-mode-causes-403-error/): End users receive 403 errors when attempting to access websites - [Private domains failing to resolve in SIA-only orgs](https://cse-docs.sonicwall.com/docs/securing-internet-traffic/itp-troubleshooting/private-domains-fail-to-resolve/): End users' requests timing out when attempting to access private domains - [Malware Download Protection](https://cse-docs.sonicwall.com/docs/securing-internet-traffic/malware-download-inspection/): Automatically inspect and block malicious file downloads at the edge - [Enabling Risk-based URL Filtering](https://cse-docs.sonicwall.com/docs/securing-internet-traffic/risk-based-url-filtering/): Filter URLs in the Internet Threat Protection (ITP) policy settings in SonicWall Cloud Secure Edge (CSE) - [Configuring Zero Touch Chrome Enrollment for ITP Policies on Managed Chromebooks](https://cse-docs.sonicwall.com/docs/securing-internet-traffic/zero-touch-chrome-enrollment/): How to set up Internet Threat Protection for Managed Chromebooks - [Securing Networks with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-networks/): Migrate from your legacy VPN to Service Tunnel, a modern cloud-first VPN as a Service (VPNaaS) built on WireGuard - [Service Tunnel Access Logs](https://cse-docs.sonicwall.com/docs/securing-networks/access-logs/): How to access Service Tunnel logs - [Service Tunnel Active Connections](https://cse-docs.sonicwall.com/docs/securing-networks/active-connections/): View how many devices are actively connected to a Service Tunnel - [Alternative Routing to Public Resources via a TCP Service](https://cse-docs.sonicwall.com/docs/securing-networks/alternative-routing/): How to use a hosted web (TCP) service to route to public apps when Service Tunnel is unavailable - [Connect on Login](https://cse-docs.sonicwall.com/docs/securing-networks/connect-on-login/) - [DNS and Routing for Service Tunnels](https://cse-docs.sonicwall.com/docs/securing-networks/dns-routing/): How DNS and traffic routing works when using Service Tunnel - [Mobile Tunnel](https://cse-docs.sonicwall.com/docs/securing-networks/mobile-tunnel/): How to use Service Tunnels in the mobile app - [Notes on Service Tunnels](https://cse-docs.sonicwall.com/docs/securing-networks/notes/): Advanced concepts including Operational CIDR ranges, and more - [Enabling Name Resolution Policy Table (NRPT) Rules](https://cse-docs.sonicwall.com/docs/securing-networks/nrpt-rules/): How to enable NRPT rules for Windows devices connected to Service Tunnel - [Creating Network-level (Layer-4) policies for Service Tunnels](https://cse-docs.sonicwall.com/docs/securing-networks/policies/) - [Use a Service Tunnel for Public Domains](https://cse-docs.sonicwall.com/docs/securing-networks/public-domains/): How to configure a Service Tunnel to tunnel public domains available on the internet - [Search Domains](https://cse-docs.sonicwall.com/docs/securing-networks/search-domains/) - [Service Tunnel Troubleshooting](https://cse-docs.sonicwall.com/docs/securing-networks/troubleshooting/): General diagnostic process for resolving Service Tunnel issues - [Hostname Resolution Fails on the Service Tunnel](https://cse-docs.sonicwall.com/docs/securing-networks/troubleshooting/cannot-resolve-using-hostname/): Service Tunnel Troubleshooting - [Domain Resolution Failing on the Firewall Connector](https://cse-docs.sonicwall.com/docs/securing-networks/troubleshooting/domain-resolution-not-working-on-firewall/): Service Tunnel Troubleshooting - [Loss of Network Connectivity and Trouble Restarting the Connection](https://cse-docs.sonicwall.com/docs/securing-networks/troubleshooting/loss-of-connectivity-and-issues-restarting/): Service Tunnel Troubleshooting - [Loss of Connectivity on a Restrictive Public Network](https://cse-docs.sonicwall.com/docs/securing-networks/troubleshooting/loss-of-connectivity-on-a-public-network/): Service Tunnel Troubleshooting - [Slow performance or requests timing out due to MTU value](https://cse-docs.sonicwall.com/docs/securing-networks/troubleshooting/slow-performance-and-websites-partially-loading/): Service Tunnel Troubleshooting - [Trusted Network Settings Not Taking Effect](https://cse-docs.sonicwall.com/docs/securing-networks/troubleshooting/trusted-network-not-taking-effect/): Service Tunnel Troubleshooting - [Trusted Networks](https://cse-docs.sonicwall.com/docs/securing-networks/trusted-networks/): How to configure a Trusted Network - [Publish a Service Tunnel](https://cse-docs.sonicwall.com/docs/securing-networks/user-tunnel/): How to configure a Service Tunnel and then publish it to end users so that they have connectivity to private network segments - [Securing Private Resources with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-private-resources/): Protect your internal websites and infrastructure via CSE's Zero Trust Network Access (ZTNA) solution - [Securing Databases with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-private-resources/databases/) - [DNS and Routing for Published Services](https://cse-docs.sonicwall.com/docs/securing-private-resources/dns-routing/): Register domains and configure DNS to publish Cloud Secure Edge (CSE) services - [Securing Hosted Websites with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-private-resources/hosted-websites/): Protect your hosted websites and enable access without a VPN - [Exemptions and Cross-origin Resource Sharing (CORS)](https://cse-docs.sonicwall.com/docs/securing-private-resources/hosted-websites/cors/): How to enable exemptions and CORS on a Cloud Secure Edge (CSE)-secured web service - [Use Let's Encrypt Certificates](https://cse-docs.sonicwall.com/docs/securing-private-resources/hosted-websites/lets-encrypt/): Publish hosted websites with browser-trusted Cloud Secure Edge (CSE)-managed Let's Encrypt certificates - [Multi-domain (aka Wildcard) Web Services](https://cse-docs.sonicwall.com/docs/securing-private-resources/hosted-websites/multi-domain/) - [Advanced Settings for Hosted Websites](https://cse-docs.sonicwall.com/docs/securing-private-resources/hosted-websites/notes/): Advanced concepts including WebSockets and more - [Creating API-level (Layer-7) policies for Hosted Websites](https://cse-docs.sonicwall.com/docs/securing-private-resources/hosted-websites/policies/) - [Programmatic Access for Hosted Websites](https://cse-docs.sonicwall.com/docs/securing-private-resources/hosted-websites/serviceaccounts/): Provide programmatic access to third-party applications accessing Cloud Secure Edge (CSE) hosted websites - [Register a Hosted Website to Users](https://cse-docs.sonicwall.com/docs/securing-private-resources/hosted-websites/user-web/): How to create a Hosted Web Service so end users can access a web app located in your private network - [Securing Kubernetes API with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-private-resources/k8s-api/) - [Zero-Trust Access to the Kubernetes API](https://cse-docs.sonicwall.com/docs/securing-private-resources/k8s-api/kubernetes-api/) - [Kubernetes OIDC Authentication](https://cse-docs.sonicwall.com/docs/securing-private-resources/k8s-api/oidc-auth/): Leverage SonicWall Cloud Secure Edge OIDC token capabilities to manage end user access to Kubernetes API Servers, including configuring RBAC policies for K8S - [Securing RDP Servers with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-private-resources/rdp-servers/) - [Zero-Trust Access to a Collection of RDP Servers](https://cse-docs.sonicwall.com/docs/securing-private-resources/rdp-servers/collection/) - [Register an Individual RDP Server](https://cse-docs.sonicwall.com/docs/securing-private-resources/rdp-servers/individual/) - [Securing SSH Servers with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-private-resources/ssh-servers/) - [SSH Certificate Authentication](https://cse-docs.sonicwall.com/docs/securing-private-resources/ssh-servers/cert-auth/): Leverage SonicWall Cloud Secure Edge (CSE) SSH certificates capabilities to manage end user access to individual SSH servers - [Register an SSH Service for a Collection of SSH Servers](https://cse-docs.sonicwall.com/docs/securing-private-resources/ssh-servers/collection/) - [Register an SSH Service for an Individual SSH Server](https://cse-docs.sonicwall.com/docs/securing-private-resources/ssh-servers/ssh-server/) - [Securing TCP Services with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-private-resources/tcp-services/) - [Tunnelling to a Collection of TCP Services](https://cse-docs.sonicwall.com/docs/securing-private-resources/tcp-services/collection/) - [Multi-domain (aka Wildcard) TCP Services](https://cse-docs.sonicwall.com/docs/securing-private-resources/tcp-services/multi-domain/) - [Notes on Securing TCP Services](https://cse-docs.sonicwall.com/docs/securing-private-resources/tcp-services/notes/): Managing access to administrative services like SSH, RDP, and Kubernetes - [Register a Generic TCP Infrastructure Service](https://cse-docs.sonicwall.com/docs/securing-private-resources/tcp-services/user-tcp/): This article will show you how to create a Infrastructure service to enable access to an internal database located in your private network, so a user can conveniently yet securely connect using their preferred DB management tool. - [Attribute Variables](https://cse-docs.sonicwall.com/docs/securing-private-resources/user-attributes/): Cloud Secure Edge user variables that can be used for patterned name substitution - [Securing Public Applications with SonicWall Cloud Secure Edge (CSE)](https://cse-docs.sonicwall.com/docs/securing-public-applications/): Add device trust and Zero Trust policy enforcement to your SaaS applications with CSE's access-focused Cloud Access Security Broker (CASB) - [Enforce Zero Trust Security Policies for Public Applications integrated with Azure AD](https://cse-docs.sonicwall.com/docs/securing-public-applications/azure-ad/) - [Use IdP Federation to Enforce Zero Trust Policies on All SaaS Applications Integrated With Microsoft Entra ID](https://cse-docs.sonicwall.com/docs/securing-public-applications/azure-ad/idp-federation/): Use federation in Microsoft Entra ID to enforce Cloud Secure Edge (CSE) policies and enable passwordless authentication for Microsoft 365 and other Entra-integrated SaaS applications - [Use IP Allowlisting to enforce zero trust policies for specific SaaS Applications integrated with Entra ID](https://cse-docs.sonicwall.com/docs/securing-public-applications/azure-ad/ip-allowlisting/): Use Named locations and Conditional Access policies in Entra ID to ensure use of a Service Tunnel when authenticating to a SaaS Application like O365 - [Use IdP Federation to enforce zero trust policies on all SaaS Applications integrated with Duo](https://cse-docs.sonicwall.com/docs/securing-public-applications/duo/idp-federation/): Add CSE as a SAML Identity Provider authentication source in Cisco Duo Single Sign-On so that all SaaS applications federated through Duo SSO are subject to CSE zero trust policy enforcement and Passwordless authentication - [Use IP Allowlisting to enforce zero trust policies for specific SaaS Applications integrated with Duo](https://cse-docs.sonicwall.com/docs/securing-public-applications/duo/ip-allowlisting/): Use a Duo Networks policy to require a CSE Service Tunnel when authenticating to a SaaS Application - [Secure SaaS Applications with IdP Federation](https://cse-docs.sonicwall.com/docs/securing-public-applications/federated-saas-apps/): Protect SaaS Applications by enabling Device Trust via IdP Federation - [IdP Routed SaaS Applications](https://cse-docs.sonicwall.com/docs/securing-public-applications/federated-saas-apps/idp-routed/): Use IdP routing capabilities in your Identity Provider to enforce Cloud Secure Edge Policies on your SaaS applications - [Publish a Federated SaaS App](https://cse-docs.sonicwall.com/docs/securing-public-applications/federated-saas-apps/user-saas/): Use the CSE Federated technique to enforce device-based access control policies on a SaaS application using Cloud Secure Edge's zero-trust security framework - [IdP Federation for Google Workspace Zero Trust Policy Enforcement](https://cse-docs.sonicwall.com/docs/securing-public-applications/google-workspace/idp-federation/): Federate Google Workspace to SonicWall Cloud Secure Edge (CSE) so Google delegates sign-in to the CSE policy engine, enforcing device trust and zero trust policy before Google completes authentication to SaaS applications - [Secure SaaS Applications with IP Allowlisting](https://cse-docs.sonicwall.com/docs/securing-public-applications/ip-allowlisting/): Protect SaaS Applications by enabling Device Trust and Continuous Authorization via IP Allowlisting - [Enforce Zero Trust Security Policies for Public Applications integrated with Okta](https://cse-docs.sonicwall.com/docs/securing-public-applications/okta/) - [Use IdP Federation to enforce zero trust policies on all SaaS Applications integrated with Okta](https://cse-docs.sonicwall.com/docs/securing-public-applications/okta/idp-federation/): Use federation capabilities in Okta to enforce Cloud Secure Edge (CSE) policies on and enable Passwordless for your SaaS apps - [Use IP Allowlisting to enforce zero trust policies for specific SaaS Applications integrated with Okta](https://cse-docs.sonicwall.com/docs/securing-public-applications/okta/ip-allowlisting/): Use Network Zones and Sign-on Policies in Okta to ensure use of a Service Tunnel when authenticating to a SaaS Application like Salesforce - [Enforce Zero Trust Security Policies for Public Applications integrated with OneLogin](https://cse-docs.sonicwall.com/docs/securing-public-applications/onelogin/) - [Use IdP Federation to enforce zero trust policies on all SaaS Applications integrated with OneLogin](https://cse-docs.sonicwall.com/docs/securing-public-applications/onelogin/idp-federation/): Use federation capabilities in OneLogin to enforce CSE Policies on your SaaS applications - [Use IP Allowlisting to enforce zero trust policies for specific SaaS Applications integrated with OneLogin](https://cse-docs.sonicwall.com/docs/securing-public-applications/onelogin/ip-allowlisting/): Use a OneLogin App Policy IP Address Allow List to require a CSE Service Tunnel when authenticating to a SaaS Application - [Set Up Remote Access](https://cse-docs.sonicwall.com/docs/set-up-remote-access/): Use Cloud Secure Edge to set up a remote access VPN for your organization - [Set Up Zero Trust Network Access (ZTNA)](https://cse-docs.sonicwall.com/docs/set-up-ztna/): Use Cloud Secure Edge to provide users in your org with granular access to protected services - [Solutions](https://cse-docs.sonicwall.com/docs/solutions/) - [Solutions](https://cse-docs.sonicwall.com/docs/solutions/automation/) - [Solutions](https://cse-docs.sonicwall.com/docs/solutions/business-apps/) - [Solutions](https://cse-docs.sonicwall.com/docs/solutions/cloud-infra/) - [Solutions](https://cse-docs.sonicwall.com/docs/solutions/databases/) - [Solutions](https://cse-docs.sonicwall.com/docs/solutions/dev-tools/) - [Solutions](https://cse-docs.sonicwall.com/docs/solutions/migration/) - [Solutions](https://cse-docs.sonicwall.com/docs/solutions/security/) - [Solutions](https://cse-docs.sonicwall.com/docs/solutions/server-access/) - [Trust Scoring](https://cse-docs.sonicwall.com/docs/trust-scoring/): SonicWall Cloud Secure Edge (CSE) calculates Trust Levels for devices in your fleet to determine access - [Using Regular Expressions in Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/trust-scoring/regex/): How to use Regular Expressions (Regex) in the Command Center - [Remediation](https://cse-docs.sonicwall.com/docs/trust-scoring/remediation/): Customize the default device Trust Level remediation instructions for users in your organization - [Trust Scoring Calculation](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-calculation/): A conceptual overview of the Trust calculation, a part of Cloud Secure Edge’s Granular Trust Scoring feature - [Trust Effect](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-effect/): A conceptual overview of the Trust Effect, how it relates to device Trust Level, and how it affects end users' access to protected resources - [Trust Factors](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/): An overview of Trust Factors, their origin, and their impact on devices’ Trust Levels - [Application Check](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/app-check/): Automatically adjust Trust Levels and enforce security policies based on whether specific applications are running on a device - [Auto Update](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/auto-update/): Automatically adjust Trust Levels and enforce security policies based on whether specific files are on a device - [CSE App Version](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/banyan-app-version/): Automatically adjust Trust Levels and enforce security policies based on whether specific files are on a device - [Chrome Version](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/chrome-version/): Automatically adjust Trust Levels and enforce security policies based on whether users' Chrome versions are as specified - [Disk Encryption](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/disk-encryption/): Automatically adjust Trust Levels and enforce security policies based on whether specific files are on a device - [File Check](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/file-check/): Automatically adjust Trust Levels and enforce security policies based on whether specific files are on a device - [Firewall](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/firewall/): Automatically adjust Trust Levels and enforce security policies based on whether specific files are on a device - [Device Geolocation Trust Factor](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/geolocation/) - [Operating System Version](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/os-version/): Automatically adjust Trust Levels and enforce security policies based on whether users' OS versions are as specified - [Property List Check](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/property-list-check/): Automatically adjust Trust Levels and enforce security policies based on whether specific property list file keys match their defined values on macOS devices - [Registry Key Check](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-factors/registry-key-check/): Automatically adjust Trust Levels and enforce security policies based on whether specific registry keys match their defined values on Windows devices - [Trust Integrations](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-integrations/) - [SonicWall Capture Client Integration](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-integrations/capture-client/) - [CrowdStrike Integration](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-integrations/crowdstrike/) - [SentinelOne Integration](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-integrations/sentinel-one/) - [Trust Profile](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-profile/): Admin-defined assignment of Trust Factors to subsets of devices in an org - [Trust Score Settings](https://cse-docs.sonicwall.com/docs/trust-scoring/trust-score-settings/): An overview of Trust Score Settings - [Unified Management](https://cse-docs.sonicwall.com/docs/unified-management/): Administer Cloud Secure Edge (CSE) via Unified Management - [Visibility and Logging](https://cse-docs.sonicwall.com/docs/visibility-logging/) - [Access Logs](https://cse-docs.sonicwall.com/docs/visibility-logging/access-logs/): Review detailed logs of user access activity in your Cloud Secure Edge SIA organization - [Events Viewer](https://cse-docs.sonicwall.com/docs/visibility-logging/events/): Filter and review security events associated with end-user activity in your Cloud Secure Edge organization - [Forward Cloud Secure Edge (CSE) Events to the ELK Stack](https://cse-docs.sonicwall.com/docs/visibility-logging/events/elk-stack/): Use our Filebeat integration to view and analyze CSE events in your ELK stack - [Event Properties & Definitions](https://cse-docs.sonicwall.com/docs/visibility-logging/events/event-props/) - [Public Application Discovery](https://cse-docs.sonicwall.com/docs/visibility-logging/public-application-discovery/): Automatically discover public applications accessed by your users - [Create a Custom Public App](https://cse-docs.sonicwall.com/docs/visibility-logging/public-application-discovery/custom-public-apps/): Define, manage, and secure your own public applications in Cloud Secure Edge - [Managing Discovered Public Resources](https://cse-docs.sonicwall.com/docs/visibility-logging/public-application-discovery/managing-public-resources/): Use Cloud Secure Edge to secure your org's public resources - [Reporting Dashboard](https://cse-docs.sonicwall.com/docs/visibility-logging/reporting/): Review summary reports on end-user activity for your Cloud Secure Edge organization - [Downloadable Reports](https://cse-docs.sonicwall.com/docs/visibility-logging/reporting/downloadable-reports/): Download reports in PDF and CSV format for auditing and to share with your broader teams - [Private Resource Discovery](https://cse-docs.sonicwall.com/docs/visibility-logging/service-tunnel-discovery/): Automatically discover resources accessed via Service Tunnels - [System Log](https://cse-docs.sonicwall.com/docs/visibility-logging/system-log/): Review detailed logs of administrator activity in your Cloud Secure Edge organization ## Solutions - [Automate zero-trust security for your AWS resources using Terraform and CSE](https://cse-docs.sonicwall.com/docs/solutions/automation/terraform-aws/): Use CSE's short-lived cryptographic credentials to connect to your AWS resources and enforce zero-trust access control policies. - [Automate zero-trust security for your Azure resources using Terraform and CSE](https://cse-docs.sonicwall.com/docs/solutions/automation/terraform-azure/): Use CSE's short-lived cryptographic credentials to connect to your Azure resources and enforce zero-trust access control policies. - [Enforce device trust for access to Dropbox](https://cse-docs.sonicwall.com/docs/solutions/business-apps/dropbox/): Configure Dropbox SAML authentication to use CSE's federated Identity Provider so you can enforce device posture requirements. - [Use a Service Tunnel to route to Salesforce](https://cse-docs.sonicwall.com/docs/solutions/business-apps/salesforce/): A step-by-step guide on how to use CSE’s Service Tunnel to route to public domains, such as SaaS services - [Authentication and device trust with AWS Amazon Application Load Balancer (ALB)](https://cse-docs.sonicwall.com/docs/solutions/cloud-infra/aws-alb/): Use AWS ALB's built-in OpenID Connect feature to delegate authentication to CSE's federated Identity Provider. - [Secure access to AWS Amazon Relational Database Service (RDS) instances](https://cse-docs.sonicwall.com/docs/solutions/cloud-infra/aws-rds/): Enable access to an internal RDS instance so a user can conveniently yet securely connect using their favorite database management tool. - [Secure Git operations to your self-managed GitLab – without a VPN](https://cse-docs.sonicwall.com/docs/solutions/dev-tools/gitlab-hosted-operations/): Use CSE to support SSH and PAT protocols/authentication schemes seamlessly, while still ensuring zero trust security. - [Secure browser access to your self-managed GitLab – without a VPN](https://cse-docs.sonicwall.com/docs/solutions/dev-tools/gitlab-hosted/): Provide access to Gitlab based on user and device identity, with first-class support for mobile devices. No need to backhaul traffic through a VPN. - [Enforce device trust for access to your gitab.com organization](https://cse-docs.sonicwall.com/docs/solutions/dev-tools/gitlab-saas/): Configure gitlab.com SAML authentication to use CSE's federated Identity Provider so you can enforce device posture requirements. - [Secure access to your self-hosted Jenkins server – without a VPN](https://cse-docs.sonicwall.com/docs/solutions/dev-tools/jenkins/): Provide access to Jenkins based on user and device identity, with first-class support for mobile devices. No need to backhaul traffic through a VPN. - [Secure access to your self-hosted Jira instance – without a VPN](https://cse-docs.sonicwall.com/docs/solutions/dev-tools/jira/): Provide access to Jira based on user and device identity, with first-class support for mobile devices. No need to backhaul traffic through a VPN. - [Migrate from Cisco Umbrella to Cloud Secure Edge](https://cse-docs.sonicwall.com/docs/solutions/migration/migrating-from-umbrella-to-cse/): Steps to complete a full migration to Cloud Secure Edge while concurrently running Cisco Umbrella and SonicWall - [Continuous authorization without compromising privacy](https://cse-docs.sonicwall.com/docs/solutions/security/continuous-authz/): Learn how CSE ensures devices are validated before granting access to resources, regardless of whether the devices are company-managed via MDM/UEM. - [Enforce device trust for Okta applications](https://cse-docs.sonicwall.com/docs/solutions/security/okta/): Learn how to use SonicWall Cloud Secure Edge (CSE) to roll out device trust in a phased manner, providing admins high visibility and end-users a great authentication experience. - [Protect sensitive SaaS apps using a SAML proxy configuration in Okta](https://cse-docs.sonicwall.com/docs/solutions/security/saml-okta/): Learn how to use CSE to secure access to high-security corporate apps. - [Replace your SSH bastion host](https://cse-docs.sonicwall.com/docs/solutions/server-access/bastion-ssh/): Use CSE to replace bastions for secure remote access – without the headache of credential management or IP whitelisting. - [Secure browser-based access to your servers using Apache Guacamole](https://cse-docs.sonicwall.com/docs/solutions/server-access/guacamole/): Leverage CSE's ability to secure hosted websites and its capability as a federated IdP to manage access to desktop environments via Guacamole. - [CSE Solution - Apache Guacamole - Setup Guide](https://cse-docs.sonicwall.com/docs/solutions/server-access/guacamole/deploy/) - [CSE Solution - Apache Guacamole - Setup Guide](https://cse-docs.sonicwall.com/docs/solutions/server-access/guacamole/primary-admin/) - [CSE Solution - Apache Guacamole - Setup Guide](https://cse-docs.sonicwall.com/docs/solutions/server-access/guacamole/saml/) - [Convenient Remote Access to your Home Lab](https://cse-docs.sonicwall.com/docs/solutions/server-access/home-lab-access/): Use CSE to securely share your apps with others, without exposing your entire home network. - [Simplify Real VNC configs needed to connect to remote servers](https://cse-docs.sonicwall.com/docs/solutions/server-access/real-vnc/): Pre-define VNC configurations and enforce security policies for users connecting to remote servers using Real VNC.