---
title: "Configure secure identity access portal"
canonical: "https://docs.aryaka.com/space/KNOW/122781710/Configure%20secure%20identity%20access%20portal"
format: markdown
---
The Secure Identity Access Portal page allows you to manage your secure identity access portal configuration by enabling secure identity access portal and creating secure identity access portal rules. Secure identity access portal Secure identity access portal uses browser-based activity to intercept unidentified network users' traffic and redirect users to a login page for authentication. When secure identity access portal is enabled, your network users encounter the secure identity access portal when their traffic is intercepted by the SSL engine.  The secure identity access portal allows users to log in to the network as a known user with their IdP credentials or to access the network as a guest user. When users choose to log in as a known user, the secure identity access portal works with  Aryaka Identity Manager  to authenticate them, which then redirects them to your external identity provider (IdP), such as Microsoft Entra ID or Okta. After users log in as a known user or a guest, they can connect to the internet and their traffic is subjected to all relevant security rules. Users can also access the secure identity access portal directly at  captive.aryaka.com . When you enable secure identity access portal, you can include customized text that you want displayed to users when they encounter the secure identity access portal. This could include privacy information, an acceptable use policy, or a legal statement.  Enabling secure identity access portal results in the following: Users in branch offices encounter the secure identity access portal. Traffic that is permitted by your  Next Generation Firewall rules  encounters the secure identity access portal.  You can write secure identity access portal rules to bypass clients that should  not  encounter the secure identity access portal. To enable secure identity access portal Navigate to the Secure Identity Access Portal page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  Settings  in left navigation pane. The Settings page appears.  Click  Manage  in the Secure Identity Access Portal tile. The Secure Identity Access Portal page appears and displays the Configure Secure Identity Access Portal pane and Rules table in read-only mode. (Optional) Click  View Secure Identity Access Portal . The Secure Identity Access Portal page opens in a new window and displays a preview of the page users are presented with when they encounter the secure identity access portal. Click  Edit  on the Configure Secure Identity Access Portal pane. The Secure Identity Access Portal Customization page appears in edit mode.  Click the  Secure Identity Access Portal  toggle. The Secure Identity Access Portal toggle appears in the on position and the Disclaimer Text field appears. (Optional) Click the  Guest Access  toggle to turn it to the off position if you do not want guest users to be able to log in to your network. (Optional) Enter a description in the Disclaimer Text field to provide additional information to your users. For example, this field can be used to display an acceptable use policy or a required legal statement.  (Optional) Click  Preview . The Secure Identity Access Portal page opens in a new window and displays a preview of the page users are presented with when they encounter the secure identity access portal. Click  Submit . The Secure Identity Access Portal page appears and secure identity access portal is now enabled.  (Optional) Configure secure identity access portal rules to exempt certain clients from encountering the secure identity access portal. See the procedure in the next section to add secure identity access portal rules. Secure identity access portal rules When you configure the secure identity access portal, you can add secure identity access portal rules to exempt certain clients or applications from the secure identity access portal. For example, you can create rules to allow traffic from peripheral devices, such as printers, to bypass the secure identity access portal. These rules can be configured to match traffic using the following match criteria: Source IPs Source zones HTTP headers Destination networks The following secure identity access portal rules are configured by default: Intercept Browser Based Traffic—Uses an  HTTP Header asset  named  Browser based traffic  to match browser-based traffic and ensure it encounters secure identity access portal. This HTTP Header asset is managed by Aryaka and matches traffic with the sec-ch-ua header.  Skip Captive Portal for the rest of the traffic—Matches all other traffic and bypasses secure identity access portal.  You cannot edit the default rules, but you can override the default rules by creating additional rules and placing them above the default rules in the rule table.   The Rule table displays a list of configured secure identity access portal rules. Each table row includes the following details: Rule ID—Identification number for the rule, used in security logs. Name—User-defined name for the rule. Source—Match criteria related to the source of the traffic (for example, source IP address or user).  Destination—Match criteria related to the destination of the traffic (for example, destination IP address or domain). Payload—Match criteria related to HTTP method and HTTP header. Skip Secure Identity Access Portal—Indicates whether matched traffic bypasses secure identity access portal.  Note the following when interacting with the Rules table: If a single match criteria has more than four entires, click  Show More  to view all entires.  If an asset is used as match criteria, click the asset name to display an in-page view of what the asset includes. The Rules table also includes the following components: Detailed View toggle—Turn this toggle on to display details on the type of match criteria (for example, IP or URL) and the required condition (for example, is or is not) included in a rule. When this toggle is turned off, only the specific match criteria are displayed.  Download Table icon—Download the Rules table as a CSV file. Configure table icon—Select whether to display the columns related to match criteria (source, destination, and payload) in the table. Follow the procedures in this section to add secure identity access portal rules or to view and edit existing secure identity access portal rules. To add secure identity access portal rules Navigate to the Secure Identity Access Portal page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  Settings  in left navigation pane. The Settings page appears.  Click  Manage  in the Secure Identity Access Portal tile. The Secure Identity Access Portal page appears and displays the Configure Secure Identity Access Portal pane and Rules table in read-only mode. Click  Edit  on the Rules table. The Secure Identity Access Portal Policies page appears and displays the Rules table. Click  Add . The Details pane and the Match Criteria pane appear.  In the Details pane, enter a name for the rule in the Policy Name field.  (Optional) Turn the  Skip Secure Identity Access Portal  toggle to the off position if you want rule matches to encounter the secure identity access portal. In the Match Criteria pane, complete the following procedure for each of the criterion you want to include in the rule:  Click the  Condition  drop-down list and select a condition for the criterion. Complete one of the following procedures to add match criteria: Type a criterion into the appropriate field and hit Enter. The criterion is added. Click the  Add  icon. The Add < criterion > dialog appears. Depending on the type of match criteria selected, do one of the following: Click one or more entities you want to include as match criteria for the rule. The selected entities are highlighted in green and display a check. Click  Add Selected . The page displays the selected entities for each criterion.  Enter one or more entities you want to include as match criteria for the rule. Click  Add Selected . The page displays the selected entities for each criterion.  Click  Continue . The Secure Identity Access Portal Policies page appears with the rule you added included in the Rules table.  (Optional) Repeat steps 3–7 to add an additional Secure Identity Access Portal rule.  (Optional) To reorder the Rules table, click the  Reposition  icon next to the rule you want to move and drag it to a new position in the table. Note:   Rules are evaluated in a top-down manner based on the Rules table. The first rule that matches the traffic is executed and the rest are ignored. Do one of the following: Click  Save as Draft  to save a draft of your secure identity access portal rules. Click  Submit . The Secure Identity Access Portal page displays your updated configuration.  To edit secure identity access portal rules Navigate to the Secure Identity Access Portal page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  Settings  in left navigation pane. The Settings page appears.  Click  Manage  in the Secure Identity Access Portal tile. The Secure Identity Access Portal page appears in read-only mode. Click  Edit  on the Rules table. The Secure Identity Access Portal Policies page appears in edit mode. Use the following options to modify a secure identity access portal rule as needed: Edit —Displays the match criteria in edit mode. Add, edit, or remove entities from any of the match criteria. Complete step 6 of the  Add secure identity access portal rules  procedure to add or edit the entities included in a criterion, then click  Continue . Add Below —Adds a new blank rule below the selected rule. Options  >  Clone —Adds a new rule with the same match criteria as the cloned rule. The new rule is added to the Rules table directly after the rule it was cloned from. Options  >  Disable —Renders the rule inactive, but does not remove it from the Rules table. The rule can be reenabled later.  Options  >  Delete —Removes the rule from the Rules table.  Reorder the Rules table—Click the  Reposition  icon next to the rule you want to move and drag it to a new position in the Rules table. Note:   Rules are evaluated in a top-down manner based on the Rules table. The first rule that matches the traffic is executed and the rest are ignored.  Do one of the following: Click  Save as Draft  to save a draft of your secure identity access portal rules. Click  Submit . The Secure Identity Access Portal page displays your updated configuration.  In this topic Related topics Network user identity management