# Requesting Access

This guide explains how to request just-in-time access to private network resources protected by Cisco Secure Access through P0.

## Overview

When your organization uses P0 with Cisco Secure Access, you can request temporary access to private resources (servers, databases, applications) without permanent access rules. P0 creates a time-limited Access Policy rule in Cisco Secure Access and automatically removes it when access expires or is revoked.

## Prerequisites

Before requesting access, ensure you have:

* **P0 access**: Your P0 account is set up and you belong to the relevant access groups.
* **Cisco Secure Access client**: Install the Cisco Secure Access client application on your workstation.
* **SSO credentials**: Your identity provider credentials (for example, Okta, Microsoft Entra ID).

## Requesting from the P0 app

1. Open the P0 app and navigate to the **Access Management** page.
2. Click **Request Access**.
3. Click the dropdown for **Resource** and select **Cisco Secure Access**.
4. Select your **Organization** and enter the **Private Resource** name or ID.
5. Enter **Reason access is needed** and **Requested access duration**. Both fields are optional.

Once you submit the request, an approver can navigate to the **Access Management** page, select **Approve**, and approve the request for a specific time. If the system is configured for auto-approval, it grants access immediately.

To revoke access early, an approver can navigate to the **Access Management** page, select the **Prior Approval** tab, and click **Revoke**.

## After access is granted

1. Open the **Cisco Secure Access client** on your workstation.
2. Log in with your **SSO credentials**.
3. Connect to the private resource using its **private IP address**.

P0 automatically removes the access rule when the granted duration expires.

## Additional resources

* [Cisco Secure Access documentation](https://docs.sse.cisco.com/sse-dns-guide/docs/get-started-secure-access)
* [Cisco Secure Access API reference](https://developer.cisco.com/docs/cloud-security/secure-access-api-reference-overview/)
