Troubleshooting Cisco Secure Connect Account Setup
Overview
Setting up Cisco Secure Connect involves configuring your account and mapping it to a Meraki Organization. This troubleshooting article walks you through common issues you may encounter during this process and how to resolve them.
Troubleshooting automatic API Key sync issue
New customers may encounter an error when attempting automated API key exchange for a new Umbrella org. Automated API key exchange is not supported for existing Umbrella orgs. The error appears as follows

Troubleshooting steps
-
When the error appears, click the link highlighted in the error message.
-
Manually exchange the API keys by following the instructions on the page. Read more here.
Troubleshooting multiple errors
Observed error: Network tunnels, Remote access, Users, Applications, Clientless (Browser-based) ZTNA access
- Errors on Overview page: "An error occurred while loading tunnels", " Error loading Remote access data"

- Error on Users page, no users present: "An error occurred while loading users"

- Error(s) on Browser Access page, potentially many per rule: "An error was encountered while loading browser access policy rule data"

- Errors on Applications page: "An error was encountered while loading applications.", "An error was encountered while loading application groups."

Troubleshooting steps: Replace Management Key
For the errors above, replace the Umbrella Management key to address this issue.
-
Navigate to Secure Connect > License & API Keys
- On the Umbrella Management credentials card, select "Replace API credentials"

- Follow the link and instructions to retrieve a new key.

- Select Link and Continue, then return to the Overview page to verify the fix.
Observed error: Policies, Policy Overview
- Error on Overview page: "Failed to load all policy data"

- Error on Policy Overview page: "Failed to load all policy data"

Troubleshooting steps: Replace Network Devices Key
For the errors above, replace the Umbrella Network Devices key to address this issue.
- Navigate to Secure Connect > License & API Keys
- On the Umbrella Network Devices credentials card, click on "Replace API credentials"

- Follow the link and instructions to retrieve a new key.

- Click Link and Continue, return to the Overview page to verify the fix.
Observed error: Remote access, Users, Browser access
- Errors on Overview page: " Error loading Remote access data" (Network tunnels have no errors)

- Error on Users page, no users present: "An error occurred while loading users" (Users are visible)

- Error(s) on Browser Access page, potentially many per rule: "Hit counts failed to load"

Troubleshooting steps: Replace Reporting Key
For the errors above, replace the Umbrella Reporting key to address this issue.
- Navigate to Secure Connect > License & API Keys
- On the Umbrella Reporting credentials card, click on "Replace API credentials"

- Follow the link and instructions to retrieve a new key.

- Click Link and Continue, return to the Overview page to verify the fix.
Check the data storage location
When an HTTP client request does not originate from the correct location of the Umbrella data warehouse, the Umbrella server returns a 302 Found response. This can manifest across multiple pages within Secure Connect.
To spot this issue:
-
Verify the location of data in the Meraki dashboard (at the bottom of any page):
-
Verify the location of Data Storage in Umbrella (Admin > Log Management)
-
If the Meraki dashboard data location and the Umbrella data storage location are not aligned, follow these steps to correct the issue: https://docs.umbrella.com/deployment-umbrella/docs/log-to-a-data-warehouse
Correct region pairings:Region/Location Meraki Hosting Location Umbrella Storage Region North America United States North America - California, US South America United States North America - California, US Europe Europe - Germany Europe - Frankfurt, DE Asia Asia - Singapore, Australia Europe - Frankfurt, DE
Secure Connect is not currently supported in the dashboards hosted in Canada, India, or China
Errors persist? Contact support.
If the two steps above have not resolved the issue, contact our support team. They'll have additional tools to troubleshoot.
Re-sending the welcome email or changing the recipient address
To change or re-send the email account associated with Secure Connect, contact support.
When contacting support, include the following in the support case:
- Subject line: Include "Secure Connect
- Description: Include the following details from the order:
- First Name, Last Name
- Admin Email - Use the admin email that matches Umbrella org
- Use the email from the order, or
- Use another email belonging to an admin in the Umbrella account, if others exist
- Umbrella Org Id
- If you cannot contact support through the dashboard, create a case here: https://meraki.cisco.com/meraki-supp...-support-case/
Troubleshooting wrong Umbrella organization dashboard issue
If you linked a wrong Umbrella organization that is not enabled for Secure Connect to the dashboard, use the steps in this section to unlink the incorrect org and link the correct one. Relinking the correct org ensures the integration between the dashboard and Umbrella is properly established.
For account-related queries, activation issues, or additional troubleshooting, contact Secure Connect support directly. How to Contact Support
Symptoms of this issue:
- Cannot go back in the API key exchange flow.
- Cannot see the Secure Connect tab in the left navigation.
Prerequisites
- If the Meraki org is new, create at least one network. This allows you to access the Cloud On-Ramps configuration, which is required to employ the workaround.
- If you previously deployed any Umbrella SD-WAN Connector under the Organization > Cloud On-Ramps page > Deployments tab, delete all current Umbrella SD-WAN Deployments.
All sites enrolled in Secure Connect must be detached via the Secure Connect > Sites page before unlinking the current Umbrella organization. Verify that the dashboard has deleted all Secure Connect Hub networks after branch sites were detached. Allow the Secure Connect and Umbrella systems sufficient time to complete the un-enrollment process and deletion of Secure Connect Hubs before making any changes to the linked Umbrella organization.
Troubleshooting steps
To override the org mapping, replace any one API key:
- Navigate to Organization > Cloud On-Ramps page.
- Under the Configuration tab of the Umbrella SD-WAN Connector > select the vertical ellipsis button (3 dots) > select Disconnect Umbrella to disconnect the current Umbrella org integration.

- Obtain the correct API Keys from your correct Secure Connect enabled Umbrella organization. For more information, refer to our Secure Connect Onboarding KB – Setting Up Your Cisco Secure Connect Account.
- Follow the steps from the Secure Connect Welcome Email to activate Secure Connect for the dashboard. For more information, refer to the Secure Connect Onboarding KB – Setting Up Your Cisco Secure Connect Account.
Changing the Umbrella org mapping to a new Meraki Org
You can change the Umbrella org mapping and re-enter or regenerate API keys.
To change the mapping, contact Secure Connect support to clear the API keys from the Secure Connect dashboard. Once cleared, you can use or regenerate Umbrella API keys to map another org. Once complete, follow the appropriate onboarding guide here: Setting Up Your Cisco Secure Connect Account
Troubleshooting EA licensing grace period warning
An organization with Secure Connect and Enterprise Agreement (EA) licensing has a warning in the Organization > Configure > Subscription and License Info page that Secure Connect Region networks do not have a subscription and will be disabled at the end of the licensing "Grace Period."
This warning will not affect the connectivity or management of Secure Connect or connected networks. You can consider this a cosmetic issue.

Troubleshooting steps
To resolve the grace period warning:
- Navigate to Organization > Configure > Subscription and License Info.
- Bind the Secure Connect networks to your existing EA subscription.
Binding the Secure Connect networks removes the networks from their subscription-less state and does not consume any license seats.
Remove Secure Connect from a Meraki org
Meraki orgs with Secure Connect enabled cannot currently be deleted. They can be downgraded. The Umbrella org with Secure Connect license can be connected to a new org (see below). To wind-down a Secure Connect org for example one used in a trial, contact support.
Deleting a Meraki org with Secure Connect enabled
To delete a Meraki org that has had Secure Connect enabled, first follow the steps above to remove Secure Connect from a Meraki org. Then follow the steps to delete a Meraki org here: https://documentation.meraki.com/General_Administration/Organizations_and_Networks/Deleting_an_Organization
Cannot complete setup after Umbrella and Meraki MR Auto integration
This issue occurs when the same admin user or email is used for MR-Advanced and Secure Connect accounts on MR Networks. When provisioning Secure Connect, an admin user who already has the MR-Advanced capability configured in any organization they control cannot see the Umbrella dashboard.
As noted in the documentation for Automatically Integrating Cisco Umbrella with Meraki Networks, this process is irreversible by a user. A single admin cannot manage multiple organizations that include a mix of MR-Advanced orgs automatically integrated with Umbrella and Secure Connect.
If this applies to you, contact support for further assistance.

