Access decisions in Cloud Secure Edge (CSE) depend on accurately identifying who the user is and which device they are using. CSE integrates with your existing Identity Provider (IdP) and device management platforms so that user identity and device posture remain authoritative in their source systems.
During this process, CSE evaluates device trust using Certificate‑based authentication, device trust verification, integrations with device managers such as Intune, Jamf Pro, Kandji, JumpCloud, and Workspace ONE UEM.
However, if a user attempts to log in with a different method or email than the one used during initial registration or if the certificate is missing or incorrectly deployed, authentication errors may occur.
NOTE: Do NOT Delete Users from the CSE Console. Doing so may trigger additional errors, as it revokes the certificates previously registered with that account.
To confirm if the CSE certificate was installed on Windows:
Managed Certificates - Trusted Root Certification Authorities - Certificates - Locate your CSE private certificate such as “CSEnamePrivateRootCA”
Follow these steps when a device needs to be unregistered and re‑registered or when login/authentication issues occur or certificate errors.
-Client-kA1VN0000000DYP0A2-0EMVN00000aH9YP.jpg)
-Client-kA1VN0000000DYP0A2-0EMVN00000aH6fO.jpg)
If the Issue Persists:
Please, open a technical CSE support ticket and include:
You can revisit debug log analysis for help interpreting the logs.
How to Collect Banyan Debug Logs: https://www.sonicwall.com/support/knowledge-base/how-to-collect-banyan-debug-logs/kA1VN0000000RwL0AU