[2026-07-22] Unlock Your Creativity: Adobe Creative Cloud Available to All HKBU Staff (Staff Only)
[2026-08-18] Service Maintenance: BUniPort (Staff & Student)
[2026-08-24] Scheduled Maintenance: Human Capital Management (HCM) System (Staff Only)
The Secure Remote Access Service (“The SASE Service”) is a modern security channel that provides users with an enhanced remote access experience, ensuring secure and efficient connections to the University's sensitive IT services, systems and data—anytime, anywhere.
Enhanced Security and Accessibility with Ease
The SASE service facilitates remote access to sensitive data in intranet office backend systems with enhanced user experience by adopting the "Zero Trust" security principle: "Never trust, always verify". It checks your identity (SSOid) and the device's explicit permission for every single access and action taken to enhance the protection.
SASE simplifies how you connect to the Supported IT Services/Applications and sensitive data you need. It provides a single, secure gateway to all university resources.
What this means for you:
Universal Access: Reach internal websites and restricted systems from any location, e.g. stationed at "Open Office" or from your home.
Seamless File Management: Access your network folders and shared drives off-campus.
Flexible Printing: Print to your office network printers from anywhere. *
* Please contact ITO for configuration arrangement
| Laptop or Desktop PC models purchased under PC or Laptop Tender with FO | Others * | |||
| Type of Device | Domain-joined Windows Device | Standalone Windows Device | Mac OS Device | |
| Official Support | Yes | Yes | No | No |
* Including the non-standard laptop/PC models owned by the University/Department Units/Research Projects/Centres, or any personally owned laptops/PCs.
We will continuously expand the service by increasing the number of intranet/restricted IT services supported by SASE.
The initial launch will include access to, but is not limited to, the following:
It depends on the resources you need to access.
SIA is used to connect to Restricted Internet Cloud Service including but not limited to Human Capital Management (HCM), Activity and Relationship Management System (ARMS) and Geographically Restricted Internet Resources (e.g. OpenAI)
SPA is used to connect to Restricted Intranet Service including but not limited to Office/ Staff PCs, Central Managed Network Drives, Oracle E-Business Suite (EBS), Network Printers* and Restricted Departmental Applications*.
If not sure, connect/ enroll to both SIA and SPA or refer to Supported IT Services/Applications for more details
* Please contact ITO for configuration arrangement
You will be automatically logged out of SIA & SPA after 24 hours and will need to reauthenticate to continue using these services.
It is a best practice to disconnect from / unenroll from SIA & SPA manually once finish using.
This could be caused by a network issue. If you are on campus, please make sure you are connected to one of the following Wi-Fi networks:
If you are already connected to one of these networks and still experience issues, try restarting your device or contact ITO for further assistance.
Please refer to the Supported IT Services/Applications to check if the resource is currently supported by SASE.
For access to other restricted departmental applications, kindly contact ITO for configuration arrangement.
The Campus LAN will take priority, and your network traffic will bypass SASE service.
Please enter the full path of the network drive (eg. \\xxx.hkbuad.local\xxx).
You can ignore this error message. Please try logging in with your credentials again; you should then be able to access the network drive.
Please verify that you have entered the correct username and password. Also, ensure that the domain is set to HKBUAD. If it is not, enter your username in the format HKBUAD\username
Please restart your computer and try again. If you are on campus, make sure you are connected to either the BU-Standard or BU-Advanced Wi-Fi networks. If the issue persists, contact ITO for further assistance.
If your profile option missing in SIA:
Manually enter ap-east-1-5c53.vpn.sse.cisco.com/HKBU_Prd to connect using the HK IP address
OR
Manually enter ap-southeast-1-5c53.vpn.sse.cisco.com/HKBU_Prd to connect using Singapore IP address for accessing geographically restricted cloud services
It typically takes around 10-15 minutes for the system to re-evaluate your device. If you want to trigger the posture check immediately, you can manually unenroll and then re-enroll your device. For instructions on how to unenroll, please refer to the installation guide.
You may have installed multiple endpoint security agents, some of which may not be supported by the solution. Please uninstall any unsupported security agents (refer to the device pre-requisites of installation guide).
If you have installed ESET Endpoint Security, please refer to the steps below to uninstall it from Windows or macOS devices:
1. Uninstall ESET (for Windows users):
2. Uninstall ESET (for macOS users):
3. Restart your computer
4. Manually unenroll
Third-party security firewall may take over native firewall, so you fail the posture checking. To fix the issue, please follow the steps below:
1. Disable the Third-Party Firewall:
2. Enable Windows Firewall (for Windows users):
3. Enable Mac Firewall (for Mac users):
4. Restart Your Computer:
Cisco Secure Client does not support multiple user sessions. Before signing out or switching to another user account, please disconnect from/ unenroll from the SIA/ SPA. This helps prevent you SASE account from being locked.
Yes, however, Cisco Secure Client is supported only on iPads; other mobile devices are not supported.
Type “Add or remove programs” in the Windows search bar and open the application.
Search for “Cisco” in the list of installed programs and uninstall the following five applications.
After uninstalling, manually remove the leftover folders at the following locations:
C:\ProgramData\Cisco
C:\Users\<user>\AppData\Local\Cisco
C:\Program Files (x86)\Cisco
C:\Program Files\Cisco\Cisco Secure Client
Free of Charge
The Secure Remote Access Service (“The SASE Service”) is a modern security channel that provides users with an enhanced remote access experience, ensuring secure and efficient connections to the University's sensitive IT services, systems and data—anytime, anywhere.
This briefing session will introduce you to this new service and guide you on its use, which will cover the following topics:
| 10 October 2025 (Fri) | |
| 3:00 pm – 4:00 pm | |
| Online | |
| Cantonese | |
| Staff | |
| Training Deck | |
| Training Video |
The Secure Remote Access Service (“The SASE Service”) is a modern security channel that provides users with an enhanced remote access experience, ensuring secure and efficient connections to the University's sensitive IT services, systems and data—anytime, anywhere.
This briefing session will introduce you to this new service and guide you on its use, which will cover the following topics:
| 13 October 2025 (Mon) | |
| 3:00 pm – 4:00 pm | |
| Online | |
| English | |
| Staff | |
| Training Deck | |
| Training Video |