<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RBAC - Read only is not working for External Admin User in ISE 2.4 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/rbac-read-only-is-not-working-for-external-admin-user-in-ise-2-4/m-p/3999084#M454997</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have questions regarding Admin Access, if the Admin user that i created is based on External AD.&lt;/P&gt;&lt;P&gt;and If i tick the read only or apply an rbac-read only policy.&lt;/P&gt;&lt;P&gt;It is not affecting the admin account. Once i Login, i can still write on ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but if i create an internal admin account on ISE. Read only and RBAC policy is working.&lt;/P&gt;&lt;P&gt;Have you encountered this scenario? How to fix this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Sun, 15 Dec 2019 15:22:49 GMT</pubDate>
    <dc:creator>jakeraze</dc:creator>
    <dc:date>2019-12-15T15:22:49Z</dc:date>
    <item>
      <title>RBAC - Read only is not working for External Admin User in ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/rbac-read-only-is-not-working-for-external-admin-user-in-ise-2-4/m-p/3999084#M454997</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have questions regarding Admin Access, if the Admin user that i created is based on External AD.&lt;/P&gt;&lt;P&gt;and If i tick the read only or apply an rbac-read only policy.&lt;/P&gt;&lt;P&gt;It is not affecting the admin account. Once i Login, i can still write on ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but if i create an internal admin account on ISE. Read only and RBAC policy is working.&lt;/P&gt;&lt;P&gt;Have you encountered this scenario? How to fix this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 15 Dec 2019 15:22:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rbac-read-only-is-not-working-for-external-admin-user-in-ise-2-4/m-p/3999084#M454997</guid>
      <dc:creator>jakeraze</dc:creator>
      <dc:date>2019-12-15T15:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: RBAC - Read only is not working for External Admin User in ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/rbac-read-only-is-not-working-for-external-admin-user-in-ise-2-4/m-p/3999140#M454999</link>
      <description>&lt;P&gt;Is the AD user only mapped to a single group leveraged in the admin access policy or multiple?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could see ise using first match rather than least privilege for access but I have not tested it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What ise admin groups are you trying to leverage right now?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Dec 2019 22:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rbac-read-only-is-not-working-for-external-admin-user-in-ise-2-4/m-p/3999140#M454999</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-12-15T22:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: RBAC - Read only is not working for External Admin User in ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/rbac-read-only-is-not-working-for-external-admin-user-in-ise-2-4/m-p/3999230#M455001</link>
      <description>I created custom admin groups that have limitation on viewing some menu. - didn't work as external&lt;BR /&gt;i tried helpdesk admin group. - still did not work if the account is external.&lt;BR /&gt;&lt;BR /&gt;same username and make it as internal to ISE. - Read only and RBAC Helpdesk admin is working.&lt;BR /&gt;&lt;BR /&gt;is this some kind of a bug? using ISE 2.4 patch none.</description>
      <pubDate>Mon, 16 Dec 2019 07:14:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rbac-read-only-is-not-working-for-external-admin-user-in-ise-2-4/m-p/3999230#M455001</guid>
      <dc:creator>jakeraze</dc:creator>
      <dc:date>2019-12-16T07:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: RBAC - Read only is not working for External Admin User in ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/rbac-read-only-is-not-working-for-external-admin-user-in-ise-2-4/m-p/3999698#M455002</link>
      <description>It is possible that you are hitting a defect as RBAC read-only support with external identity sources gained support in ISE 2.3.  I would also check the release notes to see if there is a defect listed and if it is resolved in a patch for ISE 2.4.  If not, you can contact the TAC to troubleshoot further.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;-Tim</description>
      <pubDate>Tue, 17 Dec 2019 00:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rbac-read-only-is-not-working-for-external-admin-user-in-ise-2-4/m-p/3999698#M455002</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2019-12-17T00:45:09Z</dc:date>
    </item>
  </channel>
</rss>

