<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic roll based access control in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/roll-based-access-control/m-p/3837682#M473878</link>
    <description>&lt;P&gt;got this question from a customer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Calibri, sans-serif; font-size: 14.666666984558105px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;Is there a way to restrict an ISE Admin to maintaining policy for certain Identity Groups?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Calibri, sans-serif; font-size: 14.666666984558105px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;Any help would be greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Apr 2019 15:14:40 GMT</pubDate>
    <dc:creator>darnorri</dc:creator>
    <dc:date>2019-04-12T15:14:40Z</dc:date>
    <item>
      <title>roll based access control</title>
      <link>https://community.cisco.com/t5/network-access-control/roll-based-access-control/m-p/3837682#M473878</link>
      <description>&lt;P&gt;got this question from a customer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Calibri, sans-serif; font-size: 14.666666984558105px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;Is there a way to restrict an ISE Admin to maintaining policy for certain Identity Groups?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Calibri, sans-serif; font-size: 14.666666984558105px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;Any help would be greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 15:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/roll-based-access-control/m-p/3837682#M473878</guid>
      <dc:creator>darnorri</dc:creator>
      <dc:date>2019-04-12T15:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: roll based access control</title>
      <link>https://community.cisco.com/t5/network-access-control/roll-based-access-control/m-p/3837754#M473880</link>
      <description>As far as I know you cannot accomplish that scenario. As far as Authorization permissions for RBACL it is broken down by Menu and Data access. In the Menu access you can either Show or Hide all policy sets. However, you can grant RBACL for the admins to only manage their specific identity groups via specific configuration under Data access. That would be similar to modifying the Policy Admin Data Access role. HTH!</description>
      <pubDate>Fri, 12 Apr 2019 17:29:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/roll-based-access-control/m-p/3837754#M473880</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-04-12T17:29:24Z</dc:date>
    </item>
  </channel>
</rss>

