<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multi-tenant admin group for ISE platform in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multi-tenant-admin-group-for-ise-platform/m-p/3768132#M486816</link>
    <description>&lt;P&gt;This is possible but with some limitation -- See&amp;nbsp;CSCvb55884&lt;/P&gt;</description>
    <pubDate>Sat, 22 Dec 2018 02:27:41 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-12-22T02:27:41Z</dc:date>
    <item>
      <title>Multi-tenant admin group for ISE platform</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-tenant-admin-group-for-ise-platform/m-p/3767674#M486814</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;Customer using 2.3P5 version, Currently it only supports single tenancy (ie. Single Admin group). Customer looking at migrating four different networks to this platform and there may be a requirement to have the different operational groups managing their own four network.&lt;/P&gt;
&lt;P&gt;What’s the current Roadmap for the ISE Platform?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Dave Viral&lt;/P&gt;
&lt;P&gt;+6 470254746&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 02:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-tenant-admin-group-for-ise-platform/m-p/3767674#M486814</guid>
      <dc:creator>vidave</dc:creator>
      <dc:date>2018-12-21T02:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-tenant admin group for ISE platform</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-tenant-admin-group-for-ise-platform/m-p/3767700#M486815</link>
      <description>&lt;P&gt;You'll have a hard time getting roadmap information on this forum - best to reach out internally to the ISE PM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has your customer considered using RBAC?&amp;nbsp; You can create some Data Access restrictions that will ensure that only the right people can edit their allowed devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It doesn't seem possible to HIDE the non-allowed devices - but you can enforce adds/changes to be made.&lt;/P&gt;
&lt;P&gt;e.g. below the user group member can only edit the devices that are in location IPTEL-LOCATION-MILTON&lt;/P&gt;
&lt;P&gt;If they try editing any other devices they get a GUI error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's not perfect, but potentially useful.&amp;nbsp; You can hide menu items though - but in a multi-tenanted environment the data hiding is probably more important. It seems like a bug to me that you can specify "No access" to ertain data elements, but ISE will still display the data.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RBAC.PNG" style="width: 988px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/26580i85AA02530BAC9EA3/image-size/large?v=v2&amp;amp;px=999" role="button" title="RBAC.PNG" alt="RBAC.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 05:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-tenant-admin-group-for-ise-platform/m-p/3767700#M486815</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-12-21T05:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-tenant admin group for ISE platform</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-tenant-admin-group-for-ise-platform/m-p/3768132#M486816</link>
      <description>&lt;P&gt;This is possible but with some limitation -- See&amp;nbsp;CSCvb55884&lt;/P&gt;</description>
      <pubDate>Sat, 22 Dec 2018 02:27:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-tenant-admin-group-for-ise-platform/m-p/3768132#M486816</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-22T02:27:41Z</dc:date>
    </item>
  </channel>
</rss>

