<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE ERS API Limited Access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ers-api-limited-access/m-p/4389080#M566791</link>
    <description>&lt;P&gt;The ERS Admin and ERS Operator groups have no Menu Access Permissions (and cannot be customised) so admin users associated with these groups cannot login to the GUI.&lt;/P&gt;
&lt;P&gt;There is currently no full RBAC functionality for the REST API to limit access to ERS admins/operators. Although we cannot discuss roadmap on this forum, it is likely that future versions of ISE will provide feature enhancements around RBAC for the REST API. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Apr 2021 01:27:56 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2021-04-19T01:27:56Z</dc:date>
    <item>
      <title>ISE ERS API Limited Access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ers-api-limited-access/m-p/4388443#M566774</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have certain teams that have very limited ISE GUI permissions for both Menu and Data. The purpose is to give them as simple an interface as possible but enable them to add/edit/delete endpoints that will have access to their specific network. Their Data Access permissions are limited to a single Endpoint Identity Group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering if there is a way to also give these specific users access to the ERS API, but with the same limited permissions. Are users in the ERS Operator or ERS Admin group also limited to the Data Permissions for the GUI, or do they have access to everything on ISE, either Read-Only or Read &amp;amp; Write? Or is there another way to limit their access?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 14:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ers-api-limited-access/m-p/4388443#M566774</guid>
      <dc:creator>lukeberkheiser</dc:creator>
      <dc:date>2021-04-16T14:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE ERS API Limited Access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ers-api-limited-access/m-p/4388662#M566778</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/112766"&gt;@lukeberkheiser&lt;/a&gt;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;take a look at: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/api_ref_guide/api_ref_book/ise_api_ref_ers1.pdf" target="_blank" rel="noopener"&gt;Introduction to ERS API - 2.7&lt;/A&gt;, check the &lt;U&gt;prerequisites&lt;/U&gt; ...&lt;/P&gt;&lt;P class="lia-align-justify"&gt;"&lt;STRONG&gt;&lt;EM&gt;Prerequisites for Using the External RESTful Services API Calls&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;You &lt;STRONG&gt;must fulfill&lt;/STRONG&gt; the following prerequisites before invoking an External RESTful Services API call:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;• You &lt;STRONG&gt;must have&lt;/STRONG&gt; &lt;U&gt;enabled External RESTful Services&lt;/U&gt; from the GUI.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;• You &lt;STRONG&gt;must have&lt;/STRONG&gt; &lt;U&gt;External RESTful Services &lt;STRONG&gt;Admin privileges&lt;/STRONG&gt;&lt;/U&gt;.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;You can use any REST client like JAVA, curl linux command, python or any other client to invoke&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;External RESTful Services API calls.&lt;/EM&gt;"&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2021 00:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ers-api-limited-access/m-p/4388662#M566778</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-04-17T00:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE ERS API Limited Access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ers-api-limited-access/m-p/4389080#M566791</link>
      <description>&lt;P&gt;The ERS Admin and ERS Operator groups have no Menu Access Permissions (and cannot be customised) so admin users associated with these groups cannot login to the GUI.&lt;/P&gt;
&lt;P&gt;There is currently no full RBAC functionality for the REST API to limit access to ERS admins/operators. Although we cannot discuss roadmap on this forum, it is likely that future versions of ISE will provide feature enhancements around RBAC for the REST API. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 01:27:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ers-api-limited-access/m-p/4389080#M566791</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-04-19T01:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE ERS API Limited Access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ers-api-limited-access/m-p/4389156#M566795</link>
      <description>&lt;P&gt;Thank you for the information Greg&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 06:06:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ers-api-limited-access/m-p/4389156#M566795</guid>
      <dc:creator>lukeberkheiser</dc:creator>
      <dc:date>2021-04-19T06:06:11Z</dc:date>
    </item>
  </channel>
</rss>

