<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Sponsor Groups with different privileges in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4423748#M568104</link>
    <description>&lt;P&gt;Hi Leoni,&lt;/P&gt;&lt;P&gt;Maybe you could try to create multiple standard sponsor groups, in which each user would be able to see only his own accounts. You would achieve this by creating and configuring multiple locations, and option Sponsor Can Manage: Only accounts sponsor has created.&lt;/P&gt;&lt;P&gt;You would then create manager sponsor group, which would be combination of local location, and option Sponsor Can Manage: Accounts created by members of this sponsor group. Main idea is to use combination of Location and "Sponsor Can Manage" options.&lt;/P&gt;&lt;P&gt;I never used this combination, but logically, it might work.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jun 2021 11:18:43 GMT</pubDate>
    <dc:creator>Milos_Jovanovic</dc:creator>
    <dc:date>2021-06-25T11:18:43Z</dc:date>
    <item>
      <title>ISE Sponsor Groups with different privileges</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4423048#M568049</link>
      <description>&lt;P&gt;Hello Community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are operation a ISE deployment for all of our sites araund the world. At the moment we are chanign our Guest Workflow to a Sponsor based deployment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Originally it was planned that every user can sponsor guest accounts but the requirements chagened.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we have the the requirement that we have to controll it on a country basis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need for every country a Admin Sponsor group which can see all Accounts which are created in that Area. And the User should only see his Accounts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i create a new sponsor group on a country Basis everybody how is in the group can see all accounts. Is it possible to solve that problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards Stefan&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 08:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4423048#M568049</guid>
      <dc:creator>Leoni Wartung</dc:creator>
      <dc:date>2021-06-24T08:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Groups with different privileges</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4423497#M568098</link>
      <description>&lt;P&gt;As per my understanding all sponsor users can saw all the guest account.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 22:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4423497#M568098</guid>
      <dc:creator>Nit in Net</dc:creator>
      <dc:date>2021-06-24T22:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Groups with different privileges</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4423702#M568101</link>
      <description>&lt;P&gt;Yes that is possible, but i want, that the Manager of a Region can see all Guest Accounts from that Region. But the Sponsors should only see there created Accounts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lets say, i have only one region, than its not a problem. But i have lets say 20 Regions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards Stefan&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 09:23:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4423702#M568101</guid>
      <dc:creator>Leoni Wartung</dc:creator>
      <dc:date>2021-06-25T09:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Groups with different privileges</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4423748#M568104</link>
      <description>&lt;P&gt;Hi Leoni,&lt;/P&gt;&lt;P&gt;Maybe you could try to create multiple standard sponsor groups, in which each user would be able to see only his own accounts. You would achieve this by creating and configuring multiple locations, and option Sponsor Can Manage: Only accounts sponsor has created.&lt;/P&gt;&lt;P&gt;You would then create manager sponsor group, which would be combination of local location, and option Sponsor Can Manage: Accounts created by members of this sponsor group. Main idea is to use combination of Location and "Sponsor Can Manage" options.&lt;/P&gt;&lt;P&gt;I never used this combination, but logically, it might work.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 11:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4423748#M568104</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-06-25T11:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Groups with different privileges</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4424474#M568125</link>
      <description>&lt;P&gt;Create your sponsor accounts for each country and be sure to select:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="attributePaddingBottom"&gt;&lt;LABEL&gt;&lt;STRONG&gt;Sponsor Can Manage&lt;/STRONG&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;TABLE width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;INPUT id="manageOnlyAccountOpt" style="margin-right: 5px;" name="manageAccount" type="radio" /&gt;&lt;LABEL&gt;Only accounts sponsor has created&lt;/LABEL&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;⦿&amp;nbsp;&lt;LABEL&gt;Accounts created by members of this sponsor group&lt;/LABEL&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;INPUT id="manageAccountByAllOpt" style="margin-right: 5px;" name="manageAccount" type="radio" /&gt; &lt;LABEL&gt;All guest accounts&amp;nbsp; &amp;lt;=== &lt;EM&gt;make sure you are not using this one!&lt;/EM&gt;&lt;BR /&gt;&lt;/LABEL&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 27 Jun 2021 21:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4424474#M568125</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-06-27T21:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Groups with different privileges</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4426587#M568255</link>
      <description>&lt;P&gt;Hello Thomas,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, i know that option but than all users see the guest accounts and not only the Manager of the region.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 08:38:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4426587#M568255</guid>
      <dc:creator>Leoni Wartung</dc:creator>
      <dc:date>2021-07-01T08:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Groups with different privileges</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4428219#M568324</link>
      <description>&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;A id="link_19" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/224143" target="_self" aria-label="View Profile of Leoni Wartung"&gt;&lt;SPAN class=""&gt;Leoni Wartung,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;Milos has the right idea. Below is an example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;User Identity Groups&lt;/U&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;us-sponsors&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;us-managers&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;uk-sponsors&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;uk-managers&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;cn-sponsors&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;cn-managers&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;U&gt;Network Access Users&lt;/U&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;For each region, sponsors will be in the sponsors group of that region but managers will be in both the sponsors and the managers groups of the region.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;Sponsor Groups&lt;/U&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;us-sponsors : Duplicate of OWN_ACCOUNTS (default) but mapped us-sponsors as the only member&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;us-managers: Duplicate of GROUP_ACCOUNTS (default) but mapped us-managers as the only member&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;uk-sponsors : Duplicate of OWN_ACCOUNTS (default) but mapped uk-sponsors as the only member&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;uk-managers: Duplicate of GROUP_ACCOUNTS (default) but mapped uk-managers as the only member&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;cn-sponsors : Duplicate of OWN_ACCOUNTS (default) but mapped cn-sponsors as the only member&lt;/LI&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;cn-managers: Duplicate of GROUP_ACCOUNTS (default) but mapped cn-managers as the only member&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 18:55:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-groups-with-different-privileges/m-p/4428219#M568324</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-07-05T18:55:49Z</dc:date>
    </item>
  </channel>
</rss>

