<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [EDIT] How to retrieve the portal ID of a guest account? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5051097#M588407</link>
    <description>&lt;P&gt;We have two ISE ecosystems different and isolated (2.7 and 3.2)&lt;BR /&gt;I must migrate guest accounts from one system to the other one.&lt;BR /&gt;On 2.7 we have two sponsorportals and so it is on 3.2.&lt;BR /&gt;I managed to retrieve captive portal users through a python script of mine.&lt;/P&gt;&lt;P&gt;Though I see that this page reports that the portal ID (I guess the sponsor portal) is present in the REST-API reply, I don't see it.&lt;/P&gt;&lt;P&gt;&lt;A href="https://developer.cisco.com/docs/identity-services-engine/v1/#!guestuser" target="_blank" rel="noopener"&gt;https://developer.cisco.com/docs/identity-services-engine/v1/#!guestuser&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have also noticed that we my AD user I can retrieve the user lists through ERS, but to get the sponsor portals IDs, I must use a super admin internal account.&lt;BR /&gt;I suspect that, since the user used to retrieve the users list might be restricted to just one sponsor portal , ERS correctly think that I don't need the portal ID.&lt;BR /&gt;Here I read:&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;"You can use the default ISE admin account for ERS APIs since it has SuperAdmin privileges. However, it is recommended to create separate users with the &lt;STRONG&gt;ERS Admin&lt;/STRONG&gt; (Read/Write) or &lt;STRONG&gt;ERS Operator&lt;/STRONG&gt; (Read-Onlly) privileges to use the ERS APIs so you can separately track and audit their activities."&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-ers-api-examples/ta-p/3622623#toc-hId-746822939" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-ers-api-examples/ta-p/3622623#toc-hId-746822939&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but honestly it doesn't seem to work that way.&lt;/P&gt;&lt;P&gt;So, from my induction reasoning, a super admin is not automatically granted the rights to manage the guest users of a sponsor portal, but it might be specifically assigned; I haven't found a way trhough.&lt;/P&gt;&lt;P&gt;I'm facing many variable things here, and since I'm quite new to ISE from this perspective, I may need the help of sombody who's more expert on this topic, to eliminate non-significant information.&lt;/P&gt;&lt;P&gt;Any help/idea/advise will be very much appreciated.&lt;/P&gt;&lt;P&gt;Gio&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2024 10:48:06 GMT</pubDate>
    <dc:creator>Gioacchino</dc:creator>
    <dc:date>2024-03-27T10:48:06Z</dc:date>
    <item>
      <title>[EDIT] How to retrieve the portal ID of a guest account?</title>
      <link>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5051097#M588407</link>
      <description>&lt;P&gt;We have two ISE ecosystems different and isolated (2.7 and 3.2)&lt;BR /&gt;I must migrate guest accounts from one system to the other one.&lt;BR /&gt;On 2.7 we have two sponsorportals and so it is on 3.2.&lt;BR /&gt;I managed to retrieve captive portal users through a python script of mine.&lt;/P&gt;&lt;P&gt;Though I see that this page reports that the portal ID (I guess the sponsor portal) is present in the REST-API reply, I don't see it.&lt;/P&gt;&lt;P&gt;&lt;A href="https://developer.cisco.com/docs/identity-services-engine/v1/#!guestuser" target="_blank" rel="noopener"&gt;https://developer.cisco.com/docs/identity-services-engine/v1/#!guestuser&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have also noticed that we my AD user I can retrieve the user lists through ERS, but to get the sponsor portals IDs, I must use a super admin internal account.&lt;BR /&gt;I suspect that, since the user used to retrieve the users list might be restricted to just one sponsor portal , ERS correctly think that I don't need the portal ID.&lt;BR /&gt;Here I read:&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;"You can use the default ISE admin account for ERS APIs since it has SuperAdmin privileges. However, it is recommended to create separate users with the &lt;STRONG&gt;ERS Admin&lt;/STRONG&gt; (Read/Write) or &lt;STRONG&gt;ERS Operator&lt;/STRONG&gt; (Read-Onlly) privileges to use the ERS APIs so you can separately track and audit their activities."&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-ers-api-examples/ta-p/3622623#toc-hId-746822939" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-ers-api-examples/ta-p/3622623#toc-hId-746822939&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but honestly it doesn't seem to work that way.&lt;/P&gt;&lt;P&gt;So, from my induction reasoning, a super admin is not automatically granted the rights to manage the guest users of a sponsor portal, but it might be specifically assigned; I haven't found a way trhough.&lt;/P&gt;&lt;P&gt;I'm facing many variable things here, and since I'm quite new to ISE from this perspective, I may need the help of sombody who's more expert on this topic, to eliminate non-significant information.&lt;/P&gt;&lt;P&gt;Any help/idea/advise will be very much appreciated.&lt;/P&gt;&lt;P&gt;Gio&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 10:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5051097#M588407</guid>
      <dc:creator>Gioacchino</dc:creator>
      <dc:date>2024-03-27T10:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: [EDIT] How to retrieve the portal ID of a guest account?</title>
      <link>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5051531#M588441</link>
      <description>&lt;P&gt;On-going troubleshooting with TAC...&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 16:12:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5051531#M588441</guid>
      <dc:creator>Gioacchino</dc:creator>
      <dc:date>2024-03-27T16:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: [EDIT] How to retrieve the portal ID of a guest account?</title>
      <link>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5071141#M588795</link>
      <description>&lt;P&gt;Hi, this is interesting. How it your troubleshooting with TAC going?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 19:51:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5071141#M588795</guid>
      <dc:creator>SingularTruth</dc:creator>
      <dc:date>2024-04-16T19:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: [EDIT] How to retrieve the portal ID of a guest account?</title>
      <link>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5073168#M588845</link>
      <description>&lt;P&gt;API queries were run against 4 different versions of ISE (2.7, 3.1, and 3.2 different patches).&lt;BR /&gt;ISE clearly replies with no portalID in all the cases.&lt;BR /&gt;The documentation says something different.&lt;BR /&gt;I'm still waiting for feedback.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 16:22:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5073168#M588845</guid>
      <dc:creator>Gioacchino</dc:creator>
      <dc:date>2024-04-18T16:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: [EDIT] How to retrieve the portal ID of a guest account?</title>
      <link>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5076371#M588945</link>
      <description>&lt;P&gt;Eventually they pointed me to a bug, that states that the documentation is wrong.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 15:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/edit-how-to-retrieve-the-portal-id-of-a-guest-account/m-p/5076371#M588945</guid>
      <dc:creator>Gioacchino</dc:creator>
      <dc:date>2024-04-23T15:26:31Z</dc:date>
    </item>
  </channel>
</rss>

