cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7970
Views
21
Helpful
12
Replies

Introducing RBAC (Role-Based Access Control) Foundations for enhanced admin management

mkung
Cisco Employee
Cisco Employee

We heard your need for more granular access control and are excited to introduce RBAC Foundations!

As a highly requested feature, RBAC Foundations (Early Access) is the first version of RBAC that makes it easier for you to control which admins have access to specific network resources and take bulk admin actions to significantly boost productivity.

Visit our documentation to learn more about RBAC in the dashboard Administrators page.

What’s new in RBAC Foundations

image.png

  • Increase productivity: manage admins in one place and enjoy faster page loading from a significant Administrators page performance boost.
  • Better network controls: assign more granular permissions with new and improved advanced role management E.g. SSID manager, Switch Port manager, and Client Monitor.
  • Save time: perform bulk actions such as managing access across multiple networks or for multiple admins in a single flow.
  • Efficient data navigation and retrieval through search and filtering.
  • 1:1 SAML admin alignment for external authentication of users and SSO.
  • Optimize workflows: enable seamless and more focused task completion with tailored interfaces and intuitive tooltips that adapt to user permissions.

Getting started

image.png

  • Log in to your Meraki dashboard
  • From the left-hand navigation > Network-wide > Configure > Administration
  • OR navigate to Organization > Administrators
  • Then, toggle the “Try new version” link in the top right of the page

Availability

RBAC Foundations will be available in Early Access in an updated version of the dashboard Administrators page globally beginning December 17, 2024.

Stay tuned as we continually innovate and add more functionality to enhance role and admin management.

P.S. share your feedback with @Katia1 and the team! Let us know what’s useful and any features you’d like to see below or from the “Give your feedback” button in the bottom right of any dashboard page.

Miriam Kung
Cisco Meraki Product Marketing
12 Replies 12

Raphael_L
Meraki Community All-Star
Meraki Community All-Star

Hi ,

This is a great step forward , but I just wish we could give "Allow Packet capture" to R/O users 😞

image.png

thank you for your feedback, Raphael! We have an extensive roadmap and this is making a good candidate for future consideration. Could you please describe your use case? Feel free to DM me or we can set up a quick call to discuss this

Raphael_L
Meraki Community All-Star
Meraki Community All-Star

DM sent 🙂

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

Packet Capture would be another good tool for the "Troubleshooter" role that I mentioned.

mloraditch
Meraki Community All-Star
Meraki Community All-Star

Am I blind, or is there no way to edit an existing user? Delete and readd?

If you found this post helpful, please give it a thumbs up. If my answer solves your problem please click Accept as Solution so others can benefit from it.

Raphael_L
Meraki Community All-Star
Meraki Community All-Star

Samething for SAML roles. That's odd

Network Sean
Level 3
Level 3

YES!!! I needed more control over my admins.

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

I would like to be able to give some observers the ability to use the tools page on the device page. This is for helpdesks that you don't want to be able to make changes but still be able to do basic troubleshooting.

For example, being able to give them the ability to reboot a Meraki device, blink LEDs, etc.

This is the page I want to be able to give some read-only users access to use:

image.png

taking a note! Thank you Philip!

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

Maybe a new category here (under "Client Monitor") called "Troubleshooter".

image.png

Boston3
Community Member

I would like to be able to do the following

Give Admins the ability to access my switches but not my firewalls
Give Admins the ability to access my firewalls but not my switches

Add more than one role to a user
Give users the ability to whitelist a device on a specific SSID

nick-gardner
Community Member

Is there a way to allow template access to users? Where a user can add/remove or move a network between templates?