cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
504
Views
5
Helpful
2
Replies

API with flexible right ISE 2.4 Patch 9 - Only Read or Full admin - Need more granular admin rights

pwittmer
Cisco Employee
Cisco Employee

A customer is asking for granular support on API for allowing to do not only read only or full admin but more granularity per command ? customer is using version 2.4 patch 9

 

1 Accepted Solution

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni
Please submit a feature request, granular ERS/API access does not exist today other than the RW or RO roles Mike covered.

External
http://cs.co/ise-feedback

Internal
http://cs.co/ise-pm

View solution in original post

2 Replies 2

Mike.Cifelli
VIP Alumni
VIP Alumni
Are you able to provide a more detailed example for their expectations? If I am understanding correctly it sounds like the customer wants to limit the ability for certain users to run different types of crud operations to ISE. What are you using to run them through? When you enable ers APIs in ISE it allows read/write on PAN and read only on other nodes (PSNs). My suggestion would be to create separate users. One with ers admin for read/write folks. One with ers operator for read only. Good luck & HTH!

Damien Miller
VIP Alumni
VIP Alumni
Please submit a feature request, granular ERS/API access does not exist today other than the RW or RO roles Mike covered.

External
http://cs.co/ise-feedback

Internal
http://cs.co/ise-pm