This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
I have five different locations for one of the client.
Each location is having 2 to 3 network device.
I want to give local site administrator the privilege to change their local device config only.
Also, one superadmin should be able to change the config on all site devices.
Is it possible to do it under one policy in Device admin policy set?
Solved! Go to Solution.
I configured a Device type which contained the main group for that Client.
Also configured device groups for different sites. e.g. 5 groups for 5 sites.
Then I configured a policy in policy sets so that it will match All devices for that client.
After that, I configured authorization policy and in the condition, I used logical AND of site_1 and internal user.
This did the trick for me.