cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
985
Views
5
Helpful
7
Replies

ISE external admin Data access

joeharb
Level 5
Level 5

I have created a new Policy for admin access.  It references a Group in AD, I am able to login with out issues and have access to all menu's but I don't have access to some of the Data.  For example I don't see any of the Endpoint or User Identity Groups.  I have configured the policy for both Super Admin Menu and Data access, see image.

 

What am I missing?

 

Thanks,

 

Joe

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

CSCvd28829 is addressed in ISE 2.2 Patch 2 or above and ISE 2.3 FCS. Joe could run into it, if his setup just upgraded to ISE 2.2 and not yet patched to the latest.

View solution in original post

7 Replies 7

hslai
Cisco Employee
Cisco Employee

You may map AD groups to the built-in admin groups (see the attached screenshot), instead of creating new ones, although what you configured should have worked, too. Please engage Cisco TAC to troubleshoot.

Screen Shot 2018-12-15 at 7.08.05 PM.png

I have seen similar problem in version 2.3. It seemed to be a bug because all required permissions were allowed,

hslai
Cisco Employee
Cisco Employee

If an admin user matched to multiple ISE admin groups, then it could be either CSCvd20214 or CSCvk10156.

BigK
Level 1
Level 1

@joeharb

 

definitely a bug. See below 

 

CSCvd28829

hslai
Cisco Employee
Cisco Employee

CSCvd28829 is addressed in ISE 2.2 Patch 2 or above and ISE 2.3 FCS. Joe could run into it, if his setup just upgraded to ISE 2.2 and not yet patched to the latest.

This is a fresh install of 2.4. 

hslai
Cisco Employee
Cisco Employee

Please try what I gave in my first response to your post. If that not helping, open a Cisco TAC support case and troubleshoot further.