cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
612
Views
0
Helpful
4
Replies

Restrict accessing specific data for ERS API access

masyamad
Cisco Employee
Cisco Employee

Hi dev team,

 

Now my customer is considering specific admin user can access only some specific network user group.

It could be achieved by admin authorization policy.  (Administration -> Authorization -> Policy).

It does work as expected, but when we tried to configure same user group via ERS API, we faced un-authorized error.  Do we need special configuration for restrict data area via ERS API access?

1 Accepted Solution

Accepted Solutions

Prerequisites for Using the External RESTful Services API Calls says,

  • You must have External RESTful Services Admin privileges.

 

View solution in original post

4 Replies 4

hslai
Cisco Employee
Cisco Employee

ERS API does not follow the same RBAC as those used in ISE admin web UI. I believe you need to discuss this requirement with our PM team and raise it as an enhancement.

> ERS API does not follow the same RBAC as those used in ISE admin web UI.
I see. Thanks. Actually I & my customer didn't notice the implementation during design session for admin access.
I hope the behavior is documented on admin access section on ISE guides.

- ISE guides: Admin Access Policies
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0101.html

Prerequisites for Using the External RESTful Services API Calls says,

  • You must have External RESTful Services Admin privileges.

 

Thanks. But it's different URL. I hope Admin Access Policies also has similar description.
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: