- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-06-2024 09:50 AM - edited 01-06-2024 09:51 AM
Hi all;
One of the options for configuring the Certificate Provisioning Portal is to specify who can access it. Look at the following figure:
As you can see above, it mentions that "User account with Super Admin privilege or ERS Admin privilege will have access to the portal". based on my understanding, users in the mentioned groups can access this portal without being explicitly specified in the "Choices" section. Right?
Thanks
Solved! Go to Solution.
- Labels:
-
BYOD
-
Identity Services Engine (ISE)
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-06-2024 12:07 PM
Hello @rezaalikhani
Nope - if you leave the Chosen column empty, then nobody has access to the Cert Prov Portal. The text comment you're referring to, is giving a hint about the permissions required for such a user in one of the Groups in the left-hand column. But I agree - it's a confusing sentence.
The default 'admin' ISE user account is an Admin Account. The cert prov portal (let's call it CPP) requires an ISE Network Access User Account (not an ISE Admin Account) or an external AD group.
If you want to use ISE Internal Network Access User Accounts, then make those individual users ISE Admins as well. You can do that in simple steps:
- Create the Network Access User account - Administration > Identity Management > Users (if not already done)
- Ensure the user account is in a named User Group (e.g. Employees, or Staff)
- Navigate to Administration > System >Admin Access > Administrators > Admin Users
- Click the "+" Add Icon and choose "Select from Network Access Users"
- Select the User and then provide the Super Admin / ERS Admin priv level

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-06-2024 12:07 PM
Hello @rezaalikhani
Nope - if you leave the Chosen column empty, then nobody has access to the Cert Prov Portal. The text comment you're referring to, is giving a hint about the permissions required for such a user in one of the Groups in the left-hand column. But I agree - it's a confusing sentence.
The default 'admin' ISE user account is an Admin Account. The cert prov portal (let's call it CPP) requires an ISE Network Access User Account (not an ISE Admin Account) or an external AD group.
If you want to use ISE Internal Network Access User Accounts, then make those individual users ISE Admins as well. You can do that in simple steps:
- Create the Network Access User account - Administration > Identity Management > Users (if not already done)
- Ensure the user account is in a named User Group (e.g. Employees, or Staff)
- Navigate to Administration > System >Admin Access > Administrators > Admin Users
- Click the "+" Add Icon and choose "Select from Network Access Users"
- Select the User and then provide the Super Admin / ERS Admin priv level
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-06-2024 10:05 PM
Thanks for your reply; as always, very insightful.
