- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-06-2020 05:22 AM
Hello,
I have been trying to find out an easy way to create multiple Local admin user who can authenticate with external identity source like RSA .
I tried to use ERS API request but it didn't give me the required output ,i could able to created internal users with the API request but not admin users.
Is it possible to create create multiple Local admin user who can authenticate with external identity source in ISE via ERS API request?
If not can any one suggest me any possible solution for this.
Thanks
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-06-2020 05:50 AM

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2020 04:52 PM
It sounds like what you are trying to do is create bulk 'shadow' admin user accounts to use in conjunction with MFA (RSA) authentication/authorisation for the ISE GUI. Since ISE still performs local Authorisation when it comes to admin flows using MFA, these admin accounts (with no password) must be created and mapped to the proper RBAC group in ISE.
There is currently no mechanism for using the API or an Import option for creating admin users. These 'shadow' accounts will have to be individually created in the GUI.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-06-2020 05:50 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-07-2020 02:25 AM
Thanks!
Is there any other way to create multiple admin user easily .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-09-2020 08:43 AM
Create Admin Group: Administration->System->Admin Access->Administrators->Admin Groups
Map to RBAC Policy: Administrations->System->Admin Access->Authorization->Policy
Good luck & HTH!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2020 04:52 PM
It sounds like what you are trying to do is create bulk 'shadow' admin user accounts to use in conjunction with MFA (RSA) authentication/authorisation for the ISE GUI. Since ISE still performs local Authorisation when it comes to admin flows using MFA, these admin accounts (with no password) must be created and mapped to the proper RBAC group in ISE.
There is currently no mechanism for using the API or an Import option for creating admin users. These 'shadow' accounts will have to be individually created in the GUI.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2020 11:31 PM
unfortunately, there is no API for us to create bulk RBAC admins.. At this point of time, there is no easy way for rbac admins..
