cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
414
Views
0
Helpful
1
Replies

ISE 2.4 : administrator permission data access : Cannot see IDENTITY

gillessapene
Level 1
Level 1

I use ISE 2.4 as a Tacacs Server.

I want to give an administrator privilege to a team in such a way that they can do anything but not update the administrators  accounts ( ex: change an admin user from one admin group to another admin group).

So I have created an new Admin group. 

I have created an admin authorization menu (show/hide)

I have created an admin data menu.(full access/ ReadOnly Access / No Access)

I have created a policy to link the admin group with the authorization menu and with the data access menu.

 

This works fine with everything but the identities. These above admin accounts can work with the "User Identity groups" but they cannot see or create an "Identity"(tacacs account).

I don't see anyoption in the data access privilege panel.  There is only the "User Identity Groups" option.access.JPG

1 Accepted Solution

Accepted Solutions

Surendra
Cisco Employee
Cisco Employee

Here is how you can give access to be able to only create identities :

 

Screenshot 2019-07-17 at 9.20.14 PM.png

 

Screenshot 2019-07-17 at 9.21.21 PM.png

 

This basically lets a user to create/delete/modify a user part of Employee identity group only.

View solution in original post

1 Reply 1

Surendra
Cisco Employee
Cisco Employee

Here is how you can give access to be able to only create identities :

 

Screenshot 2019-07-17 at 9.20.14 PM.png

 

Screenshot 2019-07-17 at 9.21.21 PM.png

 

This basically lets a user to create/delete/modify a user part of Employee identity group only.