This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
we are operation a ISE deployment for all of our sites araund the world. At the moment we are chanign our Guest Workflow to a Sponsor based deployment.
Originally it was planned that every user can sponsor guest accounts but the requirements chagened.
Now we have the the requirement that we have to controll it on a country basis.
We need for every country a Admin Sponsor group which can see all Accounts which are created in that Area. And the User should only see his Accounts.
When i create a new sponsor group on a country Basis everybody how is in the group can see all accounts. Is it possible to solve that problem?
Yes that is possible, but i want, that the Manager of a Region can see all Guest Accounts from that Region. But the Sponsors should only see there created Accounts.
Lets say, i have only one region, than its not a problem. But i have lets say 20 Regions.
Maybe you could try to create multiple standard sponsor groups, in which each user would be able to see only his own accounts. You would achieve this by creating and configuring multiple locations, and option Sponsor Can Manage: Only accounts sponsor has created.
You would then create manager sponsor group, which would be combination of local location, and option Sponsor Can Manage: Accounts created by members of this sponsor group. Main idea is to use combination of Location and "Sponsor Can Manage" options.
I never used this combination, but logically, it might work.
Leoni Wartung, Milos has the right idea. Below is an example:
User Identity Groups
Network Access Users
For each region, sponsors will be in the sponsors group of that region but managers will be in both the sponsors and the managers groups of the region.