12-15-2019 07:22 AM
Hello,
I have questions regarding Admin Access, if the Admin user that i created is based on External AD.
and If i tick the read only or apply an rbac-read only policy.
It is not affecting the admin account. Once i Login, i can still write on ISE.
but if i create an internal admin account on ISE. Read only and RBAC policy is working.
Have you encountered this scenario? How to fix this.
Thanks in advance
Solved! Go to Solution.
 
					
				
		
12-16-2019 04:45 PM
12-15-2019 02:15 PM
Is the AD user only mapped to a single group leveraged in the admin access policy or multiple?
I could see ise using first match rather than least privilege for access but I have not tested it.
What ise admin groups are you trying to leverage right now?
12-15-2019 11:14 PM
 
					
				
		
12-16-2019 04:45 PM
 
					
				
				
			
		
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide