02-23-2017 01:33 PM - edited 03-11-2019 12:29 AM
Hello
I am trying to find a way to create a read-only access policy for users in ISE so when read-only admin access the ISE, it has privileges to see all policies, policy results but with no option to alter it. Reading thru Cisco doc I was unable to find the way to do this. According to Cisco doc (noted bellow) this cannot be done. I tested on different access level for menu and data but no luck preventing a change on data that admin user has rights.
Was anyone experienced the same requirements and is there a solution to create a real, true read-only access to ISE menu and data?
Appreciate feedback..
......
Regardless of the level of access, any administrator account can modify or delete objects for which it has permission, on any page that the administrator can access.
.....
Solved! Go to Solution.
02-23-2017 05:50 PM
Hi
You're right this isn't possible. I haven't checked with Cisco ISE 2.2 yet but based on release note there is nothing like that announced.
There was a bug enhancement that's still opened and no"fix" have been provided.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCur75681/?referring_site=bugquickviewredir
Sorry for that.
Thanks
PS: Please don't forget to rate and mark as correct answer if this answered your question
02-23-2017 05:50 PM
Hi
You're right this isn't possible. I haven't checked with Cisco ISE 2.2 yet but based on release note there is nothing like that announced.
There was a bug enhancement that's still opened and no"fix" have been provided.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCur75681/?referring_site=bugquickviewredir
Sorry for that.
Thanks
PS: Please don't forget to rate and mark as correct answer if this answered your question
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide