Cisco.com MFA Mandatory on 4/06 - Including Meraki Dashboard?

Solved
rjgSICT
New here

Cisco.com MFA Mandatory on 4/06 - Including Meraki Dashboard?

Hi all, I work for an MSP and I was notified by our Director that MFA would soon be mandatory for all Cisco.com accounts. My first question is, does this requirement also include the Meraki Account portal, https://account.meraki.com/login/ ?

 

We're looking at setting up individual user profiles for accessing our client Meraki networks, but it's a bit unclear as to whether or not the Meraki portal has this functionality. We're currently working under the assumption that the account we use is possibly a "child" account to our "parent" account, which is why we don't see that option to create new users.

 

Does the Meraki Dashboard support creating users under an overall company "umbrella" account where all users can see the client networks, or permissions to those networks can be granularly provided to individual users?

 

I'm relatively new to the world of Meraki, so I apologize if my questions don't make a lot of sense. Please let me know if further information is needed. Thank you!

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

No, each person should have their own individual account, and you grant the necessary permissions according to what they need to access.

 

https://documentation.meraki.com/Platform_Management/Dashboard_Administration/Operate_and_Maintain/M...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

7 Replies 7
alemabrahao
Kind of a big deal
Kind of a big deal

Cisco.com accounts used for TAC cases, downloads, partner portals, etc, now enforce MFA for partners. This applies to logging in at id.cisco.com and related Cisco services.
Cisco documentation confirms that MFA is handled within the Cisco.com identity profile itself and supports Duo/Google Authenticator.
Meraki Dashboard accounts are separate identities unless you specifically configure one of these:

Cisco SecureX Sign‑On uses Cisco identity
SAML SSO using your own IdP

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
GIdenJoe
Kind of a big deal
Kind of a big deal

At this moment Meraki dashboard accounts are completely separate from cisco.com accounts.  So I have to assume the announcement will not apply to dashboard users.

 

Dashboard admins can however enable MFA once logged in and navigated to their profile (top right user icon).

rjgSICT
New here

Hi alemabrahao and GIdenJoe ! Thank you for your replies. So it seems like, under most circumstances, the Meraki Dashboard accounts are completely separate from the Cisco.com accounts. 

 

So my other question is about the Meraki Dashboard accounts specifically; we are wanting to pursue the creation of individual Meraki accounts for our engineers that are created within a "parent" account. So these accounts would be "children" accounts under that "parent". Is that possible with Meraki Dashboard accounts? I looked around in our account but I've not seen this functionality, but I wanted to make sure I wasn't missing something.

 

Thank you all very much for your help, I appreciate it!

alemabrahao
Kind of a big deal
Kind of a big deal

No, each person should have their own individual account, and you grant the necessary permissions according to what they need to access.

 

https://documentation.meraki.com/Platform_Management/Dashboard_Administration/Operate_and_Maintain/M...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
rjgSICT
New here

Hi alemabrahao, thank you very much for your reply, and the link! Very helpful. I think that answers all of my questions. I will mark your reply as accepted solution. Thank you again!

PhilipDAth
Kind of a big deal
Kind of a big deal

The Meraki portal *already* has mandatory MFA.

PhilipDAth
Kind of a big deal
Kind of a big deal

If you are an MSP, consider using SAML to log in to the Meraki portal.  Once fully deployed, you'll see a list of clients to access when you log in.

https://documentation.meraki.com/Platform_Management/Dashboard_Administration/Operate_and_Maintain/M...

 

Another easy solution is to use an Enterprise-style password manager that can store MFA and share credentials.  BitWarden is an example.

Get notified when there are additional replies to this discussion.