Using SAML to Grant Camera-Only Access in Combined Networks

Solved
HaydenSeng
Conversationalist

Using SAML to Grant Camera-Only Access in Combined Networks

Hi all,

 

We’re currently using SAML SSO with Azure AD across our Meraki environment. We have IT staff at each site who manage switching and wireless, and we’ve recently deployed Meraki cameras at a number of locations.

 

To keep things clean, we’ve created a separate CCTV network that includes only the cameras and sensors. We've successfully configured SAML group access to this CCTV network with the Camera and Sensor and Vision roles for our leadership team to view footage.

 

However, for some sites, we would like to keep the cameras within the main (combined) network, which also includes switching and wireless. The challenge is that Camera and Sensor roles are Meraki-local and can’t be assigned via SAML, and to view cameras in the main network, the only SAML-based option is to give read-only access to the entire network — which exposes switch and wireless config we don’t want them to see.

 

Is there a way to:

  • Allow SAML users to view cameras only (Vision role) within a combined network?
  • Assign camera/sensor roles via SAML or SAML assertion claims?
  • Implement network tags or role-based filters in SAML that apply only to the camera portion of a combined network?

 

We’ve reviewed the “Camera and Sensor Roles” documentation and tried adding those to the SAML token, but it seems to only work in camera-only networks.

 

Appreciate any advice or experience others have had with this - especially if there are updates on Meraki’s roadmap for this kind of granular role mapping in combined networks.

 

Thanks!

1 Accepted Solution
Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

7 Replies 7
alemabrahao
Kind of a big deal
Kind of a big deal

Camera and Sensor roles cannot be assigned via SAML in combined networks, only in camera-only networks.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

Camera & Sensor SAML roles can absolutely work with combined networks. See my slide deck on the topic.

 

https://docs.google.com/presentation/d/1zvDAW3on_nzV61QvPpzBkPqzE0coa7h1MP0k_xiHFwo/edit?usp=sharing

alemabrahao
Kind of a big deal
Kind of a big deal

It would be good to put this information in official documentation, not in a document that only you have access to.

 

Please 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

My slide deck is accessible to anyone.

 

The standard documentation is here https://documentation.meraki.com/MV/Advanced_Configuration/Restricting_Access_to_Cameras#Role-based_...

 

 

alemabrahao
Kind of a big deal
Kind of a big deal

Thanks for sharing the official documents.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
HaydenSeng
Conversationalist

Hi Ryan,

 

I can confirm that this is working now with the camera and sensor role with SAML auth. 

 

Appreciate the help!

PhilipDAth
Kind of a big deal
Kind of a big deal

Here are the instructions for assigning role-based camera access via SAML.

https://documentation.meraki.com/MV/Advanced_Configuration/Restricting_Access_to_Cameras#Role-based_...

 

Get notified when there are additional replies to this discussion.