Admin permissions to specific devices in an org

LeAnts
Here to help

Admin permissions to specific devices in an org

Hi,

can admin roles be set to allow engineers only access to specific devices within an org?

we have a MX and some meraki switches under the same network.. i need to give user1 admin rights to the MX only and no access to the switches.

how can I achieve this?

 

thanks

 

7 Replies 7
alemabrahao
Kind of a big deal
Kind of a big deal

Yes, take a look at this.

 

https://documentation.meraki.com/General_Administration/Managing_Dashboard_Access/Managing_Dashboard...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Thanks.. but this doc doesn't really answer my question.. it tells me i can have an org admin or a network admin..

org admin has access over the entire org whereas network admin will have access to whatever is in that network.

does not seem to add limitations to specific devices within a network..

or am i ready it wrong?

 

alemabrahao
Kind of a big deal
Kind of a big deal

No, you can only limit an administrator to a specific network at most, as you noted in the documentation.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
alemabrahao
Kind of a big deal
Kind of a big deal

Sorry, the most you can do is limit within the network according to the TAG you have defined on the device.

 

alemabrahao_1-1707482113811.png

 

Just note that "These privileges allow limited access to the entire network and configuration of devices that match the selected scope and tags."

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

For this function, you must have a System Manager license.

I would like to see more granular privilege management in the future.

For example, a read-only or monitor-only privilege for a specific user only for MX and Wireless, but not for switching and others.

For example a read-only or full privilege for MX and no access to all others menus.

PhilipDAth
Kind of a big deal
Kind of a big deal

Systems Manager wont achieve ths.

PhilipDAth
Kind of a big deal
Kind of a big deal

You can't do this ntively.  There are third-party solutions like Boundless Digital that offer granular role-based access control.

https://www.boundlessdigital.com/network-management/meraki-automation/role-based-access-control/ 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels