Managing Admins

Jwiley78
Building a reputation

Managing Admins

Is there a good way to manage Admins for multiple Organizations?  It gets a little time consuming to go through multiple organizations every time we hire a new engineer or one decides to leave the company.

7 Replies 7
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Jwiley78 ,

 

Not that I’m aware of for multiple orgs.  The organisation admins have full rights for all networks within the organisation.  Whereas a network administrator only has rights to the particular network it has been assigned.

 

https://documentation.meraki.com/zGeneral_Administration/Managing_Dashboard_Access/Managing_Dashboar...

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
Jwiley78
Building a reputation

That's what I was afraid of.  Just have to do it the manual way to get it up to date and then hopefully I can get everything up to date and then try to find a good strategy to keep it up to date after that.

 

DarrenOC
Kind of a big deal
Kind of a big deal

Could be way of automating via API?

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
PhilipDAth
Kind of a big deal
Kind of a big deal

You'll want to use SAML for this.

https://documentation.meraki.com/zGeneral_Administration/Managing_Dashboard_Access/Configuring_SAML_... 

 

Examples of SAML providers are the Duo Access Gateway and Azure AD (Azure AD is a horrible SAML gateway though ...).

Jwiley78
Building a reputation

I'll have to look into this one.  Do you know if you can us SAML and local users together or is one or the other?

 

PhilipDAth
Kind of a big deal
Kind of a big deal

You can use both at the same time.

 

Typically customers have local user accounts, and the MSP uses SAML.

BrothersTM
Getting noticed

@PhilipDAth is correct on SAML. That would be the easiest way. I just finished setting up some new SAML roles today using G Suite as the IDP. It worked quite well with the new SAML camera roles as well as traditional administrator access.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels