- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Restricting access to cameras for Network Admins
We have a number of network admin users that have full organization access, and some that have Organization Read Only Access.
I have been asked to look into preventing some of these users from being able to see the MV Cameras (without moving the the cameras out into a separate network).
This is to comply with GDPR.
Can anyone advise on how I achieve this. We use SAML (SSO via Azure).
Thanks in advance.
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It might be worthwhile looking at third-party solutions like Boundless Digital. They allow much more granular access to the Meraki Dashboard.
https://www.boundlessdigital.com/network-management/meraki-automation/role-based-access-control/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe yes.
Restricting Access to Cameras - Cisco Meraki Documentation
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure it's possible if these are combined networks. If an admin has network level access or org level access that applies to all nodes in the network. So there's no way to enforce a deny for cameras only unless I'm overlooking something in my evaluation of dashboard or my testing.
I think you'd need to break the cameras out into there own networks to achieve this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Going sideways - does the access auditing not resolve the core issue - of identifying you has accessed what private information? Sure they can still get to it - but it creates an audit trail of them doing it.
https://documentation.meraki.com/MV/Processing_Video/Video_Access_Log
ps. For one company I ended up creating a new org just for the cameras to resolve access concerns.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks @PhilipDAth & @Ryan_Miles
Breaking out the cameras into a separate network, or even organization seems a bizarre approach to address what in my opinion is a fundamental issue with access rights not being granular enough.
I wouldn't have thought it unreasonable to be able to prevent some network admins from being able to access video. If say 2 roles were passed across via SAML, the 1st being Full access to network XYZ and the 2nd being a camera/sensor role that denies access to footage on cameras in network XYZ, then the result should be the user being able to access all the network settings for the camera, but just not able to see the image itself (dashboard and vision Portal).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just tested again and perhaps it is possible. Although it would be nice if the UI was better/different.
- I created a new role in my IDP called Network_Admins;No_Video
- In the Meraki dashboard I created a SAML role for Network_Admins with full access to a network
- I created a Camera role with no camera permissions to anything
Logging in allows me access to all parts of the network except cameras. I can see the list of cameras, but clicking on them results in a View failed to load error. This is where I wish it would instead say camera access denied rather than looking like a broken webpage.
And this all only makes sense I suppose if the SAML admin is a network admin. Because if they have org level permissions they could simply edit the no video camera role giving themselves access.
Again I would recommend testing this all out and seeing if the behavior is the same for you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It might be worthwhile looking at third-party solutions like Boundless Digital. They allow much more granular access to the Meraki Dashboard.
https://www.boundlessdigital.com/network-management/meraki-automation/role-based-access-control/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Philip, that looks like a great solution.
I will investigate pricing and look into a trial to confirm it will achieve what we need.
