This guide documents how to create a local Cisco ISE user and grant it read-only access to the Admin Portal. In this lab, the account ise-user1 is first created as a Network Access User, then added as an administrator and used to verify the read-only role.
This procedure covers Admin Portal access. It does not configure authentication for endpoints or network devices.
Lab environment#
| Parameter | Value |
|---|---|
| Platform | Cisco ISE VM |
| Version | Cisco ISE 3.5 Patch 0 |
| Internal user | ise-user1 |
| Administrator access | Read-only |
1. Create an internal Network Access User#
In the Admin Portal, go to Administration > Identity Management > Identities > Users, then click Add.
Create the account with the following lab settings:
- Username:
ise-user1 - Status: Enabled
- Password Type: Internal Users
- Login Password: Set and confirm a password. The password is not included in this article.
The capture shows With Expiration selected and a 60-day password lifetime. This value reflects the password policy configured in the lab; use the policy appropriate for your environment.

Figure 1. The Network Access User form shows ise-user1 enabled with the Internal Users password type.
Click Submit to create the user in the ISE internal database. Cisco documents this workflow under Administration > Identity Management > Identities > Users. Cisco ISE Administrator Guide 3.5 — Internal user operations
2. Add the user to Admin Users#
Go to Administration > System > Admin Access > Administrators > Admin Users. Click Add > Select from Network Access Users, then select ise-user1.

Figure 2. Select the existing Network Access User from the Admin Users page.
Cisco ISE supports selecting an existing Network Access User when creating an administrator. The selected account must also be assigned administrator access. Cisco ISE Administrator Guide 3.5 — Create a new administrator
3. Assign read-only administrator access#
On the Admin User page, leave the account Enabled and keep External unchecked so the account uses the local ISE identity store. Select Read Only, then save the administrator.

Figure 3. The Admin User form shows the local account enabled with Read Only selected.
After saving, verify that ise-user1 appears in the Admin Users list and is assigned to Read Only Admin.

Figure 4. The administrator list shows ise-user1 with the Read Only Admin group.
Administrator groups determine which menus and operations are available in the Admin Portal. Assign only the access required for the task. Cisco ISE Administrator Guide 3.5 — Administrator groups and RBAC
4. Sign in with the internal user#
Open the Admin Portal using the ISE management URL. In this lab, the URL is:
1https://198.18.134.121/admin/Sign in with the ise-user1 username and the password set for that account. If the login page asks for an identity source, choose Internal.

Figure 5. The dashboard identifies the signed-in account as ise-user1 and displays Read-Only access.
Cisco documents the Admin Portal URL format as https://<IP address or host name>/admin/. Cisco ISE Installation Guide 3.5 — Log in to the web-based interface
5. Verify read-only access#
While signed in as ise-user1, open Policy > Policy Sets. The lab capture shows the Read-Only status while this page is open.

Figure 6. The Policy Sets page displays the Read-Only status for the current session.
Conclusion#
The ise-user1 account was created as an internal Network Access User, added to Admin Users, and assigned read-only Admin Portal access. The account then signed in successfully, and the Policy Sets page displayed the Read-Only status. Authenticating endpoints or network devices with internal users requires separate network access policy configuration.