Cisco ISE Admin Access: Internal Users & Active Directory

ravell
4 min read

This guide documents how to create a local Cisco ISE user and grant it read-only access to the Admin Portal. In this lab, the account ise-user1 is first created as a Network Access User, then added as an administrator and used to verify the read-only role.

This procedure covers Admin Portal access. It does not configure authentication for endpoints or network devices.

Lab environment#

ParameterValue
PlatformCisco ISE VM
VersionCisco ISE 3.5 Patch 0
Internal userise-user1
Administrator accessRead-only

1. Create an internal Network Access User#

In the Admin Portal, go to Administration > Identity Management > Identities > Users, then click Add.

Create the account with the following lab settings:

  • Username: ise-user1
  • Status: Enabled
  • Password Type: Internal Users
  • Login Password: Set and confirm a password. The password is not included in this article.

The capture shows With Expiration selected and a 60-day password lifetime. This value reflects the password policy configured in the lab; use the policy appropriate for your environment.

Cisco ISE form for creating the enabled ise-user1 internal user
Cisco ISE form for creating the enabled ise-user1 internal user

Figure 1. The Network Access User form shows ise-user1 enabled with the Internal Users password type.

Click Submit to create the user in the ISE internal database. Cisco documents this workflow under Administration > Identity Management > Identities > Users. Cisco ISE Administrator Guide 3.5 — Internal user operations

2. Add the user to Admin Users#

Go to Administration > System > Admin Access > Administrators > Admin Users. Click Add > Select from Network Access Users, then select ise-user1.

Cisco ISE Admin Users menu with Select from Network Access Users open
Cisco ISE Admin Users menu with Select from Network Access Users open

Figure 2. Select the existing Network Access User from the Admin Users page.

Cisco ISE supports selecting an existing Network Access User when creating an administrator. The selected account must also be assigned administrator access. Cisco ISE Administrator Guide 3.5 — Create a new administrator

3. Assign read-only administrator access#

On the Admin User page, leave the account Enabled and keep External unchecked so the account uses the local ISE identity store. Select Read Only, then save the administrator.

Cisco ISE Admin User form with ise-user1 enabled and Read Only selected
Cisco ISE Admin User form with ise-user1 enabled and Read Only selected

Figure 3. The Admin User form shows the local account enabled with Read Only selected.

After saving, verify that ise-user1 appears in the Admin Users list and is assigned to Read Only Admin.

Cisco ISE Admin Users list showing ise-user1 in the Read Only Admin group
Cisco ISE Admin Users list showing ise-user1 in the Read Only Admin group

Figure 4. The administrator list shows ise-user1 with the Read Only Admin group.

Administrator groups determine which menus and operations are available in the Admin Portal. Assign only the access required for the task. Cisco ISE Administrator Guide 3.5 — Administrator groups and RBAC

4. Sign in with the internal user#

Open the Admin Portal using the ISE management URL. In this lab, the URL is:

Copy code to clipboard
Open code in new window
Disable hover highlighting
1https://198.18.134.121/admin/

Sign in with the ise-user1 username and the password set for that account. If the login page asks for an identity source, choose Internal.

Cisco ISE dashboard signed in as ise-user1 with Read-Only access
Cisco ISE dashboard signed in as ise-user1 with Read-Only access

Figure 5. The dashboard identifies the signed-in account as ise-user1 and displays Read-Only access.

Cisco documents the Admin Portal URL format as https://<IP address or host name>/admin/. Cisco ISE Installation Guide 3.5 — Log in to the web-based interface

5. Verify read-only access#

While signed in as ise-user1, open Policy > Policy Sets. The lab capture shows the Read-Only status while this page is open.

Cisco ISE Policy Sets page displaying the Read-Only status
Cisco ISE Policy Sets page displaying the Read-Only status

Figure 6. The Policy Sets page displays the Read-Only status for the current session.

Conclusion#

The ise-user1 account was created as an internal Network Access User, added to Admin Users, and assigned read-only Admin Portal access. The account then signed in successfully, and the Policy Sets page displayed the Read-Only status. Authenticating endpoints or network devices with internal users requires separate network access policy configuration.

References#