Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass administrator with custom privileges

This thread has been viewed 9 times
  • 1.  ClearPass administrator with custom privileges

    Posted Apr 26, 2013 08:06 AM

    Hi

     

    Would it be possible to create a ClearPass administrator with only read access to access tracker and read/write/delete permissions on the Endpoint Repository?

     

    First part with Access tracker is easy, but is it possible to create granular access under the Configuration section and only allow access to the Endpoint Repository and not anything else?

     

    Regards

    Jonas Erlund Hammarbäck



  • 2.  RE: ClearPass administrator with custom privileges
    Best Answer

    EMPLOYEE
    Posted Apr 26, 2013 08:46 AM
      |   view attached

    Go to Administration> Users and Privileges> Admin privileges and import the attached file.

     

    Create an admin user and Apply the imported privileges to the user.

     

    EDIT:  Somehow I cannot attach an XML file.  Let me try to get that fixed.  Okay, change the attached filename extention from .txt to .xml before importing.

     

     

    Attachment(s)



  • 3.  RE: ClearPass administrator with custom privileges

    Posted Apr 26, 2013 08:53 AM

    Thank you!

     

    Works greate.

     

    Regards

    Jonas



  • 4.  RE: ClearPass administrator with custom privileges

    Posted Jul 04, 2013 07:09 AM

    Hi,

     

    thats cool. Do you have an overview about the

     

     <AdminTask taskid="[VAR]">

     

    commands?

     

    I just want to allow the service desk to create local users. Would it be like that?

     

          <AdminTask taskid="con.id.lu">
            <AdminTaskAction type="RWD"/>
          </AdminTask>

     

    for CONfigure -> IDentity -> Local Users?

     

    Thx in advance.

     

    Regards,

    Dennis



  • 5.  RE: ClearPass administrator with custom privileges

    Posted Jul 04, 2013 07:32 AM

    Hi dbo

     

    The information you need is now available in ClearPass Policy Manager 6.1 User Guide under section Administration\Custom Admin Privileges beginning on page 236.

     

    Regards

    Jonas



  • 6.  RE: ClearPass administrator with custom privileges

    Posted Jul 04, 2013 07:38 AM

    Hi Jonas,

     

    Thx for your fast reply and help.

     

     

    I just searched the user guide version 6.0...

     

    Regards,

    Dennis



  • 7.  RE: ClearPass administrator with custom privileges

    Posted Jun 17, 2014 02:04 AM
      |   view attached

    Hi,

     

    I know this is an old topic but does anyone know why I get the error message in the attached screenshot when logging in using these custom admin privleges? Normal admin account is fine.

     

    ClearPass 6.3.1

     

    Cheers

     

    Chris

     

     



  • 8.  RE: ClearPass administrator with custom privileges

    EMPLOYEE
    Posted Jun 17, 2014 07:56 AM

    Did you create the XML file from scratch or export one of the pre-built roles and then change attributes?



  • 9.  RE: ClearPass administrator with custom privileges

    Posted Oct 24, 2014 07:44 PM

    @cjoseph

     

    Thanks for this post, it was a quick and easy way how to create a profile for just EndpointsDB access. This was tied into AD USers / Group, for ease of providing access without giving admin rights. This was used specifically for provisioning phones / RAP's that use MAC Auth. 

     

     



  • 10.  RE: ClearPass administrator with custom privileges

    Posted Aug 25, 2016 01:37 PM

    Ok, I know this is a very old thread, but it seemed to be the right place to ask the question. We want to create a custom profile for the helpdesk to see the live monitor for radius, but NOT for TACACS. I know that we can restrict the "Accounting" tab from them, but the TACACS requests still show up in the live view. Is there a way to restrict this?

     

    Thanks!



  • 11.  RE: ClearPass administrator with custom privileges

    Posted May 14, 2019 03:14 PM

    cjoseph, we are having the issue where we have created a custom admin account, but the custom admin account (who we need to create non admin accounts) is able to create "super admin" accounts. We only want the custom admin account to be able to create one account type.  Tried adjusting the view and privs but can't seem to figure it out.  Any thoughts?



  • 12.  RE: ClearPass administrator with custom privileges

    Posted Jun 17, 2014 08:02 AM
    I used cjoseph's one from the earlier post.


  • 13.  RE: ClearPass administrator with custom privileges

    Posted Jun 17, 2014 08:07 AM
    Might try and export one and edit it. Maybe a problem between different clearpass versions.


  • 14.  RE: ClearPass administrator with custom privileges

    EMPLOYEE
    Posted Jun 17, 2014 08:08 AM
    That would be my recommendation. It's always worked for me that way.


  • 15.  RE: ClearPass administrator with custom privileges

    EMPLOYEE
    Posted Jun 17, 2014 10:41 PM
    You need to be carful of the smarty quotes. "" some txt editors change the format and it will error out.


  • 16.  RE: ClearPass administrator with custom privileges

    Posted Aug 21, 2019 07:15 PM

    I want to restric a specific user to be the admin for a specific service only. Is this doable ?



  • 17.  RE: ClearPass administrator with custom privileges

    Posted Feb 05, 2018 04:20 PM

    I read this thread and I am looking to do this as well but looking for admin priviledges for only read/write of onboarded devices.  I want the role to be able to removed onboarded devices and users from ClearPass Onboard.

     

    Do you think you could help me out with this as well?

     

    Thank you in advance.

    David



  • 18.  RE: ClearPass administrator with custom privileges

    EMPLOYEE
    Posted Feb 05, 2018 04:52 PM

    In the operator profile, give the following privs:
    - Delete Certificate: Full
    - Manage Devices: Full
    - Revoke Certificate: Full
    - View Certificate: Read-Only

    Be sure there is no filter enabled.



  • 19.  RE: ClearPass administrator with custom privileges

    Posted Feb 05, 2018 06:11 PM

    Thanks Tim will try this out>>

     

    David