Home > Enterprise Mobility Management > Other Topics > Limited Access Roles

Limited Access Roles

A Limited Access Role is a type of Network Administrator that is restricted by both the scope of devices they can manage, as well as features they can access. This allows the creation of an administrator who only has access to specific devices in your Systems Manager network.

This article outlines how to create a Limited Access Role and apply it to a user, as well as describes options available to these users.

Creating and Assigning a Limited Access Role

The following instructions outline how to create a limited access role, and assign it to specific device scopes by tag:

  1. In Dashboard, navigate to Systems manager > Configure > General for a standalone SM network, or Network-wide > Configure > Alerts & administration in a combined network.

  2. Navigate to the Network Administration > Limited Access Roles section.

  3. Select Add a New Limited Access Role.

  4. Name the new Limited Access Role, and select which device tags this role should have the ability to manage. These can be static or dynamic tags, including schedules and geofencing:

     

  5. Click Save changes to save the role.

  6. Under the Network Admins section, select or create a user, and assign the newly-created Limited Access Role from the drop-down Privilege menu:
     

  7. Click Save changes.

Limited Access Role Functionality

When a Limited Access Admin logs into Dashboard, their view is restricted in terms of both devices and functionality. This accomplishes two goals: It simplifies the menu for users to quickly and easily access the tools they need, and protects other managed devices from unwanted changes.

Client List View and Commands

Users with a Limited Access Role have access to the clients list (Systems Manager > Monitor > Clients). They can view devices within their scoped role, and only have access to the “Command” menu. This allows them to perform common functions, like send notifications or lock devices into single app mode. Multiple devices can be selected at once, allowing these commands to be executed en masse:

Client Details

Users with a Limited Access Role can access the client details page by navigating to Systems Manager > Monitor > Clients, and clicking on a specific client device. This allows them to access MDM commands or Live tools depending on the device type chosen. From here, users can clear passcodes, reboot devices, and (for iOS devices) initiate AirPlay for media sharing:

Profiles and Settings

Users with a Limited Access Role can modify profiles and settings under Systems Manager > MDM > Profiles. Here, users can make changes to restrictions like disabling the camera, or managing content on the device via the backpack feature. Any profiles they manage are automatically scoped to devices tagged to them, including any geofence or schedule tags:

Please note that users with a Limited Access Role may only modify existing profiles, they cannot create or delete profiles.

 
You must to post a comment.
Last modified
12:12, 2 Dec 2016

Tags

This page has no custom tags.

Classifications

This page has no classifications.

Article ID

ID: 4311

Contact Support

Most questions can be answered by reviewing our documentation, but if you need more help, Cisco Meraki Support is ready to work with you.

Open a Case