Location in GUI : Work Centers » Device Administration » Device Admin Policy Sets » XXX » Authorization Policy - Global Exceptions
Name Type Constraint Mandatory Default Value authorization_global_exception_rules List [authorization_global_exception_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d\_\-\. \(\)]+$ Yes state Choice enabled, disabled, monitorNo enabledcondition Class [condition]No profile String No command_sets List String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith, macContains, macEndsWith, macEquals, macIn, macNotContains, macNotEndsWith, macNotEquals, macNotIn, macNotStartsWith, macStartsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith, macContains, macEndsWith, macEquals, macIn, macNotContains, macNotEndsWith, macNotEquals, macNotIn, macNotStartsWith, macStartsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith, macContains, macEndsWith, macEquals, macIn, macNotContains, macNotEndsWith, macNotEquals, macNotIn, macNotStartsWith, macStartsWithNo attribute_value String No name String No
Example-1 Global Authorization Exception Rule for User2 Denying All Commands
This example defines a global authorization exception rule in the device administration policy for User2. When the condition matches User2 in the TACACS dictionary, the rule is enabled and applies the command set “DenyAllCommands,” effectively denying all commands for this user. This configuration enforces strict command restrictions globally for User2 across the network device administration environment.
authorization_global_exception_rules :
type : ConditionAttributes
Example-2 Global Authorization Exception Rule with Multiple Identity Group Conditions Using AND Operator
This example illustrates a global authorization exception rule in device administration that requires two identity group conditions to be met simultaneously using an AND operator. The rule applies when the user belongs to both the “GuestEndpoints” and “Employee” identity groups. When both conditions match, the rule is enabled and applies the “AllowShowCommands” command set, permitting only show commands for users who satisfy both identity group memberships.
authorization_global_exception_rules :
- type : ConditionAttributes
dictionary_name : IdentityGroup
attribute_value : GuestEndpoints
- type : ConditionAttributes
dictionary_name : IdentityGroup
attribute_value : Employee
Location in GUI : Work Centers » Device Administration » Device Admin Policy Sets » XXX » Authorization Policy - Global Exceptions
Name Type Constraint Mandatory Default Value authorization_global_exception_rules List [authorization_global_exception_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d_\-\. ]+$ Yes state Choice enabled, disabled, monitorNo enabledcondition Class [condition]No profile String No command_sets List String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No
authorization_global_exception_rules :
type : ConditionAttributes
Location in GUI : Work Centers » Device Administration » Device Admin Policy Sets » XXX » Authorization Policy - Global Exceptions
Name Type Constraint Mandatory Default Value authorization_global_exception_rules List [authorization_global_exception_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d_\-\. ]+$ Yes state Choice enabled, disabled, monitorNo enabledcondition Class [condition]No profile String No command_sets List String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No
authorization_global_exception_rules :
type : ConditionAttributes
Location in GUI : Work Centers » Device Administration » Device Admin Policy Sets » XXX » Authorization Policy - Global Exceptions
Name Type Constraint Mandatory Default Value authorization_global_exception_rules List [authorization_global_exception_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d_\-\. ]+$ Yes state Choice enabled, disabled, monitorNo enabledcondition Class [condition]No profile String No command_sets List String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No
authorization_global_exception_rules :
type : ConditionAttributes