Location in GUI : Work Centers » Device Administration » Device Admin Policy Sets » XXX » Authorization Policy
Name Type Constraint Mandatory Default Value authorization_rules List [authorization_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d\_\-\. \(\)]+$ Yes state Choice enabled, disabled, monitorNo enabledcondition Class [condition]No profile String No command_sets List String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith, macContains, macEndsWith, macEquals, macIn, macNotContains, macNotEndsWith, macNotEquals, macNotIn, macNotStartsWith, macStartsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith, macContains, macEndsWith, macEquals, macIn, macNotContains, macNotEndsWith, macNotEquals, macNotIn, macNotStartsWith, macStartsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith, macContains, macEndsWith, macEquals, macIn, macNotContains, macNotEndsWith, macNotEquals, macNotIn, macNotStartsWith, macStartsWithNo attribute_value String No name String No
Example-1 Authorization Rule Allowing User1 with Show Command Access
This example defines an authorization rule within the Global Policy of device administration that specifically allows a user named “User1” to access the network device. The rule is enabled and matches when the TACACS user attribute equals “User1.” Upon matching, the user is assigned the “Default Shell Profile” and granted the command set “AllowShowCommands,” which permits execution of show commands. This configuration is useful for granting limited read-only access to specific users in the device administration policy framework.
type : ConditionAttributes
profile : Default Shell Profile
Example-2 Device Administration Authorization Rule with OR Condition for Identity Groups
This example demonstrates how an authorization rule in Cisco ISE device administration uses an OR operator to evaluate multiple identity group conditions. The authorization is granted if the user belongs to either the “Employee” or “RegisteredDevices” identity groups. When the condition matches, the user receives the “Default Shell Profile” and is allowed to execute show commands. This setup enables the policy to authorize access flexibly by satisfying any one of the specified identity group conditions, rather than requiring all conditions to be met.
- name : AuthorizationGroup
- type : ConditionAttributes
dictionary_name : IdentityGroup
attribute_value : Employee
- type : ConditionAttributes
dictionary_name : IdentityGroup
attribute_value : RegisteredDevices
profile : Default Shell Profile
Location in GUI : Work Centers » Device Administration » Device Admin Policy Sets » XXX » Authorization Policy
Name Type Constraint Mandatory Default Value authorization_rules List [authorization_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d_\-\. ]+$ Yes state Choice enabled, disabled, monitorNo enabledcondition Class [condition]No profile String No command_sets List String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No
type : ConditionAttributes
profile : Default Shell Profile
Location in GUI : Work Centers » Device Administration » Device Admin Policy Sets » XXX » Authorization Policy
Name Type Constraint Mandatory Default Value authorization_rules List [authorization_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d_\-\. ]+$ Yes state Choice enabled, disabled, monitorNo enabledcondition Class [condition]No profile String No command_sets List String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No
type : ConditionAttributes
profile : Default Shell Profile
Location in GUI : Work Centers » Device Administration » Device Admin Policy Sets » XXX » Authorization Policy
Name Type Constraint Mandatory Default Value authorization_rules List [authorization_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d_\-\. ]+$ Yes state Choice enabled, disabled, monitorNo enabledcondition Class [condition]No profile String No command_sets List String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No
type : ConditionAttributes
profile : Default Shell Profile