Managing Dashboard Administrators and Permissions (2024)

  1. Last updated
  2. Save as PDF

This article will cover the different permission levels within the dashboard and how to manage administrative users. These are the users who have access to log in to the dashboard and view/administer Cisco Meraki networks/devices. For information on how to manageusers with access to join a client VPN or wireless network, please review the article on Managing User Accounts using MerakiAuthentication.

Summary

There are two basic types of dashboard administrators: Organization and Network.

  • Organization administrators have complete access totheir organization and all its networks. This type of account is equivalent to a root or domain admin, so it is important to carefully maintain who has this level of control;see below for best practices regarding these accounts
  • Network administrators have access to individual networks and their devices. These users can have complete or limited control over their network configuration, and have the ability to view organization inventory and claim devices into networks they administer. They do not have access to most organization-level information, such as licensing information.

Most dashboard administratorswill fall into one of the two above categories.The remainder of thisarticle goes in-depth about the options and limitations associated with different admin types.

Learn more with this free online training courseon the Meraki Learning Hub:

Sign in with your Cisco SSO or create a free account to start training.

Organization Permission Types

None: User will not have organization-wide access. Use this option if you want the user to have network only permissions.

Read-only: User able to access mostaspects ofnetworkand organization-wide settings, but unable to make any changes.

Read-Only admins can perform switch port cycles and cable tests

Full: User has full administrative access to all networks and organization-wide settings. This is the highest level of access available.

Managing Dashboard Administrators and Permissions (1)

Note: Dashboard organizations should always haveat least two organization admins with full permissions. This is best practice in case one account is locked out or if access to that account's email address is lost.

Network Permission Types

Guest ambassador: User only able to see the list of Meraki authentication users, add users, update existing users, and authorize/deauthorize users on an SSID or client VPN. Ambassadors can also remove wireless users if they are an ambassador on all networks. The existence of network templates anywhere in a dashboard organization prevents guest ambassadors from deleting wireless users.

User will only be presented with user management portal only.

Managing Dashboard Administrators and Permissions (2)

This feature can used whenindividuals such as a receptionist or office manager may need more privileges to grant network access to a visitor without giving them full network access.

Monitor-only: User only able to view a subset of the Monitor section in the dashboard and no changes can be made.
Note:monitor-only adminscan view summary reportsbut not schedulereports via email in the dashboard.

Read-only: User able to access mostaspects of a network, including the Configure section, but no changes can be made.

Full: User has access to view all aspects of a network and make any changes to it.

Managing Dashboard Administrators and Permissions (3)

Mobile App Administrator Management

Administrator management is also available in the Meraki Mobile app(iOS) (Android). Using this tool, you can view, add, edit and delete Organization and Network administrators on the go,whenever most convenient.

Managing Dashboard Administrators and Permissions (4)Managing Dashboard Administrators and Permissions (5)Managing Dashboard Administrators and Permissions (6)Managing Dashboard Administrators and Permissions (7)

Note that some administration management features are not yet available in the mobile app, including:

  • SAML Admins
  • Camera-only admins
  • Unlocking accounts

Managing Organization Permissions

All permissions for a dashboard organization can be managed under Organization > Administrators, however, this page is only visible to users with full or read-only organization access. Changes on this page can only be made by users with full organization access.

Adding an Organization Admin

UnderOrganization > Administrators

  1. Click Add adminalong the right side of the page.
    Managing Dashboard Administrators and Permissions (8)
  2. Enter the admin'sName and theEmail they will use to log in.
  3. Choose a level of Organization Accessas defined in the Organization Permission Types sectionwithin this doc.
  4. Click Create admin.
    Managing Dashboard Administrators and Permissions (9)
  5. An email from noreply@meraki.com will be sent to the email address entered with a temporary password instructing the user how to log in.Managing Dashboard Administrators and Permissions (10)
  6. Click Save changes.

Note: To change the admin's Name/Email after creation, see Changing a Dashboard Account's Username/Email

Modifying/Removing Organization-Wide Access

UnderOrganization > Administrators

  1. Click the row for the admin.
    Managing Dashboard Administrators and Permissions (11)
  2. Change their Organization Access to "None,"or the desired privilege level.
    Managing Dashboard Administrators and Permissions (12)
  3. Click Update admin.
    Managing Dashboard Administrators and Permissions (13)
  4. Click Save changes.

Note: If an admin has no other network-specific access and is given "None" for organization access, they will be deleted from the list of administrators.

Deleting an Organization Admin

UnderOrganization > Administrators

  1. Click the checkbox next to the name of the admin.
    Managing Dashboard Administrators and Permissions (14)
  2. Click Delete.
    Managing Dashboard Administrators and Permissions (15)
  3. Click Save changes.

Policy and Best Practices for Organization Management

By policy, Cisco Meraki’s support team does not make dashboard configuration changes on behalf of the customer. Dashboard administratorsmust make their own configuration and accountchanges onthe Meraki dashboard. Just as CiscoMeraki will not make any configuration changes, they can not make any adjustments to organization or network permissions; all changes to the dashboard administration must be made by an existing org admin on that dashboard account. Please refer to section 2.3 of our End Customer Agreement for details.

This policy is designed to protect the owners of the network from malicious intent. As such, it is strongly recommended to follow these best practices when determining org administrationto ensure the security of your dashboard network:

  • Dashboard organizations should always have at least two organization admins

    • This is best practice in case one account is locked out or if access to that account's email address is lost

  • Be cautious in selecting an appropriate org admin, as the org admin has the highest level of control in the dashboard organization

    • The active owner of the CiscoMerakihardware and licensesshould beorg admins on the account

  • Ensure that the username/email address of the org admin is associated with a domain under your control

    • Helpswhen separating relationships with previous org adminsfor account recovery purposes

    • Allows control of the email alias of the org admin

  • Use two-factor authentication and store backup authentication keys in a safe place

    • For example,Google Authenticatorcan be used as a two-factor auth solution with the dashboard

  • Consultants should be granted limited access as needed

    • Most likely, for technical configuration changes, offering temporary access as a network admin is the best option

    • If the consultant requiresorg admin permissions, be sure to revoke all permissionsonce the necessary changes have been implemented; ideally, the hardware/license owner should be the only org admin

  • If the current org admin is leaving the company, it is strongly recommended to revoke and/or reassign their account permissions early in the off-boarding process

  • Treat a dashboardorganization administrator like a domain admin for Active Directoryor the primary contact for domain name registration;only the person in this role has the ability to promote other users to this role

Managing Network Permissions

Privileges granted at the organization level will apply to all networks in an organization, and can only be managed from the Organization > Administrators page. Permissions for specific networks can be managed in two locations. Under Organization > Administratorsor under Network-wide >Configure > Administration.

Adding a Network Admin

Under Organization > Administrators

  1. Click Add admin.
    Managing Dashboard Administrators and Permissions (16)
  2. Enter the admin'sNameandEmailthey will use to log in.
    Managing Dashboard Administrators and Permissions (17)

    Note: To change the admin's Name/Email after creation, see Changing a Dashboard Account's Username/Email

  3. (Optional) Choose a level ofOrganization Access, as defined in theOrganization Permission Types section within this doc.
    Managing Dashboard Administrators and Permissions (18)
  4. Click Add access privileges.
    Managing Dashboard Administrators and Permissions (19)
  5. Select the network to grant access to in the Target field.
    Managing Dashboard Administrators and Permissions (20)
  6. Select the level of privilege to provide under the Access field, as defined in the Network Permission Types section of this doc.
    Managing Dashboard Administrators and Permissions (21)
  7. Click Create admin.
    Managing Dashboard Administrators and Permissions (22)
  8. Click Save changes.
  9. An email will be sent to the address entered with a temporary password and log-in instructions for the user.

Under Network-wide > Configure > Administration

  1. Select a user in Add an existing user... or click Create new user.
    Managing Dashboard Administrators and Permissions (23)
  2. If using Create new user, enter the admin'sNameandEmailthey will use to log in.
  3. Click Create user.
    Managing Dashboard Administrators and Permissions (24)
  4. If a message indicates the user already exists, use the Add an existing user...field to search for the email address.
    Managing Dashboard Administrators and Permissions (25)
  5. Under Privileges for the new user, choose the level of network access to provide,as defined in theNetwork Permission Typessection within this doc.
    Managing Dashboard Administrators and Permissions (26)
  6. Click Save changes.

Modifying Network Access

Under Organization > Administrators

  1. Click the row for the admin.
    Managing Dashboard Administrators and Permissions (27)
  2. In the row for the Target network, change the Access to the desired level.
    Managing Dashboard Administrators and Permissions (28)
  3. Click Update admin.
    Managing Dashboard Administrators and Permissions (29)
  4. Click Save changes.

Under Network-wide > Configure > Administration

  1. Update the Privilege drop-down for the admin user to the desired level.
    Managing Dashboard Administrators and Permissions (30)
  2. Click Save changes.

Removing Network Access

Under Organization > Administrators

  1. Click the row for the admin.
    Managing Dashboard Administrators and Permissions (31)
  2. Click the X in the row for the Target network.
    Managing Dashboard Administrators and Permissions (32)
  3. Click Update admin.
    Managing Dashboard Administrators and Permissions (33)
  4. Click Save changes.

Under Network-wide > Configure > Administration

  1. Click the X in the row for the admin user.
    Managing Dashboard Administrators and Permissions (34)
  2. Click Save changes.

Note: At present, current and past administrative users will continue to appear in the Configure > Users list when using Meraki authentication, even if no permissions are granted. Unless the user has been authorized for the SSID/VPN or hasdashboard permissions, they will not have access as a result of appearing in this list.

Troubleshooting Network Permissions

Error - This email is already in use

When attempting to add a network admin by using theCreate new userbutton, an error may appear indicating "This email is already in use,"even when the user doesn't appear in the list above.This is because an account had been previously created for this email address, either on this page or elsewhere in the organization. To add the user, click in theAdd an existing userboxand begin entering the email address of the user. It should appear in the drop-down and can be selected. Then choose thePrivilegesdesired and clickSave changes.

Permissions by Network Tag

To simplify the assignment of network-level permissions in an organization with many networks, permissions can be granted to users for a given network tag. Those permissions will then be applied to all networks in an organization with that tag. These changes can only be made by users with full organization access.

Managing Dashboard Administrators and Permissions (35)

Start by tagging any appropriate networks:

  1. Navigate to Organization > Overview.
    Managing Dashboard Administrators and Permissions (36)
  2. Click the checkboxes next to the desired networks.
    Managing Dashboard Administrators and Permissions (37)
  3. Click Tag.
    Managing Dashboard Administrators and Permissions (38)
  4. In the Addfield, select or enter any desired tags.
    1. To add a new tag, type the name of the new tag as a single wordwith no spaces. (e.g. "newtag" or "new_tag")
    2. Then click Add option next to the name of the tag desired.
      Managing Dashboard Administrators and Permissions (39)
  5. Once the tag appears as a bubble in the Add field, click the Add button.
    Managing Dashboard Administrators and Permissions (40)

Then grant permissions to those networks based on the tag:

  1. Navigate to Organization > Administrators.
  2. Click the row for the admin.
    Managing Dashboard Administrators and Permissions (41)
  3. Click Add access privileges.
    Managing Dashboard Administrators and Permissions (42)
  4. Under Target, select the entry that begins with Tag and includes the name of the tag applied earlier.
    Managing Dashboard Administrators and Permissions (43)
  5. Under Access indicate the level of access this admin should have to the networks with this tag.
    Managing Dashboard Administrators and Permissions (44)
  6. Click Update admin.
    Managing Dashboard Administrators and Permissions (45)
  7. Click Save Changes.

Switch Port Management Privileges

Permissions can also be assigned at theswitch port levelto allow for lower-tier technicians or external contractors to make basic changes to the network, such as cycling a port. This is done by tagging individual switch ports, creating a port management privilege for the tag(s), and then granting that privilege to an administrator.

Adding Port Tags

  1. Navigate to Configure > Switch ports.
    Managing Dashboard Administrators and Permissions (46)
  2. Click the checkbox next to any switch ports that should be tagged.
    Managing Dashboard Administrators and Permissions (47)
  3. ClickTag.
    Managing Dashboard Administrators and Permissions (48)
  4. In theAddbox, select an existing tag...
    Managing Dashboard Administrators and Permissions (49)

    ...or create a new tag by entering the nameand clickingAdd option.
    Note: Tags cannot contain spaces.
    Managing Dashboard Administrators and Permissions (50)

  5. Once any desired tags appear in the box as bubbles, clickAdd.
    Managing Dashboard Administrators and Permissions (51)
  6. The selected ports will now be tagged as desired.
    Note: The "Tags" column may need to be added to the table using the+button on the right side of the header column.
    Managing Dashboard Administrators and Permissions (52)

Removing Port Tags

  1. Navigate toConfigure > Switch ports.
    Managing Dashboard Administrators and Permissions (53)
  2. Click the checkbox next to any switch ports that should be tagged.
    Managing Dashboard Administrators and Permissions (54)
  3. ClickTag.
    Managing Dashboard Administrators and Permissions (55)
  4. In theRemovebox, select any existing tags that should be removed.
    Managing Dashboard Administrators and Permissions (56)
  5. Once any desired tags appear in the box as bubbles, clickRemove.
    Managing Dashboard Administrators and Permissions (57)

Creating Port Management Privileges

  1. For a combined network,navigate toNetwork-wide > Administration.
    Managing Dashboard Administrators and Permissions (58)
  2. For a non-combined network, navigate toNetwork-wide > General.

Managing Dashboard Administrators and Permissions (59)

3. UnderPort management privilegesclickAdd a port management privilege.
Managing Dashboard Administrators and Permissions (60)

4. Enter aPrivilege namethat describes the purpose of the privilege.
Managing Dashboard Administrators and Permissions (61)

5. Select anyPort tagsthat the privilege provides access to.
Managing Dashboard Administrators and Permissions (62)

6. Select whetherPacket captureis allowed or not on these ports.
Managing Dashboard Administrators and Permissions (63)

7. ClickSave changes.

Note:If your switch is in a combined network, you will need to make these changes on the Network-wide > Administrationpage rather than the Network-wide > Generalpage.

Removing Port Management Privileges

  1. Navigate to Network-wide >Configure > Administration.
    Managing Dashboard Administrators and Permissions (64)
  2. UnderPort management privileges, click theXin theActionscolumn for the privilege to be removed.
    Managing Dashboard Administrators and Permissions (65)
  3. ClickSave changes.

Assigning a Port Management Privilege

Port management privileges are assigned to network administrators the same wayas other privileges described in theManaging Network Permissionssection earlier in this doc. Select the privilege created earlier from thePrivilegedrop-down for the desired administrator.

Managing Dashboard Administrators and Permissions (66)

Resending confirmatione-mail

Upon creating an administratoraccount for a specific organization, aconfirmatione-mail is sent to the address associated with that account.

Managing Dashboard Administrators and Permissions (67)Managing Dashboard Administrators and Permissions (68)

In case the e-mail has not been receivedand the new administratoris still showing as 'Unverified',full-org admins have the option to resendthe verification e-mail in Organization> Administrators> choose the account in question>Resend confirmation e-mail.

Managing Dashboard Administrators and Permissions (69)

Unlocking an Administrator Account

It is possible to configure a lockout policy for accounts in a dashboard organization underOrganization > Configure > Settings > Securityby enablingtheAccount lockoutoption.

In the event an administrator's account has been locked as a result of too many failed authentication attempts, it can be unlocked by another user with full network permissions (for network admins) or full organization permissions. The user unlocking the account must have equivalent or greater permissions (i.e. a network-only admin cannot unlock the account for an organization-only admin).

Managing Dashboard Administrators and Permissions (70)

For admin users with organization permissions:

  1. Navigate to Organization > Administrators.
  2. Click the checkbox next to the admin with the locked account.
    Managing Dashboard Administrators and Permissions (71)
  3. Click Unlock.
    Managing Dashboard Administrators and Permissions (72)

For admin users with network permissions:

  1. Navigate to Network-wide > Configure > Administration
  2. Click the Unlock button next to the admin with the locked account.
    Managing Dashboard Administrators and Permissions (73)

Resetting an Admin User's Password

In order to reset an admin user's password:

  1. Log out of the dashboard by clicking sign out in the upper-right corner.
  2. Go tohttps://account.meraki.com/login/reset_password.
  3. Enter the email address of the admin account that needs to be reset.
  4. Click Submit.

An email will be sentwith details on how to reset thepassword.

Privilege Precedence

Privileges in the dashboard are additive, and a user will be granted rights on a page based on their highest level of applicable assigned permissions. Thus, an admin with read-only rights at the organization level, but full permissions for a particular network will effectively have full permissions to that network.

This is similarly applied with tags. If a user has read-only and full access to a network based on different tags, the user will be given full access.

Managing Dashboard Administrators and Permissions (2024)

References

Top Articles
Latest Posts
Article information

Author: Carlyn Walter

Last Updated:

Views: 6010

Rating: 5 / 5 (70 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Carlyn Walter

Birthday: 1996-01-03

Address: Suite 452 40815 Denyse Extensions, Sengermouth, OR 42374

Phone: +8501809515404

Job: Manufacturing Technician

Hobby: Table tennis, Archery, Vacation, Metal detecting, Yo-yoing, Crocheting, Creative writing

Introduction: My name is Carlyn Walter, I am a lively, glamorous, healthy, clean, powerful, calm, combative person who loves writing and wants to share my knowledge and understanding with you.