Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To restrict administrative access in Cisco SD-WAN Manager, assign each user an appropriate role and scope instead of giving everyone the built-in netadmin role. A role controls permitted actions; a scope limits the devices, sites, or configurations those actions can reach. Configure both under Administration > Users and Access, then verify the result with representative accounts. Labels and capabilities can vary by release; Cisco’s user-management guide covers releases 26.x and later and was updated September 28, 2026.

How roles and scopes work together

Cisco describes role-based access control (RBAC) as restricting or authorizing access based on user roles and scope. These are separate controls: the role determines whether a user can read, write, or is denied access to a feature, while the scope limits the resources available to that user. Effective write access depends on both the role and the permitted scope or locale. See Cisco’s Role-Based Access Control guide.

That distinction matters in practice. A read-capable role does not itself limit a user to a particular set of devices, and a narrow scope does not make an overly broad role safe. Match the user’s required actions and required resources independently.

Choose a role that matches the work

Cisco’s built-in roles cover broad job categories. The operator role is intended for view-only access; netadmin permits all operations; network_operations covers non-security-policy operations; and security_operations is for security operations. Cisco also notes that only netadmin users can view running and local configuration. Check the release-specific Authentication documentation before relying on a built-in role for a precise local job function.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When the built-in choices grant too much or too little, create a custom role rather than modifying a default role: Cisco says default roles cannot be changed. In a custom role, set Deny, Read, or Write for relevant features and subfeatures. Treat write access to deployment and other high-impact operations as an explicit decision. From Manager Release 20.18.1, a role and its descendants can have different permissions, so inspect child permissions instead of assuming a parent setting controls every subfeature.

Create a scope for the resources the user needs

Scopes define the resource boundary for access. Cisco’s procedure lets administrators create a scope from nodes, add the required nodes, and optionally associate users and configurations. Use only the nodes and configurations needed for the relevant group; avoid a global scope when a narrower one will do.

  1. Open Administration > Users and Access.
  2. Create a scope and add the nodes representing the resources the group needs.
  3. Optionally associate relevant users and configurations, following the workflow for your installed release.

See Cisco’s Configure RBAC procedure for the release-specific interface details.

Create the custom role and assign users

Use this sequence to translate job duties into access without granting every user global administrator rights:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. List each person’s administrative tasks and the resources involved. Separate view-only work, routine configuration, security operations, and full administration.
  2. Under Administration > Users and Access, create or select a scope containing only the needed nodes and configurations.
  3. Create a custom role if a built-in role does not fit. Set Deny, Read, or Write for each relevant feature and subfeature.
  4. Add or edit the user and assign the matching role and scope. Cisco’s Configure Users guide describes user creation, role and scope assignment, and editing users.
  5. Test allowed and denied tasks with representative non-admin accounts before treating the policy as complete. This is an operational verification step, not a Cisco-documented test result.

Use VPN restrictions for segment-level monitoring

If the requirement is specifically to limit monitoring to network segments, Cisco documents a separate RBAC-by-VPN mechanism. Users assigned to VPN groups see a read-only VPN dashboard and monitoring restricted to devices and interfaces in those segments. This specialized control is useful for segmented visibility, but it is not a substitute for designing suitable administrative roles and scopes. See Cisco’s RBAC by VPN documentation.

Manage authentication and account access

Cisco’s onboarding guide documents both local authentication and SAML identity-provider setup. For SAML, the procedure includes enabling IdP settings, providing an IdP name and domain, and uploading SAML metadata; after a new IdP is configured, users are redirected to a unified SAML login page. The availability and sign-in flow depend on deployment and release, so verify the guide and UI for your environment. See Cisco’s Configure users and access guide.

Rank #4
Sale
Cisco Meraki MX68CW-HW Wireless LTE Security SD-WAN Appliance (Renewed)
  • Renewed Enterprise Appliance: This Cisco Meraki MX68CW-HW comes professionally renewed to deliver reliable performance for small to medium-sized business networks, offering enterprise-grade security and SD-WAN capabilities at an accessible price point
  • Integrated Wireless Connectivity: Features built-in wireless capabilities that enable seamless network deployment without requiring additional access points, providing flexible connectivity options for your business environment
  • LTE Failover Support: Equipped with LTE cellular connectivity to ensure continuous network uptime by automatically switching to cellular backup when primary internet connections fail, maintaining business continuity during outages
  • Advanced Security Features: Delivers comprehensive network security with integrated firewall, content filtering, and intrusion detection capabilities to protect your business from cyber threats and unauthorized access
  • SD-WAN Technology: Incorporates software-defined wide area networking functionality that intelligently routes traffic across multiple connections, optimizing application performance and reducing bandwidth costs while simplifying network management

The same guide describes configurable login protections. For the guide version updated July 7, 2026, its documented settings are:

Setting Documented range Documented default
Failed-login count 1–3600 attempts 3600
Failed-attempt counting window 1–60 minutes 60 minutes
Lockout interval 1–60 minutes 15 minutes
Inactive-days lockout threshold 2–90 days, when enabled Not stated in the guide

These are product-setting ranges and defaults documented for the stated guide version, not universal recommendations. Confirm the current options and defaults in the guide and UI for your installed release before changing them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Review sessions and block access when needed

The user-management guide documents administrative user locks, resetting a locked user, and reviewing active HTTP sessions. Session details include username, domain, and source IP information. If an account needs to be blocked, use the administrative lock controls and review its active sessions. Do not rely on deleting the user alone to end access immediately: Cisco states that deleting a user does not log out a session that is already signed in. Consult Configure Users for the applicable controls and procedures.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.