Modify or delete roles
You can modify the role settings as needed. All devices, users and hosts in the database are required to have a role. You cannot remove a role from these elements. You can only change the role to something else. If no role is specified devices, users and hosts default to the NAC Default role.
If a role is in use by a Device Profiling Rule, guest template, or assigned to a Host, User, or Device, the role cannot be removed from the database. If a role is simply mapped to a device based on the device's membership in a group and not assigned specifically to the device, the role can be removed.
- Select Policy & Objects > Roles.
- Select the role from the list.
- To remove the role from the database, click Delete.
- On the confirmation window, click Yes to remove the role.
- If the role is in use, a warning message is displayed and the role is not deleted. Click In Use for a complete list of places where this role is referenced.
- To modify the role, click Modify .
- Modify settings as needed and click OK to save.