ISE 2.1 How to Join a Node to Active Directory

preview_player
Показать описание
Video Presented by: Anastasyia Volkova

This video walks you through the steps of joining a node to Active Directory along with some basic troubleshooting steps.

Starting in ISE 1.3 the follow is applicable

For the newly created Cisco ISE machine account that is used to communicate to the Active Directory connection, the following permissions are required:

Ability to change own password

Read the user/machine objects corresponding to users/machines being authenticated

Query some parts of the Active Directory to learn about required information (for example, trusted domains, alternative UPN suffixes and so on.)

Ability to read tokenGroups attribute

You can precreate the machine account in Active Directory, and if the SAM name matches the Cisco ISE appliance hostname, it should be located during the join operation and re-used.
Рекомендации по теме
Комментарии
Автор

Adding a new active directory to the ISE server, during the operation, could affect the operation or could it affect users?

alejandroalbino
Автор

Adding a new active directory to the ISE server, during the operation, could affect the operation or could it affect users?

alejandroalbino