<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Directory and Cisco Secure Access Integration in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/active-directory-and-cisco-secure-access-integration/m-p/5239126#M2106</link>
    <description>&lt;P&gt;Is there a way to integrate Active Directory (Child Domain) to Cisco Secure Access without any involving any Enterprise Account?&lt;BR /&gt;Our setup with Cisco Secure Access and Active Directory integration using domain and AD connector, when installing AD connector where ad is installed it requires user credentials for the ad connector to have a successful connection but the credentials used for ad connector is not a member of "Enterprise Read-Only Domain Controllers". I think that's why it's causing the error because the user used is not a member of "Enterprise Read-Only Domain Controllers". But when I try to add the user to that member, the status is connected.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Dec 2024 01:36:15 GMT</pubDate>
    <dc:creator>hadi123</dc:creator>
    <dc:date>2024-12-20T01:36:15Z</dc:date>
    <item>
      <title>Active Directory and Cisco Secure Access Integration</title>
      <link>https://community.cisco.com/t5/cloud-security/active-directory-and-cisco-secure-access-integration/m-p/5239126#M2106</link>
      <description>&lt;P&gt;Is there a way to integrate Active Directory (Child Domain) to Cisco Secure Access without any involving any Enterprise Account?&lt;BR /&gt;Our setup with Cisco Secure Access and Active Directory integration using domain and AD connector, when installing AD connector where ad is installed it requires user credentials for the ad connector to have a successful connection but the credentials used for ad connector is not a member of "Enterprise Read-Only Domain Controllers". I think that's why it's causing the error because the user used is not a member of "Enterprise Read-Only Domain Controllers". But when I try to add the user to that member, the status is connected.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 01:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/active-directory-and-cisco-secure-access-integration/m-p/5239126#M2106</guid>
      <dc:creator>hadi123</dc:creator>
      <dc:date>2024-12-20T01:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and Cisco Secure Access Integration</title>
      <link>https://community.cisco.com/t5/cloud-security/active-directory-and-cisco-secure-access-integration/m-p/5239465#M2109</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;the requirements are documented here. you need to have read and replicating directory change permissions.. there is no way around it to get the user to ip mapping information.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.sse.cisco.com/sse-user-guide/docs/prerequisites-for-ad-connectors#:~:text=You%20must%20configure%20a%20server," target="_blank"&gt;https://docs.sse.cisco.com/sse-user-guide/docs/prerequisites-for-ad-connectors#:~:text=You%20must%20configure%20a%20server,&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FFCC00"&gt;Assign&amp;nbsp;Read&amp;nbsp;and&amp;nbsp;Replicating Directory Changes&amp;nbsp;permissions.&lt;/FONT&gt;&lt;BR style="box-sizing: border-box; color: #384248; font-family: CiscoSans, helvetica, arial, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;Alternatively, you can make the AD Connector account a member of the built-in&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: 600; color: #384248; font-family: CiscoSans, helvetica, arial, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;Enterprise Read-only Domain Controllers&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;group, which will automatically assign these permissions.&lt;/SPAN&gt;&lt;BR style="box-sizing: border-box; color: #384248; font-family: CiscoSans, helvetica, arial, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;BR style="box-sizing: border-box; color: #384248; font-family: CiscoSans, helvetica, arial, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;BR style="box-sizing: border-box; color: #384248; font-family: CiscoSans, helvetica, arial, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;The AD Connector does an initial synchronization of the AD structure to Secure Access. After this, it detects changes to the AD structure and communicates these changes only. The detection of changes requires the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: 600; color: #384248; font-family: CiscoSans, helvetica, arial, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;Replicating Directory Changes&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;permission. The AD Connector cannot function without this permission.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 18:27:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/active-directory-and-cisco-secure-access-integration/m-p/5239465#M2109</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-12-20T18:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and Cisco Secure Access Integration</title>
      <link>https://community.cisco.com/t5/cloud-security/active-directory-and-cisco-secure-access-integration/m-p/5239655#M2111</link>
      <description>&lt;P&gt;Noted and thank you&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2024 14:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/active-directory-and-cisco-secure-access-integration/m-p/5239655#M2111</guid>
      <dc:creator>hadi123</dc:creator>
      <dc:date>2024-12-21T14:18:33Z</dc:date>
    </item>
  </channel>
</rss>

