<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE AD Integration Issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212544#M100166</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the replies. I'll work through the information and post back the outcome.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Jun 2013 03:14:56 GMT</pubDate>
    <dc:creator>James Smith</dc:creator>
    <dc:date>2013-06-26T03:14:56Z</dc:date>
    <item>
      <title>ISE AD Integration Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212541#M100163</link>
      <description>&lt;P&gt;G'day All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am attempting to ad my primary admin node to AD, but I am receving the following error message in the ISE gui. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;using Writable Domain Controller: addc01.abc.com&lt;/P&gt;&lt;P&gt;Update Computer DnsName Failed.&lt;/P&gt;&lt;P&gt;User Does Not Have Update Privileges On The DNSHostName Attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error: Either User &lt;A href="mailto:ise_ad@abc.com" target="_blank"&gt;ise_ad@abc.com&lt;/A&gt; Does Not Have Sufficient Permissions To Join&lt;/P&gt;&lt;P&gt;Domain Abc.com, Zone Null&lt;/P&gt;&lt;P&gt;Or This Computer Already Has An Account In The Domain.&lt;/P&gt;&lt;P&gt;In Order To Rejoin, You Must Have Domain Administrator Privileges.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Join To Domain&amp;nbsp; Abc.com , Zone&amp;nbsp; Null&amp;nbsp; Failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The detailed test passes fine. I don't see any NTP errors and DNS is completely resolvable at both ends. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance is greatly appreciated guys. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212541#M100163</guid>
      <dc:creator>James Smith</dc:creator>
      <dc:date>2019-03-11T03:34:56Z</dc:date>
    </item>
    <item>
      <title>ISE AD Integration Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212542#M100164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi,&lt;/P&gt;&lt;P&gt;I think I had similar problem in the past so check:&lt;/P&gt;&lt;P&gt;- whether u got PTR record (so reverse lookup zone must be configured as well).&lt;/P&gt;&lt;P&gt;- your CLI dns points the right server with this records&lt;/P&gt;&lt;P&gt;- your CLI domain name is the same as AD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Przemek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 06:19:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212542#M100164</guid>
      <dc:creator>Przemyslaw Konitz</dc:creator>
      <dc:date>2013-06-25T06:19:09Z</dc:date>
    </item>
    <item>
      <title>ISE AD Integration Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212543#M100165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="line-height: normal;"&gt;This happen due to incorrect DNS entry on DNS server also make sure that your user which you are using to join the domain have administrator right on AD. Cross check that you are able to resolve the name of your domain and vice versa.&lt;/P&gt;&lt;P style="line-height: normal;"&gt;For more detail you can check the below link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_troubleshooting.html#wp1049448"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_troubleshooting.html#wp1049448&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 08:25:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212543#M100165</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-06-25T08:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Integration Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212544#M100166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the replies. I'll work through the information and post back the outcome.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 03:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212544#M100166</guid>
      <dc:creator>James Smith</dc:creator>
      <dc:date>2013-06-26T03:14:56Z</dc:date>
    </item>
    <item>
      <title>I had a similar problem. I</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212545#M100167</link>
      <description>&lt;P&gt;I had a similar problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I received the following error:&lt;/P&gt;&lt;P&gt;Using domain controller: paprowdc.domain.corp writable=true&lt;BR /&gt;Update Computer dnsName failed.&lt;BR /&gt;User does not have update privileges on the dNSHostName attribute.&lt;/P&gt;&lt;P&gt;Error: Either user user_ad@domain.corp &amp;nbsp;does not have sufficient permissions to join&lt;BR /&gt;&amp;nbsp;domain domain.corp, zone null&lt;BR /&gt;&amp;nbsp;or this computer already has an account in the domain.&lt;BR /&gt;In order to rejoin, you must have Domain Administrator privileges.&lt;/P&gt;&lt;P&gt;Join to domain `domain.corp`, zone `null` failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem was solved, adding the privilege for add machine object on the AD to the user user_ad.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2014 20:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212545#M100167</guid>
      <dc:creator>khernandezruiz</dc:creator>
      <dc:date>2014-03-18T20:51:59Z</dc:date>
    </item>
    <item>
      <title>James, I agree with the above</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212546#M100168</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;James, I agree with the above reply by&amp;nbsp;&lt;A about="/users/khernandezruiz" class="username" datatype="" href="https://community.cisco.com/users/khernandezruiz" property="foaf:name" style="background-color: rgb(247, 247, 247);" title="View user profile." typeof="sioc:UserAccount" lang=""&gt;khernandezruiz&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;AD account required for domain access in ACS should have either of the&amp;nbsp;following:&lt;BR /&gt;- Add workstations to domain user right in corresponding domain.&lt;BR /&gt;- Create Computer Objects or Delete Computer Objects permission on&amp;nbsp;corresponding computers container where ACS machine's account is&amp;nbsp;precreated (created before joining ACS to the domain).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;*Do rate helpful posts*&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2014 03:34:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-integration-issues/m-p/2212546#M100168</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-03-19T03:34:57Z</dc:date>
    </item>
  </channel>
</rss>

