<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/error-token-groups-insufficient-permissions/m-p/4026831#M454221</link>
    <description>Hello Mike,&lt;BR /&gt;&lt;BR /&gt;Thanks for the answer.&lt;BR /&gt;I have informed the customer about the "Active Directory Account Permissions Required to Perform Various Operations"&lt;BR /&gt;For the join operation, the account used is definitely correct. I have already sent to the customer the "Cisco ISE Machine Accounts" permissions in order to double-check.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 10 Feb 2020 14:07:18 GMT</pubDate>
    <dc:creator>kostasthedelegate</dc:creator>
    <dc:date>2020-02-10T14:07:18Z</dc:date>
    <item>
      <title>ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS</title>
      <link>https://community.cisco.com/t5/network-access-control/error-token-groups-insufficient-permissions/m-p/4026727#M454013</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a new ISE deployment with two nodes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with user authentication against Active Directory.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try to authenticate a user I get the following error:&lt;/P&gt;&lt;P&gt;24371&amp;nbsp;&amp;nbsp;&amp;nbsp; The ISE machine account does not have the required privileges to fetch groups. - ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS&lt;/P&gt;&lt;P&gt;24371&amp;nbsp;&amp;nbsp;&amp;nbsp; The ISE machine account does not have the required privileges to fetch groups. - xxx-xxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried this solution&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200780-Fix-Active-Directory-group-retrieval-iss.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200780-Fix-Active-Directory-group-retrieval-iss.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but if I am not mistaken is per user, so it is not scalable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer says that the accounts have the required privileges.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any hint?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 10:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-token-groups-insufficient-permissions/m-p/4026727#M454013</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2020-02-10T10:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS</title>
      <link>https://community.cisco.com/t5/network-access-control/error-token-groups-insufficient-permissions/m-p/4026823#M454220</link>
      <description>I would take a peek here: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Feb 2020 13:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-token-groups-insufficient-permissions/m-p/4026823#M454220</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-02-10T13:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS</title>
      <link>https://community.cisco.com/t5/network-access-control/error-token-groups-insufficient-permissions/m-p/4026831#M454221</link>
      <description>Hello Mike,&lt;BR /&gt;&lt;BR /&gt;Thanks for the answer.&lt;BR /&gt;I have informed the customer about the "Active Directory Account Permissions Required to Perform Various Operations"&lt;BR /&gt;For the join operation, the account used is definitely correct. I have already sent to the customer the "Cisco ISE Machine Accounts" permissions in order to double-check.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Feb 2020 14:07:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-token-groups-insufficient-permissions/m-p/4026831#M454221</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2020-02-10T14:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS</title>
      <link>https://community.cisco.com/t5/network-access-control/error-token-groups-insufficient-permissions/m-p/4135967#M562332</link>
      <description>&lt;P&gt;Try this fix to reset the computer account permissions:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200349-ISE-1-3-AD-Authentications-Fail-with-Err.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200349-ISE-1-3-AD-Authentications-Fail-with-Err.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 13:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-token-groups-insufficient-permissions/m-p/4135967#M562332</guid>
      <dc:creator>avinash4567</dc:creator>
      <dc:date>2020-08-14T13:15:18Z</dc:date>
    </item>
  </channel>
</rss>

