<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Passive ID Error with WMI Config or Agent Install in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3559864#M535553</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am getting the error below when trying to configure WMI.&amp;nbsp; I almost get a similar error if I try to deploy the agent instead, i.e. remote copy failed to set credentials.&amp;nbsp; I am using a domain admin account and I didn't see anything obvious when I turned on debug for Passive ID and didn't see anything obvious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can go through all the steps to check what the Config WMI script is supposed to do, but I thought the only prerequisite to running the Config WMI was the ID used was a member of Domain Admins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/108409_Capture.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Jun 2017 14:55:09 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2017-06-19T14:55:09Z</dc:date>
    <item>
      <title>ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3559864#M535553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am getting the error below when trying to configure WMI.&amp;nbsp; I almost get a similar error if I try to deploy the agent instead, i.e. remote copy failed to set credentials.&amp;nbsp; I am using a domain admin account and I didn't see anything obvious when I turned on debug for Passive ID and didn't see anything obvious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can go through all the steps to check what the Config WMI script is supposed to do, but I thought the only prerequisite to running the Config WMI was the ID used was a member of Domain Admins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/108409_Capture.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jun 2017 14:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3559864#M535553</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-06-19T14:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3559865#M535555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct.&amp;nbsp; The only requirements are domain admin privileges as well as the ability for ISE / ISE-PIC to have access through windows firewalls.&amp;nbsp; Check out the troubleshooting section of the ISE-PIC admin guide verify you AD instance is set up properly.&amp;nbsp; Also, we have an ISE-PIC specific community that you can post these types of questions to in the future: &lt;A href="https://community.cisco.com/space/5633"&gt;Passive Identity Connector (PIC) &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/pic_admin_guide/PIC_admin/PIC_admin_chapter_01000.html#id_31521" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/pic_admin_guide/PIC_admin/PIC_admin_chapter_01000.html#id_31521"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/pic_admin_guide/PIC_admin/PIC_admin_chapter_01000.html#id_31521&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jun 2017 15:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3559865#M535555</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-06-19T15:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3675117#M535556</link>
      <description>&lt;P&gt;Hi,&amp;nbsp; I have the same problem "Unable to run executable on dc3.test.corp, The IseExec remote execution functionality failed to read response"&lt;/P&gt;
&lt;P&gt;One difference I have 3 DC in one domain.&lt;/P&gt;
&lt;P&gt;dc1&amp;nbsp;is win server 2012 - ISE-PIC works fine&lt;/P&gt;
&lt;P&gt;dc2 is win server 2016 (upgraded from win server 2012) -ISE-PIC works fine&lt;/P&gt;
&lt;P&gt;dc3 is win server 2016 - ISE-PIC doesn`t works.&lt;/P&gt;
&lt;P&gt;Firewall on dc3&amp;nbsp; is disabled&amp;nbsp; and account from which I connect&amp;nbsp; is domain admin.&lt;/P&gt;
&lt;P&gt;ISE dubug constantly&amp;nbsp; shows&amp;nbsp; this massage:&lt;/P&gt;
&lt;P&gt;"2018-07-25 15:37:47,334 DEBUG [Thread-19][] com.cisco.idc.dc-probe- DCOM timeout reached on DC. Identity Mapping.NTLMv2 = true , Identity Mapping.dc-domainname = test.corp , Identity Mapping.probe = WMI , Identity Mapping.dc-windows-version = Win2016 , Identity Mapping.dc-username = administrator , Identity Mapping.dc-name = dc3.test.corp , Identity Mapping.dc-host = dc3.test.corp/{ip address} , Identity Mapping.server = ise , Identity Mapping.dc-netBIOS = TEST , &lt;BR /&gt;2018-07-25 15:37:52,220 DEBUG [qtp60830820-14 - /][] com.cisco.idc.dc-probe- [ConfigHandler] configuration-server received request&lt;BR /&gt;2018-07-25 15:37:57,222 DEBUG [qtp60830820-13 - /][] com.cisco.idc.dc-probe- [ConfigHandler] configuration-server received request "&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 08:03:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3675117#M535556</guid>
      <dc:creator>pramakasha</dc:creator>
      <dc:date>2018-07-26T08:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3675683#M535557</link>
      <description>Recommend debug thru tac&lt;BR /&gt;</description>
      <pubDate>Thu, 26 Jul 2018 18:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3675683#M535557</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-07-26T18:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708531#M535559</link>
      <description>&lt;P&gt;We just moved a domain controller, by demoting and then promoting it afterwards. Now I receive the same error, and the firewall is ok.&lt;/P&gt;
&lt;P&gt;Is there are possibility that all the configuration on the domain controller got rolled back when we demoted it, and have to be done again? Shouldn't the config from ISE automatically apply the proper changes on the DC?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 06:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708531#M535559</guid>
      <dc:creator>Michael Bartholomæussen</dc:creator>
      <dc:date>2018-09-18T06:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708719#M535562</link>
      <description>You made changes on the domain controller and expecting Ise to refresh the config changes? No it’s a one time configuration please rerun it&lt;BR /&gt;&lt;BR /&gt;If you need troubleshooting help work thru tac &lt;BR /&gt;</description>
      <pubDate>Tue, 18 Sep 2018 13:03:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708719#M535562</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-18T13:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708721#M535563</link>
      <description>&lt;P&gt;I read that newer version of ISE takes care of the registry settings etc. Then I only need to "Add DCs", type in user and pass for a account with sufficient privileges, and It should work?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 13:09:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708721#M535563</guid>
      <dc:creator>Michael Bartholomæussen</dc:creator>
      <dc:date>2018-09-18T13:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708837#M535564</link>
      <description>Here is the admin guide information on it:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01110.html#id_31516" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01110.html#id_31516&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;some other links:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210522-Configure-ISE-2-2-PIC-with-Active-Direct.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210522-Configure-ISE-2-2-PIC-with-Active-Direct.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Sep 2018 14:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708837#M535564</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-18T14:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708839#M535565</link>
      <description>Yes.  You are correct.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Tim</description>
      <pubDate>Tue, 18 Sep 2018 14:46:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3708839#M535565</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-09-18T14:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3710212#M535567</link>
      <description>something messed up ISE. The configuration on 2 other Domain Controllers were exact the same.&lt;BR /&gt;I did a "leave" of both nodes, and then joined them again, then it worked.</description>
      <pubDate>Thu, 20 Sep 2018 08:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3710212#M535567</guid>
      <dc:creator>Michael Bartholomæussen</dc:creator>
      <dc:date>2018-09-20T08:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3851388#M535570</link>
      <description>&lt;P&gt;The &lt;U&gt;password&lt;/U&gt; for the joining user &lt;U&gt;must NOT&lt;/U&gt; contain special characters; at least no $ sign......for whatever reason.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding and testing of a passiv-ID connection works with the "wrong" password as well, but the provider stays down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Environment:&lt;/P&gt;&lt;P&gt;ISE 2.4&lt;/P&gt;&lt;P&gt;Domain Controller 2016&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 13:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/3851388#M535570</guid>
      <dc:creator>rzergoi</dc:creator>
      <dc:date>2019-05-10T13:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/4671970#M576762</link>
      <description>&lt;P&gt;Paul, what was solution? Firewall settings are correct and we are using domain admin account, with same error.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 19:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/4671970#M576762</guid>
      <dc:creator>blooy</dc:creator>
      <dc:date>2022-08-18T19:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/5014312#M587138</link>
      <description>&lt;P&gt;Below is message in the Windows Domain Controller system log: plus a Microsoft knowledge base article&lt;/P&gt;&lt;P&gt;The server-side authentication level policy does not allow the user Domain\[domain id] SID (S-1-5-21-3253444385-1653231566-2523731723-1128) from address [ise-server-ip] to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.&lt;/P&gt;&lt;H1&gt;KB5004442—Manage changes for Windows DCOM Server Security Feature Bypass (CVE-2021-26414)&lt;/H1&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c" target="_blank" rel="noopener"&gt;https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c&lt;/A&gt;&lt;/P&gt;&lt;P&gt;After adding the registry entry the PassiveID Domain Controllers &amp;gt; Add &amp;gt; test still fails&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 16:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/5014312#M587138</guid>
      <dc:creator>frasware</dc:creator>
      <dc:date>2024-02-07T16:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Error with WMI Config or Agent Install</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/5023634#M587637</link>
      <description>&lt;P&gt;WMI as protocol for Agent after KB5004442 does not work properly anymore. You have to change it for MS-RPC protocol.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 19:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-error-with-wmi-config-or-agent-install/m-p/5023634#M587637</guid>
      <dc:creator>stayd</dc:creator>
      <dc:date>2024-02-23T19:44:12Z</dc:date>
    </item>
  </channel>
</rss>

