<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.6 patch 3 Active Directory Profiler - NTLM errors from DC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-3-active-directory-profiler-ntlm-errors-from-dc/m-p/4085075#M560386</link>
    <description>Looks like this is cosmetic. The wording threw me off, a coworker pointed out that this is an "Allowed" message.</description>
    <pubDate>Wed, 13 May 2020 15:51:45 GMT</pubDate>
    <dc:creator>t-roy</dc:creator>
    <dc:date>2020-05-13T15:51:45Z</dc:date>
    <item>
      <title>ISE 2.6 patch 3 Active Directory Profiler - NTLM errors from DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-3-active-directory-profiler-ntlm-errors-from-dc/m-p/4085065#M560385</link>
      <description>&lt;P&gt;Our deployment has the Active Directory Profiling Configuration enabled, and it appears to be working, I see the AD-* attributes for profiled nodes, but Active Directory is logging some interesting "errors" from our ISE node:&lt;/P&gt;&lt;PRE&gt;05/12/2020 03:58:05 PM LogName=Microsoft-Windows-NTLM/Operational

SourceName=Microsoft-Windows-Security-Netlogon

EventCode=8004

EventType=4

Type=Information

ComputerName=ad-server.domain.name&amp;nbsp;

User=NOT_TRANSLATED

Sid=S-1-5-18

SidType=0

TaskCategory=Auditing NTLM

OpCode=Info

RecordNumber=139156223

Keywords=None

Message=Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.

Secure Channel name:&amp;nbsp;ISE-SERVER

User name:&amp;nbsp;workstatoin@domain.name

&amp;nbsp;Domain name:&amp;nbsp;domain.name

&amp;nbsp;Workstation name: \\ISE-SERVER

&amp;nbsp;Secure Channel type: 2

Audit NTLM authentication requests within the domain&amp;nbsp;domain.name&amp;nbsp;that would be blocked if the security policy Network Security: Restrict NTLM: NTLM authentication in this domain is set to any of the Deny options. If you want to allow NTLM authentication requests in the domain domain.name, set the security policy Network Security: Restrict NTLM: NTLM authentication in this domain to Disabled. If you want to allow NTLM authentication requests to specific servers in the domain&amp;nbsp;domain.name, set the security policy Network Security: Restrict NTLM: NTLM authentication in this domain to Deny for domain servers or Deny domain accounts to domain servers, and then set the security policy Network Security: Restrict NTLM: Add server exceptions in this domain to define a list of servers in the domain&amp;nbsp;domain.name&amp;nbsp;to which clients are allowed to use NTLM authentication.&lt;/PRE&gt;&lt;P&gt;Is there some configuration on the domain controllers I am missing?&amp;nbsp; I verified the ISE-SERVER is joined to the domain, can fetch groups/users, auth is working as expected&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 15:41:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-3-active-directory-profiler-ntlm-errors-from-dc/m-p/4085065#M560385</guid>
      <dc:creator>t-roy</dc:creator>
      <dc:date>2020-05-13T15:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 patch 3 Active Directory Profiler - NTLM errors from DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-3-active-directory-profiler-ntlm-errors-from-dc/m-p/4085075#M560386</link>
      <description>Looks like this is cosmetic. The wording threw me off, a coworker pointed out that this is an "Allowed" message.</description>
      <pubDate>Wed, 13 May 2020 15:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-3-active-directory-profiler-ntlm-errors-from-dc/m-p/4085075#M560386</guid>
      <dc:creator>t-roy</dc:creator>
      <dc:date>2020-05-13T15:51:45Z</dc:date>
    </item>
  </channel>
</rss>

