<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE AD Join - saving creds yes or no? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306830#M566101</link>
    <description>&lt;P&gt;The Store Credentials checkbox appeared in ISE 2.2 based on Admin Guide diffs. I will say after reading it, it is still not terribly obvious but my interpretation is that it saves the credentials for subsequent joins of PSNs in a large deployment if you do not join them all at once:&lt;/P&gt;
&lt;DIV class="page" title="Page 378"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Enter the Active Directory username and password from the Join Domain dialog box that opens.&lt;BR /&gt;It is strongly recommended that you choose Store credentials, in which case your administrator's user name and password will be saved &lt;STRONG&gt;in order to be used for all Domain Controllers (DC)&lt;/STRONG&gt; that are configured for monitoring.&lt;SPAN style="font-size: 10.000000pt; font-family: 'TimesNewRomanPSMT';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 653px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/106349i6F1D0A120BC06474/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 13 Mar 2021 19:34:15 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2021-03-13T19:34:15Z</dc:date>
    <item>
      <title>ISE AD Join - saving creds yes or no?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306615#M566093</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have read/heard two completely different reasons/theories why ISE allows the AD user creds to be saved at the time of joining an Active Directory domain. I have to say I never save the creds and I have yet to see the point of it:&lt;/P&gt;
&lt;P&gt;1) Saving creds allows the PAN to easily join any nodes that are registered in the future without needing to enter the creds again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Saving creds is required to allow the AD profiler probe to work&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am comfortable with reason one and I don’t care if I have to enter the creds for each new ise node I register.&amp;nbsp;&lt;BR /&gt;But point two concerns me. Does the AD profiler probe really need this ? I have not tested but I was fairly sure that my AD probes work without saving AD creds.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Does anyone know the real use case for saving AD creds? I can’t find an answer in the manuals.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 02:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306615#M566093</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-03-13T02:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Join - saving creds yes or no?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306621#M566094</link>
      <description>&lt;P&gt;Straight from the admin guide.&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;The credentials that are used for the join or leave operation are not stored in Cisco&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;ISE&lt;/SPAN&gt;&lt;SPAN&gt;. Only the newly created Cisco&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;ISE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;machine account credentials are stored, which enables the Endpoint probe to run."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The machine account is just an object in AD, the username/password you use to join isn't saved in any way. I can confirm this is the case, I have a customer that used temporary admin accounts for joining that were deleted/destroyed after 15 minutes. Everything worked as expected.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 02:26:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306621#M566094</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-03-13T02:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Join - saving creds yes or no?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306634#M566095</link>
      <description>&lt;P&gt;Thanks Damien. In your case, were you reliant on the AD probe and was it still working?&amp;nbsp;&lt;BR /&gt;I don’t understand what the Admin guide means by “ [credentials]&amp;nbsp;&lt;SPAN&gt;are not stored in Cisco&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;ISE&lt;/SPAN&gt;&lt;SPAN&gt;. Only the newly created Cisco&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;ISE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;machine account credentials are stored”. Probably badly phrased but it seems to contradict itself.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am still none the wiser why ISE has an option to store credentials if it’s apparently not required in any way.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 04:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306634#M566095</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-03-13T04:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Join - saving creds yes or no?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306830#M566101</link>
      <description>&lt;P&gt;The Store Credentials checkbox appeared in ISE 2.2 based on Admin Guide diffs. I will say after reading it, it is still not terribly obvious but my interpretation is that it saves the credentials for subsequent joins of PSNs in a large deployment if you do not join them all at once:&lt;/P&gt;
&lt;DIV class="page" title="Page 378"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Enter the Active Directory username and password from the Join Domain dialog box that opens.&lt;BR /&gt;It is strongly recommended that you choose Store credentials, in which case your administrator's user name and password will be saved &lt;STRONG&gt;in order to be used for all Domain Controllers (DC)&lt;/STRONG&gt; that are configured for monitoring.&lt;SPAN style="font-size: 10.000000pt; font-family: 'TimesNewRomanPSMT';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 653px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/106349i6F1D0A120BC06474/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 19:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306830#M566101</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-03-13T19:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Join - saving creds yes or no?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306885#M566110</link>
      <description>&lt;P&gt;Thanks Thomas. So the Admin Guide reference about AD Probe is not correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think this needs to be documented correctly once and for all.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I don’t have a lab to verify whether AD probe works when you do not save credentials. Knowing that would be awesome.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 22:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306885#M566110</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-03-13T22:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Join - saving creds yes or no?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306889#M566111</link>
      <description>&lt;P&gt;OK, let me send this off for an authoritative answer and get the admin guide updated.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 23:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-join-saving-creds-yes-or-no/m-p/4306889#M566111</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-03-13T23:03:48Z</dc:date>
    </item>
  </channel>
</rss>

