<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE isn't authenticating against the correct active directory in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-isn-t-authenticating-against-the-correct-active-directory/m-p/4455909#M569306</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1171789"&gt;@SMD28316&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;you said "&lt;EM&gt;... for users that exist in AD2 only ...&lt;/EM&gt;", the &lt;STRONG&gt;AD2&lt;/STRONG&gt; data is not being replicated to &lt;STRONG&gt;AD1&lt;/STRONG&gt;?&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;At &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; External Identity Sources &amp;gt; Active Directory&lt;/STRONG&gt;, your &lt;STRONG&gt;Active Directory Domain&lt;/STRONG&gt; is &lt;U&gt;DOMAIN.COM&lt;/U&gt;?&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;At &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; External Identity Sources &amp;gt; Active Directory &amp;gt;&lt;/STRONG&gt; &lt;EM&gt;select your AD&lt;/EM&gt; &lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt; select the &lt;STRONG&gt;Advanced Settings&lt;/STRONG&gt; tab, double check the &lt;STRONG&gt;Identity Resolution&lt;/STRONG&gt; configuration:&lt;BR /&gt;. &lt;EM&gt;If Identity Store does not include de AD Domain&lt;/EM&gt;&lt;BR /&gt;. &lt;EM&gt;If some of the Domains are unreachable&lt;/EM&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Fri, 27 Aug 2021 12:47:51 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2021-08-27T12:47:51Z</dc:date>
    <item>
      <title>ISE isn't authenticating against the correct active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-isn-t-authenticating-against-the-correct-active-directory/m-p/4455851#M569303</link>
      <description>&lt;P&gt;I have two active directories added to ISE, both have the same domain:&lt;/P&gt;&lt;P&gt;ad1.domain.com&lt;/P&gt;&lt;P&gt;ad2.domain.com&lt;/P&gt;&lt;P&gt;, I added AD2 later, but ISE keeps authenticating against AD1 only, for users that exist in AD2 only, the live logs reports show the identity store as AD1 and the authentication fails as a result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authorization role the users hit on uses a condition that includes groups from both the ADs, but only the old one is being selected. I created another authorization role to test the AD, it includes a condition for AD2 only, but ISE skips it and keeps authenticating against the old authorization role that is below the newly configured one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user exists in the impacted AD and I have tested it via ISE, both active directories are operational as well. I'm not sure what is the issue, is there a configuration I'm missing? The identity sequence includes the new AD and ALL_AD_JOIN POINTS but the chosen identity store is always AD1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using certificate authentication profile on the sequence, do I need to edit it after adding the new AD2 or not?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 11:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-isn-t-authenticating-against-the-correct-active-directory/m-p/4455851#M569303</guid>
      <dc:creator>SMD28316</dc:creator>
      <dc:date>2021-08-27T11:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE isn't authenticating against the correct active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-isn-t-authenticating-against-the-correct-active-directory/m-p/4455909#M569306</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1171789"&gt;@SMD28316&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;you said "&lt;EM&gt;... for users that exist in AD2 only ...&lt;/EM&gt;", the &lt;STRONG&gt;AD2&lt;/STRONG&gt; data is not being replicated to &lt;STRONG&gt;AD1&lt;/STRONG&gt;?&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;At &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; External Identity Sources &amp;gt; Active Directory&lt;/STRONG&gt;, your &lt;STRONG&gt;Active Directory Domain&lt;/STRONG&gt; is &lt;U&gt;DOMAIN.COM&lt;/U&gt;?&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;At &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; External Identity Sources &amp;gt; Active Directory &amp;gt;&lt;/STRONG&gt; &lt;EM&gt;select your AD&lt;/EM&gt; &lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt; select the &lt;STRONG&gt;Advanced Settings&lt;/STRONG&gt; tab, double check the &lt;STRONG&gt;Identity Resolution&lt;/STRONG&gt; configuration:&lt;BR /&gt;. &lt;EM&gt;If Identity Store does not include de AD Domain&lt;/EM&gt;&lt;BR /&gt;. &lt;EM&gt;If some of the Domains are unreachable&lt;/EM&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 12:47:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-isn-t-authenticating-against-the-correct-active-directory/m-p/4455909#M569306</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-08-27T12:47:51Z</dc:date>
    </item>
  </channel>
</rss>

