<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Joining Cisco ISE Node with RODC Active Directory Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/joining-cisco-ise-node-with-rodc-active-directory-issue/m-p/4513218#M571449</link>
    <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01101.html#reference_F19556CAD5C949B58DF89334E2C6255D" target="_blank" rel="noopener"&gt;Active Directory Account Permissions Required to Perform Various Operations&lt;/A&gt;&lt;/P&gt;
&lt;H4 id="ariaid-title32" class="title topictitle4"&gt;Active Directory Account Permissions Required to Perform Various Operations&lt;/H4&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;&lt;STRONG&gt;Join Operations&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="50%"&gt;&lt;STRONG&gt;Cisco Machine Accounts&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;
&lt;P class="p"&gt;The join operation requires the following account permissions:&lt;/P&gt;
&lt;UL id="reference_F19556CAD5C949B58DF89334E2C6255D__ul_qx3_w4c_qx" class="ul"&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_BCA59CE71A574D179E905F51D628E21C" class="li"&gt;
&lt;P class="p"&gt;Search Active Directory (to see if a Cisco machine account exists)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_994D03F3E0FE4B1FA75D5E4E361504FF" class="li"&gt;
&lt;P class="p"&gt;Create Cisco machine account to domain (if the machine account does not already exist)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_ED1668CBC5BC4F839E56DACE2B0E42F7" class="li"&gt;
&lt;P class="p"&gt;Set attributes on the new machine account (for example, Cisco machine account password, SPN, dnsHostname)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;TD width="50%"&gt;
&lt;P class="p"&gt;The machine account that communicates to the Active Directory connection requires the following permissions:&lt;/P&gt;
&lt;UL id="reference_F19556CAD5C949B58DF89334E2C6255D__ul_sx3_w4c_qx" class="ul"&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_6B619A3339B2426AA28C6A7B242B20B4" class="li"&gt;
&lt;P class="p"&gt;Change password&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_C9B2B4D3ADA040A9BA1ADC117BC3A767" class="li"&gt;
&lt;P class="p"&gt;Read the user and machine objects corresponding to users and machines that are&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_F05564FE3CE341E8BA1888CB2BDFEA1C" class="li"&gt;
&lt;P class="p"&gt;Query Active Directory to get information (for example, trusted domains, alternative UPN suffixes, and so on)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_D797B560586242B0A74B6B8A041D8B9F" class="li"&gt;
&lt;P class="p"&gt;Read the tokenGroups attribute&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="p"&gt;You can precreate the machine account in Active Directory. If the SAM name matches the Cisco appliance hostname, it is located during the join operation and re-used.&lt;/P&gt;
&lt;P class="p"&gt;If there are multiple join operations, multiple machine accounts are maintained inside Cisco , one for each join.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;SECTION class="body refbody"&gt;
&lt;SECTION id="reference_F19556CAD5C949B58DF89334E2C6255D__section_C9AEF96CC3EB4FE29575DEAE0FA74540" class="section"&gt;
&lt;DIV class="tableContainer"&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/SECTION&gt;</description>
    <pubDate>Sat, 04 Dec 2021 22:54:11 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2021-12-04T22:54:11Z</dc:date>
    <item>
      <title>Joining Cisco ISE Node with RODC Active Directory Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/joining-cisco-ise-node-with-rodc-active-directory-issue/m-p/3067910#M23726</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am trying to join my CIsco ISE Nodes to RODC Active Directory and there's an issue when joining.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are there any limitations when joining Cisco ISE to RODC Active Directory?&lt;/P&gt;
&lt;P&gt;Does Cisco ISE needs to join to RWDC Active Directory not RODC?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;*Attached is the log produced when trying to join domain.&lt;/P&gt;
&lt;P&gt;Ps: Customer didnt permit any communication directly to RWDC.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope to hear your response.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/joining-cisco-ise-node-with-rodc-active-directory-issue/m-p/3067910#M23726</guid>
      <dc:creator>Andryan Viryadi Tanamir</dc:creator>
      <dc:date>2019-03-11T07:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Joining Cisco ISE Node with RODC Active Directory Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/joining-cisco-ise-node-with-rodc-active-directory-issue/m-p/4499785#M570943</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Did you able to solve this issue, i have to implement ISE PSN node with RODC, will it work?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 00:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/joining-cisco-ise-node-with-rodc-active-directory-issue/m-p/4499785#M570943</guid>
      <dc:creator>shah.vinit</dc:creator>
      <dc:date>2021-11-09T00:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Joining Cisco ISE Node with RODC Active Directory Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/joining-cisco-ise-node-with-rodc-active-directory-issue/m-p/4513218#M571449</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01101.html#reference_F19556CAD5C949B58DF89334E2C6255D" target="_blank" rel="noopener"&gt;Active Directory Account Permissions Required to Perform Various Operations&lt;/A&gt;&lt;/P&gt;
&lt;H4 id="ariaid-title32" class="title topictitle4"&gt;Active Directory Account Permissions Required to Perform Various Operations&lt;/H4&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;&lt;STRONG&gt;Join Operations&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="50%"&gt;&lt;STRONG&gt;Cisco Machine Accounts&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;
&lt;P class="p"&gt;The join operation requires the following account permissions:&lt;/P&gt;
&lt;UL id="reference_F19556CAD5C949B58DF89334E2C6255D__ul_qx3_w4c_qx" class="ul"&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_BCA59CE71A574D179E905F51D628E21C" class="li"&gt;
&lt;P class="p"&gt;Search Active Directory (to see if a Cisco machine account exists)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_994D03F3E0FE4B1FA75D5E4E361504FF" class="li"&gt;
&lt;P class="p"&gt;Create Cisco machine account to domain (if the machine account does not already exist)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_ED1668CBC5BC4F839E56DACE2B0E42F7" class="li"&gt;
&lt;P class="p"&gt;Set attributes on the new machine account (for example, Cisco machine account password, SPN, dnsHostname)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;TD width="50%"&gt;
&lt;P class="p"&gt;The machine account that communicates to the Active Directory connection requires the following permissions:&lt;/P&gt;
&lt;UL id="reference_F19556CAD5C949B58DF89334E2C6255D__ul_sx3_w4c_qx" class="ul"&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_6B619A3339B2426AA28C6A7B242B20B4" class="li"&gt;
&lt;P class="p"&gt;Change password&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_C9B2B4D3ADA040A9BA1ADC117BC3A767" class="li"&gt;
&lt;P class="p"&gt;Read the user and machine objects corresponding to users and machines that are&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_F05564FE3CE341E8BA1888CB2BDFEA1C" class="li"&gt;
&lt;P class="p"&gt;Query Active Directory to get information (for example, trusted domains, alternative UPN suffixes, and so on)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_F19556CAD5C949B58DF89334E2C6255D__li_D797B560586242B0A74B6B8A041D8B9F" class="li"&gt;
&lt;P class="p"&gt;Read the tokenGroups attribute&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="p"&gt;You can precreate the machine account in Active Directory. If the SAM name matches the Cisco appliance hostname, it is located during the join operation and re-used.&lt;/P&gt;
&lt;P class="p"&gt;If there are multiple join operations, multiple machine accounts are maintained inside Cisco , one for each join.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;SECTION class="body refbody"&gt;
&lt;SECTION id="reference_F19556CAD5C949B58DF89334E2C6255D__section_C9AEF96CC3EB4FE29575DEAE0FA74540" class="section"&gt;
&lt;DIV class="tableContainer"&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Sat, 04 Dec 2021 22:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/joining-cisco-ise-node-with-rodc-active-directory-issue/m-p/4513218#M571449</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-12-04T22:54:11Z</dc:date>
    </item>
  </channel>
</rss>

