<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Join ISE to AD domain in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/join-ise-to-ad-domain/m-p/4739578#M578841</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/224506"&gt;@dgaikwad&lt;/a&gt; the user account does not need domain admin rights to join the ISE node to AD.&lt;/P&gt;
&lt;P&gt;Once the ISE node is joined to the AD domain, a machine account is created - the link below lists the permissions required for that machine account, if you wish to restrict its permissions.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217351-ad-integration-for-cisco-ise-gui-and-cli.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217351-ad-integration-for-cisco-ise-gui-and-cli.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Dec 2022 10:34:37 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-12-15T10:34:37Z</dc:date>
    <item>
      <title>Join ISE to AD domain</title>
      <link>https://community.cisco.com/t5/network-access-control/join-ise-to-ad-domain/m-p/4739574#M578840</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" color="#003366"&gt;Hi Experts,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" color="#003366"&gt;We are in the process of joining a crashed back to AD.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" color="#003366"&gt;Issue:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" color="#003366"&gt;AD user has certain rights removed due to security concerns.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" color="#003366"&gt;It was later determined that this user will need to have domain admin rights to be able to join AD.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="helvetica" color="#003366"&gt;AD team has a concern regarding this assignment of rights for the user.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" color="#003366"&gt;The question is does this user utilise LSA (Local Security Authority) to perform read/write operations in AD?&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="helvetica" color="#003366"&gt;Due to this concern we are stuck since 2 months and going in circles...!&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="helvetica" color="#003366"&gt;Any suggestions?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 10:41:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/join-ise-to-ad-domain/m-p/4739574#M578840</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2022-12-15T10:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Join ISE to AD domain</title>
      <link>https://community.cisco.com/t5/network-access-control/join-ise-to-ad-domain/m-p/4739578#M578841</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/224506"&gt;@dgaikwad&lt;/a&gt; the user account does not need domain admin rights to join the ISE node to AD.&lt;/P&gt;
&lt;P&gt;Once the ISE node is joined to the AD domain, a machine account is created - the link below lists the permissions required for that machine account, if you wish to restrict its permissions.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217351-ad-integration-for-cisco-ise-gui-and-cli.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217351-ad-integration-for-cisco-ise-gui-and-cli.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 10:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/join-ise-to-ad-domain/m-p/4739578#M578841</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-15T10:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Join ISE to AD domain</title>
      <link>https://community.cisco.com/t5/network-access-control/join-ise-to-ad-domain/m-p/4740326#M578857</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" color="#003366"&gt;Thanks for the info.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" color="#003366"&gt;I was going through the document, and the document does talk about mandatory domain rights:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" color="#003366"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dgaikwad_0-1671176251510.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/171191iF96C0EE8EE9B65A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dgaikwad_0-1671176251510.png" alt="dgaikwad_0-1671176251510.png" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" color="#003366"&gt;Thus there is this concern if the LSA is being utilised to make changes to the AD domain.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 07:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/join-ise-to-ad-domain/m-p/4740326#M578857</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2022-12-16T07:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Join ISE to AD domain</title>
      <link>https://community.cisco.com/t5/network-access-control/join-ise-to-ad-domain/m-p/4756554#M579278</link>
      <description>&lt;P&gt;The issue has been resolved and confirmed that domain rights are needed to join AD.&lt;BR /&gt;The domain rights are only utilised during the creation of the machine account in AD, post that domain rights are not needed.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 07:31:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/join-ise-to-ad-domain/m-p/4756554#M579278</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2023-01-18T07:31:41Z</dc:date>
    </item>
  </channel>
</rss>

