<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Integration of ISE-PIC with AD, access denied in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/integration-of-ise-pic-with-ad-access-denied/m-p/4796589#M580595</link>
    <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to integrate ISE-PIC with AD using&amp;nbsp; WMI, user is domain admin so it has already all the permissions.&lt;/P&gt;
&lt;P&gt;Error: access denied&lt;EM&gt; please check credentials, permissions and configure the permissions windows machine for wmi access.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any extra config I need to do in active directory?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Mar 2023 13:49:58 GMT</pubDate>
    <dc:creator>Bledian</dc:creator>
    <dc:date>2023-03-17T13:49:58Z</dc:date>
    <item>
      <title>Integration of ISE-PIC with AD, access denied</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-of-ise-pic-with-ad-access-denied/m-p/4796589#M580595</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to integrate ISE-PIC with AD using&amp;nbsp; WMI, user is domain admin so it has already all the permissions.&lt;/P&gt;
&lt;P&gt;Error: access denied&lt;EM&gt; please check credentials, permissions and configure the permissions windows machine for wmi access.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any extra config I need to do in active directory?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 13:49:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-of-ise-pic-with-ad-access-denied/m-p/4796589#M580595</guid>
      <dc:creator>Bledian</dc:creator>
      <dc:date>2023-03-17T13:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Integration of ISE-PIC with AD, access denied</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-of-ise-pic-with-ad-access-denied/m-p/4796597#M580597</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1286620"&gt;@Bledian&lt;/a&gt;&amp;nbsp; it's very likely that the integration is not working due to the following bug&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz97194" target="_blank"&gt;CSCvz97194&lt;/A&gt;, this is also been documented on the Microsoft side due to the DCOM hardening that took place few days ago&amp;nbsp;&lt;A href="https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c" target="_blank"&gt;https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c&lt;/A&gt;&amp;nbsp; , one thing that you can attempt is to configure another provider such as MS-RPC more info in this link&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216512-configure-evt-based-identity-services-en.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216512-configure-evt-based-identity-services-en.html&lt;/A&gt;&amp;nbsp;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly rate and let me know if that helped you .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 14:01:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-of-ise-pic-with-ad-access-denied/m-p/4796597#M580597</guid>
      <dc:creator>Rodrigo Diaz</dc:creator>
      <dc:date>2023-03-17T14:01:23Z</dc:date>
    </item>
  </channel>
</rss>

