<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Protected Accounts not supported with ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4807009#M580912</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It's for ISE administration. The user isn't able to login in to the ISE GUI, the user is able to login within other applications.&lt;/P&gt;
&lt;P&gt;We get this logs from the ISE:&lt;/P&gt;
&lt;P&gt;Event: Administrator authentication failed&lt;/P&gt;
&lt;P&gt;Event Details: Authentication failed due to invalid user or password, or account is disabled/locked&lt;/P&gt;
&lt;P&gt;Also if we test the user from ISE within Test User Authentication with Authetication Type: MS-RPC, we get this log:&lt;BR /&gt;RFC Logon request faildes = STATUS_ACCOUNT_RESTRICTION,ERROR_LOGON_FAILURE&lt;/P&gt;
&lt;P&gt;I'm not familiar with AD and we don't handle it. What we know is that this user is a protected user.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2023 23:00:16 GMT</pubDate>
    <dc:creator>flobo</dc:creator>
    <dc:date>2023-04-03T23:00:16Z</dc:date>
    <item>
      <title>AD Protected Accounts not supported with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4599390#M574350</link>
      <description>&lt;P&gt;Windows domain admin users are not able to authenticate via ISE with AD when logging on to troubleshoot a remote PC. It looks like this is due to a bug "AD Protected Accounts not supported with ISE."&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy39859" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy39859&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I imagine that this must be causing problems with the workflow of other organizations as well. Has anyone found a creative workaround?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 16:27:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4599390#M574350</guid>
      <dc:creator>arennick</dc:creator>
      <dc:date>2022-04-25T16:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: AD Protected Accounts not supported with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4804189#M580822</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Does anyone have more information regarding AD protected users? I have a customer that is facing problems authentication with this type of users. In the bug there isn't any information.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 20:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4804189#M580822</guid>
      <dc:creator>flobo</dc:creator>
      <dc:date>2023-03-29T20:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: AD Protected Accounts not supported with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4806229#M580892</link>
      <description>&lt;P&gt;Please be very specific about your scenario.&lt;/P&gt;
&lt;P&gt;Is this an 802.1X authentication on a Windows computer?&lt;/P&gt;
&lt;P&gt;What is the Windows group that the user is a member of that is not working?&lt;/P&gt;
&lt;P&gt;What is the specific error in the ISE LiveLog?&lt;/P&gt;
&lt;P&gt;&lt;LI-MESSAGE title="How to Ask The Community for Help" uid="3704356" url="https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/m-p/3704356#U3704356" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 03:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4806229#M580892</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-04-03T03:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: AD Protected Accounts not supported with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4807009#M580912</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It's for ISE administration. The user isn't able to login in to the ISE GUI, the user is able to login within other applications.&lt;/P&gt;
&lt;P&gt;We get this logs from the ISE:&lt;/P&gt;
&lt;P&gt;Event: Administrator authentication failed&lt;/P&gt;
&lt;P&gt;Event Details: Authentication failed due to invalid user or password, or account is disabled/locked&lt;/P&gt;
&lt;P&gt;Also if we test the user from ISE within Test User Authentication with Authetication Type: MS-RPC, we get this log:&lt;BR /&gt;RFC Logon request faildes = STATUS_ACCOUNT_RESTRICTION,ERROR_LOGON_FAILURE&lt;/P&gt;
&lt;P&gt;I'm not familiar with AD and we don't handle it. What we know is that this user is a protected user.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 23:00:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4807009#M580912</guid>
      <dc:creator>flobo</dc:creator>
      <dc:date>2023-04-03T23:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: AD Protected Accounts not supported with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4810620#M581027</link>
      <description>&lt;P&gt;Ah, ok, thank you for those details! That helps!&lt;/P&gt;
&lt;P&gt;Since this is a known bug, perhaps by using a different AD Administrator Group that those same admins are members of?&lt;/P&gt;
&lt;P&gt;I show how to configure the mapping of AD groups to ISE Admin Groups in&lt;/P&gt;
&lt;H3 id="ise-initial-setup-and-operations-20220301" data-source-line="1354"&gt;▷&amp;nbsp;&lt;A title="https://youtu.be/Y6F6XCLYUWA" href="https://youtu.be/Y6F6XCLYUWA" data-from-md="" target="_blank"&gt;ISE Initial Setup and Operations&lt;/A&gt;&amp;nbsp;&lt;/H3&gt;
&lt;P data-source-line="1368"&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2033s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2033s" data-from-md="" target="_blank"&gt;33:53&lt;/A&gt;&amp;nbsp;RBAC Policy&lt;BR /&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2048s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2048s" data-from-md="" target="_blank"&gt;34:08&lt;/A&gt;&amp;nbsp;Admin Groups and Roles&lt;BR /&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2138s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2138s" data-from-md="" target="_blank"&gt;35:38&lt;/A&gt;&amp;nbsp;Admin Users&lt;BR /&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2185s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2185s" data-from-md="" target="_blank"&gt;36:25&lt;/A&gt;&amp;nbsp;Use Active Directory External Identity Store for Admin Groups&lt;BR /&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2402s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2402s" data-from-md="" target="_blank"&gt;40:02&lt;/A&gt;&amp;nbsp;Map AD Groups to ISE Admin Groups&lt;BR /&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2536s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=2536s" data-from-md="" target="_blank"&gt;42:16&lt;/A&gt;&amp;nbsp;NetworkDeviceAdmin Role Test&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Apr 2023 22:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4810620#M581027</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-04-08T22:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: AD Protected Accounts not supported with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4811804#M581057</link>
      <description>&lt;P&gt;Test message 3&lt;/P&gt;
&lt;P&gt;&lt;LI-MESSAGE title="how to bypass the flash" uid="4376981" url="https://community.cisco.com/t5/%E7%BD%91%E7%BB%9C%E6%96%87%E6%A1%A3/how-to-bypass-the-flash/m-p/4376981#U4376981" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 10:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4811804#M581057</guid>
      <dc:creator>neaugust</dc:creator>
      <dc:date>2023-04-11T10:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: AD Protected Accounts not supported with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4811960#M581077</link>
      <description>&lt;P&gt;The AD team modified the users to be "normal users", now these users can authenticate and login ISE without problems.&lt;/P&gt;
&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 14:55:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4811960#M581077</guid>
      <dc:creator>flobo</dc:creator>
      <dc:date>2023-04-11T14:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: AD Protected Accounts not supported with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4918118#M583913</link>
      <description>&lt;P&gt;It is painful for us too. For security reasons ( some of them&amp;nbsp; are nicely described here&amp;nbsp;&lt;A href="https://petri.com/windows-server-protected-privileged-accounts/" target="_blank"&gt;Windows Server: Protected Privileged Accounts - Petri IT Knowledgebase&lt;/A&gt;&amp;nbsp;), our admins have administrative accounts in Protected users group. It means, that authentication over MS-RPC is prohibited for that users. Since ISE needs MS-RPC " by design"(&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy39859" target="_blank"&gt;CSCvy39859 : Bug Search Tool (cisco.com)&lt;/A&gt;) for communicating with AD, those users could not be authenticated. I Think, giving up higher security standard ( recommended by Microsoft in connection with&amp;nbsp; tiering) by moving admins from protected accounts to standard accounts is no solution. It would be really nice, if Cisco solved this issue.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 13:45:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-protected-accounts-not-supported-with-ise/m-p/4918118#M583913</guid>
      <dc:creator>PetrVyhlidal1489</dc:creator>
      <dc:date>2023-09-05T13:45:18Z</dc:date>
    </item>
  </channel>
</rss>

