<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Migration To New AD Domain in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-migration-to-new-ad-domain/m-p/5008190#M586849</link>
    <description>&lt;P&gt;Found the solution to get ISE to authenticate to the subdomain:&lt;/P&gt;&lt;P&gt;Administration--&amp;gt;Identity Management--&amp;gt;External Identity Sources--&amp;gt;Active Directory--&amp;gt;SiteA.main--&amp;gt;Advanced Settings--&amp;gt;Identity Rewrite--&amp;gt;&amp;lt;choose&amp;gt;Apply the Rewrite Rules Below to modify username:&lt;BR /&gt;If Identity Matches [IDENTITY] Rewrite as [IDENTITY]@SiteA.main.newdomain.com&lt;/P&gt;&lt;P&gt;We are now able to resolve to the new subdomain that we control.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2024 15:34:28 GMT</pubDate>
    <dc:creator>ChuckMcF</dc:creator>
    <dc:date>2024-01-29T15:34:28Z</dc:date>
    <item>
      <title>ISE Migration To New AD Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-migration-to-new-ad-domain/m-p/5006665#M586790</link>
      <description>&lt;P&gt;(Names have been changed for anonymity.)&lt;/P&gt;&lt;P&gt;Background: We have been taken over by a new organization and are in the process of migrating domains in a rather complex SDA deployment. The first planned phase is to migrate all users to the new domain and phase two will be to create a new Fabric in that domain (new DNAC &amp;amp; ISE clusters) then migrate the network and connected users during a scheduled outage to that Fabric. SDA is, and will only be, deployed for devices at our subdomain level. We have full control of ISE, DNAC, the previous domain and the new subdomain. The new organization controls the new forest.&lt;/P&gt;&lt;P&gt;Current domain:&amp;nbsp;original.OldDomain.com&lt;/P&gt;&lt;P&gt;New subdomain (what we control):&amp;nbsp;SiteA.main.newdomain.com&lt;/P&gt;&lt;P&gt;New domain (what we do not control):&amp;nbsp;main.newdomain.com&lt;/P&gt;&lt;P&gt;Issue: I have modified our 802.1x policy sets to include AD groups from "original.OldDomain.com" OR "SiteA.main.newdomain.com". When testing user for all join points, I enter a known good user ID and password from&amp;nbsp;SiteA.main.newdomain.com and here are the results:&lt;BR /&gt;Resolving identity - &amp;lt;known good user&amp;gt;&lt;BR /&gt;Search for matching accounts at join point - original.OldDomain.com&lt;BR /&gt;No matching account found in forest - original.OldDomain.com&lt;BR /&gt;Search for matching accounts at join point - SiteA.main.newdomain.com&lt;BR /&gt;&lt;STRONG&gt;Skipping unavailable forest - main.newdomain.com&lt;/STRONG&gt;&lt;BR /&gt;Identity resolution detected no matching account&lt;BR /&gt;Identity resolution failed - ERROR_NO_SUCH_USER_SOME_DOMAINS_NOT_AVAILABLE&lt;BR /&gt;&lt;BR /&gt;ISE has been joined to&amp;nbsp;SiteA.main.newdomain.com with a service account that has full permission to AD at that level. ISE is also joined to&amp;nbsp;original.OldDomain.com with a different AD account with appropriate permissions. I am confused why it is "skipping the unavailable forest" since we only want ISE to authenticate to the subdomain. Is it possible to authenticate ONLY to the subdomain or does ISE require a service account at the forest level as well? It is going to be extremely difficult to get the forest owners to give us a service account with that level of access so any way around this would be appreciated.&lt;BR /&gt;&lt;BR /&gt;TIA&lt;/P&gt;&lt;P&gt;ChuckMcF&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 20:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-migration-to-new-ad-domain/m-p/5006665#M586790</guid>
      <dc:creator>ChuckMcF</dc:creator>
      <dc:date>2024-01-26T20:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Migration To New AD Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-migration-to-new-ad-domain/m-p/5006935#M586793</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - What ISE version is being used ?&lt;BR /&gt;&amp;nbsp; &amp;nbsp; - Examine the content of&amp;nbsp;&lt;STRONG&gt;show logging application ad_agent.log&lt;BR /&gt;&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp; - Check DNS ; make sure that the&amp;nbsp; new AD servers are known by PTR records on the ISE environment (too)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 08:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-migration-to-new-ad-domain/m-p/5006935#M586793</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-01-27T08:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Migration To New AD Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-migration-to-new-ad-domain/m-p/5008089#M586837</link>
      <description>&lt;P&gt;Apologies - ISE version is 3.2P4. Parsing the log files that you recommended at the moment. Troubleshooting is slower due to working with an outside entity. Will update this thread as it progresses. Currently showing that the "domain&amp;nbsp;marked as offline", which is odd because&amp;nbsp;Admin--&amp;gt;id mgmt--&amp;gt;ext id sources--&amp;gt;AD--&amp;gt;&amp;lt;new domain&amp;gt;--&amp;gt;Diagnostic Tools shows all tests as green.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 12:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-migration-to-new-ad-domain/m-p/5008089#M586837</guid>
      <dc:creator>ChuckMcF</dc:creator>
      <dc:date>2024-01-29T12:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Migration To New AD Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-migration-to-new-ad-domain/m-p/5008190#M586849</link>
      <description>&lt;P&gt;Found the solution to get ISE to authenticate to the subdomain:&lt;/P&gt;&lt;P&gt;Administration--&amp;gt;Identity Management--&amp;gt;External Identity Sources--&amp;gt;Active Directory--&amp;gt;SiteA.main--&amp;gt;Advanced Settings--&amp;gt;Identity Rewrite--&amp;gt;&amp;lt;choose&amp;gt;Apply the Rewrite Rules Below to modify username:&lt;BR /&gt;If Identity Matches [IDENTITY] Rewrite as [IDENTITY]@SiteA.main.newdomain.com&lt;/P&gt;&lt;P&gt;We are now able to resolve to the new subdomain that we control.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 15:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-migration-to-new-ad-domain/m-p/5008190#M586849</guid>
      <dc:creator>ChuckMcF</dc:creator>
      <dc:date>2024-01-29T15:34:28Z</dc:date>
    </item>
  </channel>
</rss>

