<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE &amp;quot;Unknown&amp;quot; Super Admin Member in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-quot-unknown-quot-super-admin-member/m-p/5094715#M589320</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am tasked with the initial configuration of an ISE deployment (primary/secondary).&lt;/P&gt;
&lt;P&gt;During the AD join and enabling AD admins to access the GUI via External Identity Source I see two members in the Admin group -&amp;gt; Super Admin.&lt;/P&gt;
&lt;P&gt;First -&amp;gt; admin2 (this is the admin user added by the customer during installation)&lt;/P&gt;
&lt;P&gt;Second -&amp;gt; ~internal-edda-ers-user991&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know this user and it looks like some kind of "system API account".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So. for now I'm clueless and I can't find any helpful information.&lt;/P&gt;
&lt;P&gt;Can anyone explain to me how this user is created?&lt;/P&gt;
&lt;P&gt;What service does this account use?&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2024 20:03:20 GMT</pubDate>
    <dc:creator>alex.f.</dc:creator>
    <dc:date>2024-05-08T20:03:20Z</dc:date>
    <item>
      <title>Cisco ISE "Unknown" Super Admin Member</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-quot-unknown-quot-super-admin-member/m-p/5094715#M589320</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am tasked with the initial configuration of an ISE deployment (primary/secondary).&lt;/P&gt;
&lt;P&gt;During the AD join and enabling AD admins to access the GUI via External Identity Source I see two members in the Admin group -&amp;gt; Super Admin.&lt;/P&gt;
&lt;P&gt;First -&amp;gt; admin2 (this is the admin user added by the customer during installation)&lt;/P&gt;
&lt;P&gt;Second -&amp;gt; ~internal-edda-ers-user991&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know this user and it looks like some kind of "system API account".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So. for now I'm clueless and I can't find any helpful information.&lt;/P&gt;
&lt;P&gt;Can anyone explain to me how this user is created?&lt;/P&gt;
&lt;P&gt;What service does this account use?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 20:03:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-quot-unknown-quot-super-admin-member/m-p/5094715#M589320</guid>
      <dc:creator>alex.f.</dc:creator>
      <dc:date>2024-05-08T20:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE "Unknown" Super Admin Member</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-quot-unknown-quot-super-admin-member/m-p/5094801#M589323</link>
      <description>&lt;P&gt;Those are local admin accounts that are not created as part of a default ISE install - looks like those were manually created.&lt;/P&gt;
&lt;P&gt;They also have nothing to do with your AD integration. Are you asking whether to remove them, or what they might be for?&lt;/P&gt;
&lt;P&gt;The "ers" in the 2nd username does seem to relate to some kind of API user. There is an ERS User Group that limits the access for those types of accounts - you don't want people logging in with that account - it should be limited to making REST API calls only.&lt;/P&gt;
&lt;P&gt;You can have a mix of local ISE Admin users, as well as AD Admin users. During the ISE Web GUI login, the default screen will display option to login with the AD Join accounts, but you can select "local accounts" from the drop down. You will always have at least one local ISE Admin user account to log into the GUI in the event that the AD join is not working. Or as a last resort option. It's also a useful account for things like Cisco DNAC/ISE integration. But you can create multiple ISE local admin accounts and it's a good practice to have&lt;/P&gt;
&lt;P&gt;During an ISE install, the first (default) ISE user is called 'admin'. Perhaps someone thought they were being more security conscious and chose the username 'admin2'. But that is just a guess.&lt;/P&gt;
&lt;P&gt;As for the second username, perhaps someone in your organisation is making API calls to ISE, using the ERS interface. You should be able to run an Operations audit report to see if that user has logged in in the last 30 days.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 21:29:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-quot-unknown-quot-super-admin-member/m-p/5094801#M589323</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-05-08T21:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE "Unknown" Super Admin Member</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-quot-unknown-quot-super-admin-member/m-p/5094842#M589328</link>
      <description>&lt;P&gt;Actually, there are some internal Super Admin user accounts that are created automatically in newer versions of ISE for some of the more recent feature enhancements. Here is an example screenshot from my ISE 3.2 patch 5 instance:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-05-09 at 8.55.17 AM.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/217851iCC78BACA083293B5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-05-09 at 8.55.17 AM.png" alt="Screenshot 2024-05-09 at 8.55.17 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The 'edda' reference is related to the pxGrid Direct feature and the 'mctrust' reference is related to the Meraki Sync Service feature. I believe both of these functions run as Docker containers, so I suspect these are internal admin accounts used for authentication of internal communications related to those container microservices.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 23:02:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-quot-unknown-quot-super-admin-member/m-p/5094842#M589328</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-05-08T23:02:59Z</dc:date>
    </item>
  </channel>
</rss>

