<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can we join Single Cisco ISE node to multiple Active Directory For in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-we-join-single-cisco-ise-node-to-multiple-active-directory/m-p/5240596#M593943</link>
    <description>&lt;P&gt;Is there any way I can break the trust / prevent one domain join point from looking for accounts in other domains that have a trust?&lt;/P&gt;&lt;P&gt;I set up a new AD join point, and the account that was previously getting grabbed by the wrong domain and coming back as disabled is now working.&amp;nbsp; The new problem, however, is that new join point is allowing authentication from multiple domains (since there are trusts between them) but I did not set up the AD groups for that join point, so now the accounts are failing authorization.&amp;nbsp; I'm looking at having to add all the groups across every domain into each join point so they can be authorized regardless of which join point authenticates them.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That explanation is getting a little wordy, yikes.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Dec 2024 21:18:31 GMT</pubDate>
    <dc:creator>asdraper</dc:creator>
    <dc:date>2024-12-24T21:18:31Z</dc:date>
    <item>
      <title>Can we join Single Cisco ISE node to multiple Active Directory Forest/domains same time</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-join-single-cisco-ise-node-to-multiple-active-directory/m-p/4416882#M567803</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can some one please help to get an answer as mentioned in Subject if we can join Single ISE Node to Multiple Active Directory Domain/Forest same time. I am aware Cisco ISE support upto 50 Active Directory domain joined but i am not sure if we can join Single ISE node to Multiple Active Directory forest/Domain same time or not. Can some one please help me on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 15:41:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-join-single-cisco-ise-node-to-multiple-active-directory/m-p/4416882#M567803</guid>
      <dc:creator>aaggarwal23</dc:creator>
      <dc:date>2021-06-11T15:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can we join Single Cisco ISE node to multiple Active Directory Forest/domains same time</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-join-single-cisco-ise-node-to-multiple-active-directory/m-p/4417073#M567805</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;
&lt;P&gt;"50 Active Directory domain join points" means 50 unique domains/forests or 50 different places within a single domain.&lt;/P&gt;
&lt;P&gt;From the ISE Admin Guide:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_30_asset_visibility.html?bookSearch=true#reference_2DED94723F2248B99730D5393E73AB56" target="_blank" rel="noopener"&gt;Configure Active Directory as an External Identity Source&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_30_asset_visibility.html?bookSearch=true#concept_2D3FDBAD9F50469BA09704BF409209C7" target="_blank" rel="noopener"&gt;Support for Active Directory Multi-Join Configuration&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 23:53:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-join-single-cisco-ise-node-to-multiple-active-directory/m-p/4417073#M567805</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-06-11T23:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can we join Single Cisco ISE node to multiple Active Directory For</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-join-single-cisco-ise-node-to-multiple-active-directory/m-p/5240596#M593943</link>
      <description>&lt;P&gt;Is there any way I can break the trust / prevent one domain join point from looking for accounts in other domains that have a trust?&lt;/P&gt;&lt;P&gt;I set up a new AD join point, and the account that was previously getting grabbed by the wrong domain and coming back as disabled is now working.&amp;nbsp; The new problem, however, is that new join point is allowing authentication from multiple domains (since there are trusts between them) but I did not set up the AD groups for that join point, so now the accounts are failing authorization.&amp;nbsp; I'm looking at having to add all the groups across every domain into each join point so they can be authorized regardless of which join point authenticates them.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That explanation is getting a little wordy, yikes.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 21:18:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-join-single-cisco-ise-node-to-multiple-active-directory/m-p/5240596#M593943</guid>
      <dc:creator>asdraper</dc:creator>
      <dc:date>2024-12-24T21:18:31Z</dc:date>
    </item>
  </channel>
</rss>

