<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 3 cannot join in AD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-cannot-join-in-ad/m-p/5337538#M598489</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1929025"&gt;@mmots&lt;/a&gt;&amp;nbsp;have you read the following and made the recommended changes?&lt;/P&gt;
&lt;P class="pChart_bodyCMT" style="font-style: normal; font-variant: normal; font-weight: normal; text-align: left; text-decoration: none; text-indent: 0pt; text-transform: none; margin: 3pt;"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: Currently, Cisco ISE integration with Microsoft Windows Active Directory 2025 requires configuration changes in the Active Directory Domain Controller. For more information, see &lt;A href="https://bst.cisco.com/bugsearch/bug/CSCwn62873" target="_blank" rel="noopener"&gt;CSCwn62873&lt;/A&gt;.&lt;/P&gt;
&lt;P class="pChart_bodyCMT" style="font-style: normal; font-variant: normal; font-weight: normal; text-align: left; text-decoration: none; text-indent: 0pt; text-transform: none; margin: 3pt;"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/release_notes/cisco-ise-release-notes-35.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/release_notes/cisco-ise-release-notes-35.html&lt;/A&gt;&lt;/P&gt;
&lt;P class="pChart_bodyCMT" style="font-style: normal; font-variant: normal; font-weight: normal; text-align: left; text-decoration: none; text-indent: 0pt; text-transform: none; margin: 3pt;"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Oct 2025 12:48:44 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2025-10-10T12:48:44Z</dc:date>
    <item>
      <title>ISE 3 cannot join in AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-cannot-join-in-ad/m-p/5337537#M598488</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi, we are testing ISE 3.5. We aren't able to join to AD , on tcp dump we found that the join stop at:&amp;nbsp;&lt;/P&gt;&lt;P&gt;271 1.817231 10.0.10.10 10.0.10.15 SAMR 166 ChangePasswordUser2 response, STATUS_ACCESS_DENIED, Error: STATUS_ACCESS_DENIED&lt;/P&gt;&lt;P&gt;We use 2 DC controller with WS2025. Such last try, we add the join user to "domain admin". We try also to grand FULL CONTROL to the user, delete the machine, reset ISE to factory default but the join still fail. Before this packet, there are a lot of other SAMR successfully exchange between ISE and DC. This is the join log (machine existing during this join)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error Description: Access is denied&lt;/P&gt;&lt;P&gt;Support Details...&lt;BR /&gt;Error Name: ERROR_ACCESS_DENIED&lt;BR /&gt;Error Code: 5&lt;/P&gt;&lt;P&gt;Detailed Log:&lt;BR /&gt;14:37:09 Joining to domain ITTS.mydomain.COM using user ise_join_svc@itts.mydomain.com&lt;BR /&gt;14:37:09 Searching for DC in domain ITTS.mydomain.COM&lt;BR /&gt;14:37:09 Found DC: Dcmydomain02.itts.mydomain.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name&lt;BR /&gt;14:37:09 Checking credentials for user ise_join_svc@itts.mydomain.com&lt;BR /&gt;14:37:09 Getting TGT for account ise_join_svc@ITTS.mydomain.COM&lt;BR /&gt;14:37:09 TGT for account ise_join_svc@ITTS.mydomain.COM was retrieved successfully&lt;BR /&gt;14:37:09 Credentials for user ise_join_svc@itts.mydomain.com were verified&lt;BR /&gt;14:37:09 Searching for DC in domain ITTS.mydomain.COM&lt;BR /&gt;14:37:09 Found DC: Dcmydomain02.itts.mydomain.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name&lt;BR /&gt;14:37:09 Generating account name for ISE machine in ITTS.mydomain.COM&lt;BR /&gt;14:37:09 Searching for an existing machine account&lt;BR /&gt;14:37:09 Searching object by filter : (&amp;amp;(objectCategory=computer)(servicePrincipalName=host/tsmxsvise01.itts.mydomain.com))&lt;BR /&gt;14:37:09 Account: tsmxsvise01 was found&lt;BR /&gt;14:37:09 ISE Machine account name is : TSMXSVISE01$&lt;BR /&gt;14:37:09 Creating machine account TSMXSVISE01$&lt;BR /&gt;14:37:09 Connecting to AD using DC Dcmydomain02.itts.mydomain.com&lt;BR /&gt;14:37:09 Connection to Dcmydomain02.itts.mydomain.com established&lt;BR /&gt;14:37:09 Opening domain mydomain&lt;BR /&gt;14:37:09 Domain mydomain was opened successfully&lt;BR /&gt;14:37:09 Machine account: TSMXSVISE01$ already exists , opening account.&lt;BR /&gt;14:37:09 Machine account TSMXSVISE01$ was opened successfully&lt;BR /&gt;14:37:09 Querying account TSMXSVISE01$ info&lt;BR /&gt;14:37:09 Account TSMXSVISE01$ information was retrieved successfully&lt;BR /&gt;14:37:09 Enabling machine account : TSMXSVISE01$&lt;BR /&gt;14:37:09 Machine account TSMXSVISE01$ was enabled successfully&lt;BR /&gt;14:37:09 Setting password for account : TSMXSVISE01$&lt;BR /&gt;14:37:09 Password for account: TSMXSVISE01$ was setted successfully&lt;BR /&gt;14:37:09 Account TSMXSVISE01$ was created successfully&lt;BR /&gt;14:37:09 Verify that machine account: TSMXSVISE01$ is accessable&lt;BR /&gt;14:37:09 Searching object by filter : (&amp;amp;(objectClass=computer)(sAMAccountName=TSMXSVISE01$))&lt;BR /&gt;14:37:09 Machine account TSMXSVISE01$ is accessable with DN: CN=TSMXSVISE01,OU=ISE_Servers,DC=itts,DC=mydomain,DC=com&lt;BR /&gt;14:37:09 Setting attributes to object: CN=TSMXSVISE01,OU=ISE_Servers,DC=itts,DC=mydomain,DC=com&lt;BR /&gt;14:37:09 Setting attribute dNSHostName : tsmxsvise01.itts.mydomain.com to object&lt;BR /&gt;14:37:09 Attribute dNSHostName : tsmxsvise01.itts.mydomain.com was setted successfully&lt;BR /&gt;14:37:09 Setting attribute servicePrincipalName : HOST/tsmxsvise01.itts.mydomain.com to object&lt;BR /&gt;14:37:09 Attribute servicePrincipalName : HOST/tsmxsvise01.itts.mydomain.com was setted successfully&lt;BR /&gt;14:37:09 Setting attribute servicePrincipalName : HTTP/tsmxsvise01 to object&lt;BR /&gt;14:37:09 Attribute servicePrincipalName : HTTP/tsmxsvise01 was setted successfully&lt;BR /&gt;14:37:09 Setting attribute operatingSystem : Cisco Identity Services Engine to object&lt;BR /&gt;14:37:09 Attribute operatingSystem : Cisco Identity Services Engine was setted successfully&lt;BR /&gt;14:37:09 Setting attribute operatingSystemVersion : 3.5.0.527 to object&lt;BR /&gt;14:37:09 Attribute operatingSystemVersion : 3.5.0.527 was setted successfully&lt;BR /&gt;14:37:09 Setting attribute userAccountControl : 4096 to object&lt;BR /&gt;14:37:09 Attribute userAccountControl : 4096 was setted successfully&lt;BR /&gt;14:37:09 Setting attribute msDS-SupportedEncryptionTypes : 28 to object&lt;BR /&gt;14:37:09 Attribute msDS-SupportedEncryptionTypes : 28 was setted successfully&lt;BR /&gt;14:37:09 Attributes was setted successfully&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 12:40:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-cannot-join-in-ad/m-p/5337537#M598488</guid>
      <dc:creator>mmots</dc:creator>
      <dc:date>2025-10-10T12:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 cannot join in AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-cannot-join-in-ad/m-p/5337538#M598489</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1929025"&gt;@mmots&lt;/a&gt;&amp;nbsp;have you read the following and made the recommended changes?&lt;/P&gt;
&lt;P class="pChart_bodyCMT" style="font-style: normal; font-variant: normal; font-weight: normal; text-align: left; text-decoration: none; text-indent: 0pt; text-transform: none; margin: 3pt;"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: Currently, Cisco ISE integration with Microsoft Windows Active Directory 2025 requires configuration changes in the Active Directory Domain Controller. For more information, see &lt;A href="https://bst.cisco.com/bugsearch/bug/CSCwn62873" target="_blank" rel="noopener"&gt;CSCwn62873&lt;/A&gt;.&lt;/P&gt;
&lt;P class="pChart_bodyCMT" style="font-style: normal; font-variant: normal; font-weight: normal; text-align: left; text-decoration: none; text-indent: 0pt; text-transform: none; margin: 3pt;"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/release_notes/cisco-ise-release-notes-35.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/release_notes/cisco-ise-release-notes-35.html&lt;/A&gt;&lt;/P&gt;
&lt;P class="pChart_bodyCMT" style="font-style: normal; font-variant: normal; font-weight: normal; text-align: left; text-decoration: none; text-indent: 0pt; text-transform: none; margin: 3pt;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 12:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-cannot-join-in-ad/m-p/5337538#M598489</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-10-10T12:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 cannot join in AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-cannot-join-in-ad/m-p/5337545#M598491</link>
      <description>&lt;P&gt;Hi, many thanks. We forgotten to change this:&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Under the "Options" section, choose "Allow all change password RPC methods."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 13:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-cannot-join-in-ad/m-p/5337545#M598491</guid>
      <dc:creator>mmots</dc:creator>
      <dc:date>2025-10-10T13:12:38Z</dc:date>
    </item>
  </channel>
</rss>

