<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, According to the ACS 5.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554546#M89600</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to the ACS 5.2 user guide, ACS 5.2 does not support windows 2012R2 servers. Here are the list of supported OS:&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; line-height: normal;"&gt;ACS supports these AD domains:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;•&lt;/SPAN&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;" width="19" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;Windows Server 2003&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;•&lt;/SPAN&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;" width="19" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;Windows Server 2003 R2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;•&lt;/SPAN&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;" width="19" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;Windows Server 2008&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;•&lt;/SPAN&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;" width="19" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;Windows Server 2008 R2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-2/user/guide/acsuserguide/users_id_stores.html#wp1248491&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However ACS 5.5 with the latest patch does support the windows 2012R2 :&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; line-height: normal;"&gt;ACS supports these AD domains:&lt;/P&gt;&lt;UL style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal;"&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2003&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2003 R2&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2008&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2008 R2&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2012&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2012 R2 is supported after installing ACS 5.5 patch 1.&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/user/guide/acsuserguide/users_id_stores.html#pgfId-1321235&lt;/LI&gt;&lt;/UL&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;So you would need to upgrade the ACS to the latest version of ACS 5.5 in order for the AD integration to work.&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;To check the supported upgrade path, you can go to&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/release/notes/acs_55_rn.html#pgfId-284251&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Kush&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jul 2014 10:32:05 GMT</pubDate>
    <dc:creator>kushsriva</dc:creator>
    <dc:date>2014-07-10T10:32:05Z</dc:date>
    <item>
      <title>Active Directory operation has failed because of an unspecified error in the ACS (after migration to Server 2012 R2 Domain Controllers)</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554542#M89587</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are experiencing an inability to authenticate our wireless client devices via Cisco ACS connected to Active Directory. &amp;nbsp;We are getting the following errors in ACS:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial; font-size: 13px; line-height: normal; white-space: nowrap;"&gt;24444 Active Directory operation has failed because of an unspecified error in the ACS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial; font-size: 13px; line-height: normal; white-space: nowrap;"&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial; font-size: 13px; line-height: normal; white-space: nowrap;"&gt;11051 RADIUS packet contains invalid state attribute&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial; font-size: 13px; line-height: normal; white-space: nowrap;"&gt;This seems to have started after we migrated from Windows Server 2008 R2 Domain Controllers to Windows Server 2012 R2 Domain Controllers. &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial; font-size: 13px; line-height: normal; white-space: nowrap;"&gt;Is there some sort of compatibility issue that we might be running into? &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;We are running ACS Version:&lt;/SPAN&gt;5.2.0.26.11&lt;/P&gt;&lt;P&gt;What do you think? &amp;nbsp;Our VPN Connections using this same ACS device and Domain Controllers seem to work just fine, but no one can authenticate to our wireless network. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Under the active directory Identity store, Active Directory shows connected to the domain and a test result shows the connection test passed. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554542#M89587</guid>
      <dc:creator>NPT_2</dc:creator>
      <dc:date>2019-03-11T04:51:17Z</dc:date>
    </item>
    <item>
      <title>11051 RADIUS packet contains</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554543#M89590</link>
      <description>&lt;DIV class="bugTitle"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-size: 13px;"&gt;11051 RADIUS packet contains invalid state attribute&lt;/SPAN&gt;&lt;/STRONG&gt; :&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="bugTitle"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="bugTitle"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;System Created AD attributes should be protected&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="bugId"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;CSCuf26657&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="sectionHeader bugDescription"&gt;&lt;DIV class="downArrowImage" id="descriptionArrowImage" tabindex="21" title="Expand collapse description"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="title"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;A name="description" style="text-decoration:none"&gt;Description&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="releaseNoteText"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;B&gt;Symptom:&lt;/B&gt;&lt;BR /&gt;&lt;BR /&gt;User create attributes have the potential to overwrite system created ones changing the data type from boolean to string, causing authentication attempts to AD to fail. With the error messages below.&lt;BR /&gt;Authentication failed : 11051 RADIUS packet contains invalid state attribute&lt;BR /&gt;RADIUS Request dropped : 12315 PEAP inner method finished with failure&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Conditions:&lt;/B&gt;&lt;BR /&gt;&lt;BR /&gt;A user created attribute can overwrite a system created attribute, if a system created attribute exists with the same name. The user created attribute 'IdentityAccessRestricted' overwrote the system created one changing the data type from Boolean to string, causing authentication attempts to AD to fail.&lt;BR /&gt;&lt;BR /&gt;IdentityAccessRestricted is a system created attribute that is created when an ISE node joins AD. If a duplicate attribute is created under Administration&amp;gt;External Identity Sources&amp;gt;Active Directory&amp;gt;Attributes, It will overwrite the data type changing the value from boolean to string.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Workaround:&lt;/B&gt;&lt;BR /&gt;1. Leave AD&lt;BR /&gt;2. Delete the AD connection&lt;BR /&gt;3. Rejoin AD&lt;BR /&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;BR /&gt;Restore from a backup.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="releaseNoteText"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="releaseNoteText"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-size: 13px;"&gt;24444 Active Directory operation has failed because of an unspecified error in the ACS&lt;/SPAN&gt;&lt;/STRONG&gt; : &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="releaseNoteText"&gt;&lt;DIV class="bugTitle"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;ACS 5.x random 24429 and 24444 AD failures&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="bugId"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;CSCuh59288&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="sectionHeader bugDescription"&gt;&lt;DIV class="downArrowImage" id="descriptionArrowImage" tabindex="21" title="Expand collapse description"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="title"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;A name="description" style="text-decoration:none"&gt;Description&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;B&gt;Symptom:&lt;/B&gt;&lt;BR /&gt;We are seeing some authentications fail with either of the following errors:&lt;BR /&gt;24429 Could not establish connection with Active Directory&lt;BR /&gt;24444 Active Directory operation has failed because of an unspecified error in the ACS&lt;BR /&gt;&lt;BR /&gt;The failures are totally random.&lt;BR /&gt;&lt;BR /&gt;24444 errors usually occurred for users that typed the wrong password or for usernames that did not exist in AD&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Conditions:&lt;/B&gt;&lt;BR /&gt;ACS 5.3 patch 6&lt;BR /&gt;&lt;BR /&gt;ACS is incorrectly interpreting the response it receives from AD. Rather than reading the response as a failure of the authentication attempt, the ACS is reading the response as a failure of the AD process/failure of connectivity to AD&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Workaround:&lt;/B&gt;&lt;BR /&gt;N/A&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Jul 2014 09:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554543#M89590</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2014-07-04T09:23:36Z</dc:date>
    </item>
    <item>
      <title>The problem is these 2</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554544#M89593</link>
      <description>&lt;P&gt;The problem is these 2 messages just started popping up when we changed from AD Win2008R2 DC's to Win2012R2 DC's. &amp;nbsp;This appears to be preventing all wireless connections from our wireless clients on all AP's across our network. &amp;nbsp;On the plus side it is not affecting our VPN connectivity that uses the same ACS server for authentication. &amp;nbsp;That being said:&lt;/P&gt;&lt;P&gt;1. &amp;nbsp;I'm going to try disjoining ACS from AD and then rejoining it to see if it fixes the problem. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. &amp;nbsp;However, I'm thinking that version 5.2 of ACS has some sort of compatibility issue with Windows Server 2012 R2 and I will have to upgrade to a newer version. &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone confirm #2? &amp;nbsp;If so, what version do I need to upgrade ACS to in order to get around this issue if this is the root cause? &amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm thinking I'm likely going to have to open a TAC case in the morning if no can confirm these theories. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2014 02:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554544#M89593</guid>
      <dc:creator>NPT_2</dc:creator>
      <dc:date>2014-07-07T02:59:22Z</dc:date>
    </item>
    <item>
      <title>Disjoining and rejoining ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554545#M89596</link>
      <description>&lt;P&gt;Disjoining and rejoining ACS from AD unfortunately did nothing to fix the problem. &amp;nbsp;&lt;/P&gt;&lt;P&gt;I then decided to upgrade to version 5.4. &amp;nbsp;This upgrade was incredibly slow and after it completed I still was unable to authenticate to the wireless network. &amp;nbsp;&lt;/P&gt;&lt;P&gt;I took one last chance and upgraded to the latest 5.5.0.46 ACS Software. &amp;nbsp;Miraculously this fixed the problem and the authentication errors went away and clients are now able to connect to and authenticate to the wireless network without issue. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jim&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2014 22:06:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554545#M89596</guid>
      <dc:creator>NPT_2</dc:creator>
      <dc:date>2014-07-07T22:06:26Z</dc:date>
    </item>
    <item>
      <title>Hi, According to the ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554546#M89600</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to the ACS 5.2 user guide, ACS 5.2 does not support windows 2012R2 servers. Here are the list of supported OS:&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; line-height: normal;"&gt;ACS supports these AD domains:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;•&lt;/SPAN&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;" width="19" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;Windows Server 2003&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;•&lt;/SPAN&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;" width="19" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;Windows Server 2003 R2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;•&lt;/SPAN&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;" width="19" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;Windows Server 2008&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;•&lt;/SPAN&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;" width="19" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal; text-indent: -0.25in;"&gt;Windows Server 2008 R2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-2/user/guide/acsuserguide/users_id_stores.html#wp1248491&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However ACS 5.5 with the latest patch does support the windows 2012R2 :&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; line-height: normal;"&gt;ACS supports these AD domains:&lt;/P&gt;&lt;UL style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal;"&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2003&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2003 R2&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2008&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2008 R2&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2012&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Windows Server 2012 R2 is supported after installing ACS 5.5 patch 1.&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/user/guide/acsuserguide/users_id_stores.html#pgfId-1321235&lt;/LI&gt;&lt;/UL&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;So you would need to upgrade the ACS to the latest version of ACS 5.5 in order for the AD integration to work.&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;To check the supported upgrade path, you can go to&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/release/notes/acs_55_rn.html#pgfId-284251&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Kush&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 10:32:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554546#M89600</guid>
      <dc:creator>kushsriva</dc:creator>
      <dc:date>2014-07-10T10:32:05Z</dc:date>
    </item>
    <item>
      <title>Thanks for the response.  I</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554547#M89604</link>
      <description>&lt;P&gt;Thanks for the response.&amp;nbsp; I ended up upgrading to the latest 5.5 version which fixed the problem and everything is working great.&amp;nbsp; I just wish I would have had your message earlier as I upgraded in the hopes (but not knowing for sure the new version would fix my issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 16:05:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-operation-has-failed-because-of-an-unspecified/m-p/2554547#M89604</guid>
      <dc:creator>NPT_2</dc:creator>
      <dc:date>2014-07-10T16:05:12Z</dc:date>
    </item>
  </channel>
</rss>

