cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
577
Views
5
Helpful
3
Replies

Cannot Retrieve Active Directory Groups

Murtaza Haider
Level 1
Level 1

Hi All

I recently connected my ACS deployment to Active Directory 2003. However when I try to add the active directory groups for group mapping, i.e. navigating to Users and Identity Stores > External Identity Stores > Active Directory > Directory Groups Tab and click select.

My GUI on IE just loops and does not display anything(it does not freeze). On Firefox I receive "The connection was reset" error.

Any ideas?


Thanks in Advance

 

3 Replies 3

Saurav Lodh
Level 7
Level 7

what is the ACS version? here are few Tshoot steps

https://supportforums.cisco.com/document/111776/acs-5x-debugging-ad-related-issues

nspasov
Cisco Employee
Cisco Employee

Do you have the proper AD permissions set for the AD account used to join ACS to the domain?

Note: AD account required for domain access in ACS should have either of these:

  • Add workstations to domain user right in corresponding domain.

  • Create Computer Objects or Delete Computer Objects permission on corresponding computers container where ACS machine's account is created before joining ACS machine to the domain.

 

Thank you for rating helpful posts!

Venkatesh Attuluri
Cisco Employee
Cisco Employee

 

https://supportforums.cisco.com/discussion/11505326/acs-integration-microsoft-active-directory-services

http://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/113571-acs5-ad-int-config-00.html