cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5566
Views
0
Helpful
5
Replies

Cisco ISE Active Directory Joining Issue

munzirk
Level 1
Level 1

Dear Members,

 

I am facing issue while joining to domain, it is giving below error. Please help how can i resolve this issue. The user ABC is authorized to join the domain. NTP is also synchronized

 

Error Description: Access is denied

Support Details...
Error Name: ERROR_ACCESS_DENIED
Error Code: 5

Detailed Log:
12:57:31 Joining to domain XXXXDOMAIN.LOCAL using user ABC
12:57:31 Checking credentials for user ABC
12:57:31 Getting TGT for account ABC@XXXXDOMAIN.LOCAL
12:57:31 TGT for account ABC@XXXXDOMAIN.LOCAL was retrieved successfully
12:57:31 Credentials for user ABC were verified
12:57:31 Searching for DC in domain XXXXDOMAIN.LOCAL
12:57:31 Found DC: xxxxdc01.xxxxdomain.local , client site is Head-Office , dc site is Head-Office

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

You might be using an older ISE release, as I expected the error would have indicated more details (see my example below). If you just learning on your own and not entitled to open a TAC case, then please enable TRACE on the component active directory, retry this join operation, and check the log file ad_agent.log. Also, you should be able to enable some auditing in AD and please seek Microsoft support if you need any help on that.

Here is my error example:

Error Description: Access Is Denied
 
Support Details...
Error Name: ERROR_ACCESS_DENIED
Error Code: 5

Detailed Log:

Error Description : 
Cannot Open Machine Account ISE-1$ : Access Denied.

Error Resolution : 
Please Make Sure That User Employee1 Has Sufficient Permissions To Change Account ISE-1$ 

Join Steps : 
01:50:11 Joining To Domain DEMO.LOCAL Using User Employee1
01:50:11   Checking Credentials For User Employee1
01:50:11     Getting TGT For Account Employee1@DEMO.LOCAL 
01:50:11     TGT For Account Employee1@DEMO.LOCAL Was Retrieved Successfully 
01:50:11   Credentials For User Employee1 Were Verified 
01:50:11   Searching For DC In Domain DEMO.LOCAL
01:50:11   Found DC: Ad.demo.local , Client Site Is Default-First-Site-Name , Dc Site Is Default-First-Site-Name 
01:50:11   Generating Account Name For ISE Machine In DEMO.LOCAL
01:50:11     Searching For An Existing Machine Account 
01:50:11       Searching Object By Filter : (&(objectCategory=computer)(servicePrincipalName=host/ise-1.demo.local))  
01:50:11     Account: Ise-1 Was Found
01:50:11   ISE Machine Account Name Is : ISE-1$ 
01:50:11   Creating Machine Account ISE-1$ 
01:50:11     Connecting To AD Using DC Ad.demo.local 
01:50:11     Connection To Ad.demo.local Established
01:50:11     Opening Domain DEMO 
01:50:11     Domain DEMO Was Opened Successfully
01:50:11     Machine Account: ISE-1$ Already Exists , Opening Account.
01:50:11     Cannot Open Machine Account ISE-1$ : Access Denied.

View solution in original post

5 Replies 5

hslai
Cisco Employee
Cisco Employee

You might be using an older ISE release, as I expected the error would have indicated more details (see my example below). If you just learning on your own and not entitled to open a TAC case, then please enable TRACE on the component active directory, retry this join operation, and check the log file ad_agent.log. Also, you should be able to enable some auditing in AD and please seek Microsoft support if you need any help on that.

Here is my error example:

Error Description: Access Is Denied
 
Support Details...
Error Name: ERROR_ACCESS_DENIED
Error Code: 5

Detailed Log:

Error Description : 
Cannot Open Machine Account ISE-1$ : Access Denied.

Error Resolution : 
Please Make Sure That User Employee1 Has Sufficient Permissions To Change Account ISE-1$ 

Join Steps : 
01:50:11 Joining To Domain DEMO.LOCAL Using User Employee1
01:50:11   Checking Credentials For User Employee1
01:50:11     Getting TGT For Account Employee1@DEMO.LOCAL 
01:50:11     TGT For Account Employee1@DEMO.LOCAL Was Retrieved Successfully 
01:50:11   Credentials For User Employee1 Were Verified 
01:50:11   Searching For DC In Domain DEMO.LOCAL
01:50:11   Found DC: Ad.demo.local , Client Site Is Default-First-Site-Name , Dc Site Is Default-First-Site-Name 
01:50:11   Generating Account Name For ISE Machine In DEMO.LOCAL
01:50:11     Searching For An Existing Machine Account 
01:50:11       Searching Object By Filter : (&(objectCategory=computer)(servicePrincipalName=host/ise-1.demo.local))  
01:50:11     Account: Ise-1 Was Found
01:50:11   ISE Machine Account Name Is : ISE-1$ 
01:50:11   Creating Machine Account ISE-1$ 
01:50:11     Connecting To AD Using DC Ad.demo.local 
01:50:11     Connection To Ad.demo.local Established
01:50:11     Opening Domain DEMO 
01:50:11     Domain DEMO Was Opened Successfully
01:50:11     Machine Account: ISE-1$ Already Exists , Opening Account.
01:50:11     Cannot Open Machine Account ISE-1$ : Access Denied.

Dear members,

Could you share the solution to this please ?

hslai
Cisco Employee
Cisco Employee

Another possibility is some kind of ISE system issue; e.g. CSCvk23793

Ivan Miranda
Level 1
Level 1

Hi, 

How did you solved it? I have exactly the same issue in version 2.6

Gerad Parent
Level 1
Level 1

Did you folks ever share your solution?