04-08-2019 06:02 AM
We're about to deploy Cisco ISE to a customer site and they have asked the question...
"Will ISE work with a Group Managed Service Account? These are service accounts that have their passwords changed periodically."
Now, I'm assuming that if the password changes and Cisco ISE supports gMSA, then it will 'learn' the new password and won't get cut off from AD?
TIA
Dan
Solved! Go to Solution.
04-08-2019 07:07 AM
04-08-2019 07:43 AM
Like Jason Kunst posted, ISE AD runtime is similar to any Windows PC so that it uses its own computer account in AD to authenticate AD users and retrieve their attributes for authorization.
The places where ISE needs an AD user password stored are:
These two functions are not currently working with gMSA password change mechanism, so we would need update the passwords manually if such accounts are used.
04-08-2019 07:07 AM
04-08-2019 07:43 AM
Like Jason Kunst posted, ISE AD runtime is similar to any Windows PC so that it uses its own computer account in AD to authenticate AD users and retrieve their attributes for authorization.
The places where ISE needs an AD user password stored are:
These two functions are not currently working with gMSA password change mechanism, so we would need update the passwords manually if such accounts are used.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide