cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
207
Views
2
Helpful
3
Replies

Error joining ISE to AD

I am trying to connect Active Directory to ISE, but the following error appears:

Status: Join Operation Failed: The account's computer join limit has been exceeded.

Error Description: The account`s computer join limit has been exceeded.

Support Details...
Error Name: ERROR_NOT_ENOUGH_QUOTA
Error Code: 1816

3 Replies 3

Use admin to join AD 

You use non-admin user to join AD

"""You must have defined the Admin user, and added them to an Administrator group. The Admin must be a  Super Admin."""

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217351-ad-integration-for-cisco-ise-gui-and-cli.html

MHM

@ahmad-fauzi-hanif it seems like the user account being used to join ISE to the domain has exceeded the limit, which appears to be 10. Refer to this guide to amend the limit - https://learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/default-workstation-numbers-join-domain

Altertnatively use an administrator account to join ISE to the AD domain.

 

If you need to store the account credentials in ISE please note that as best practice it's recommended to use a service account instead of the admin account. The service account permissions could be find in this link:

Integrate AD for ISE GUI and CLI Log in - Cisco