cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3164
Views
0
Helpful
3
Replies

ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS

Hello, 

 

I have a new ISE deployment with two nodes. 

I have a problem with user authentication against Active Directory. 

When I try to authenticate a user I get the following error:

24371    The ISE machine account does not have the required privileges to fetch groups. - ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS

24371    The ISE machine account does not have the required privileges to fetch groups. - xxx-xxx

 

I have tried this solution 

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200780-Fix-Active-Directory-group-retrieval-iss.html

but if I am not mistaken is per user, so it is not scalable. 

 

The customer says that the accounts have the required privileges. 

Any hint?

 

Thanks and regards, 

Konstantinos

3 Replies 3

Hello Mike,

Thanks for the answer.
I have informed the customer about the "Active Directory Account Permissions Required to Perform Various Operations"
For the join operation, the account used is definitely correct. I have already sent to the customer the "Cisco ISE Machine Accounts" permissions in order to double-check.