11-01-2023 09:13 PM
Hi all,
I have a questions regarding cisco ise ad integration. I have integrated ISE and AD using one of the admin account of AD, Then, i cannot remember which one i have used. How could i find it at ise? Can i check it which account name is using at cisco ISE side? coz i need to change this AD account password according to our organization policy.
Thank you.
Solved! Go to Solution.
11-02-2023 09:20 PM
That will not be an issue. It does not matter what account is used to perform the domain join operation as long as the account has the necessary permissions as defined in the Active Directory Integration with Cisco ISE 2.x guide (which also applies to 3.x).
11-02-2023 01:17 AM
- Go to Administration > Identity Management > External Identity Sources > Active Directory
.
and review the settings,
M.
11-02-2023 09:11 PM
i cannot see any review setting there.
11-02-2023 01:19 PM
@CiscoJane - when you integrated ISE with AD, did you tick the box "store credentials" or not? If not, then ISE would not have retained the creds - all that ISE does, is to create an AD machine account. It's not required to store the creds in ISE for regular AD joins. I struggle to remember why this option is even there - I think it might only be used when doing Passive ID.
11-02-2023 09:13 PM
If we cannot know that account anymore, we may plan to join using new account.
11-02-2023 09:20 PM
That will not be an issue. It does not matter what account is used to perform the domain join operation as long as the account has the necessary permissions as defined in the Active Directory Integration with Cisco ISE 2.x guide (which also applies to 3.x).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide