cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
355
Views
0
Helpful
8
Replies

Generating users with active directory

zacht5476
Level 1
Level 1

I’m trying to generate users with Active Directory. I’ve joined Cisco ISE to the domain, added the groups, and created an authentication policy, but no users are being generated. Could you clarify what permissions Cisco ISE requires on Active Directory?

1 Accepted Solution

Accepted Solutions

@zacht5476 what do you mean "no users are being generated"? ISE does not generate AD users, ISE performs a lookup against AD to determine if the user exists, the password is valid and determine group membership.

View solution in original post

8 Replies 8

@zacht5476 what do you mean "no users are being generated"? ISE does not generate AD users, ISE performs a lookup against AD to determine if the user exists, the password is valid and determine group membership.

ok, i'm completely new to cisco ise and i was confused if ise generated users from AD. You just answers my question thank you. 

is there a way to see users on ise?

@zacht5476 you see the users being authenticated, you can do lookup of users. ISE is not used to manage the AD users. You configure ISE to join the AD domain to perform lookups, then you can retrieve the AD groups and perform the group membership lookups.

ok, thank you.

i can't see any users being authenticated. is that a problem with the policy?

@zacht5476 is the client's native supplicant configured for 802.1X authentication? Are the switches configured for RADIUS and 802.1X authentication? Are the NADs configured on ISE? What do the ISE Live Logs indicate?

is that how it works the switch has to me configured? 

@zacht5476 yes, you need to configure the client (windows, mac, linux) to perform 802.1X authentication, the switch/WLC the endpoints connect to must be configured for 802.1X using ISE as the RADIUS server and then ISE must be configured with policies to authenticate the users/computers.

Check out this training - https://www.cisco.com/site/us/en/learn/training-certifications/training/courses/802-1x.html

Videos - https://www.youtube.com/watch?v=m7NkBFCm9Tk 
https://www.youtube.com/watch?v=8-mMgc-Wt74