- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-30-2022 01:29 PM
Hi friends
recently we upgraded the ISE system from 2.4 to 3.0. since then we get this error message.
Alarm Name :
Active Directory diagnostic tool found issues
Details :
ACTIVE_DIRECTORY_DIAGNOSTIC_TOOL_ISSUES_FOUND need to complete
Description :
One or more Active Directory diagnostic tests failed during a scheduled run.
Has anyone experienced such a glitch.
Thanks SHLOMO ITZAHK
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-05-2022 10:17 AM - edited 04-05-2022 10:18 AM
You can see exactly what's generating the error if you drill in to the diagnostic tool.
- Navigate here https://<your ise admin ip>/admin/#administration/administration_identitymanagement/administration_identitymanagement_external
- Click on your active directory connector highlighted in yellow
- Click the checkbox next to one of the nodes and then the "Diagnostic Tool" link
- Once in the Diagnostic Tool you will be able to see the results, run a new test, determine which test is causing the warning.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-31-2022 11:07 PM
I have a vague memory of also seeing this - but the problem is seen intermittently and when you run a manual scan, all is well.
It's similar to the NTP and Smart Licensing health checks - they appear at random times of the month/time and when you test NTP and Smart Licensing, there are no issues. It's like chasing ghosts.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-05-2022 10:17 AM - edited 04-05-2022 10:18 AM
You can see exactly what's generating the error if you drill in to the diagnostic tool.
- Navigate here https://<your ise admin ip>/admin/#administration/administration_identitymanagement/administration_identitymanagement_external
- Click on your active directory connector highlighted in yellow
- Click the checkbox next to one of the nodes and then the "Diagnostic Tool" link
- Once in the Diagnostic Tool you will be able to see the results, run a new test, determine which test is causing the warning.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-07-2022 08:03 AM
Thanks for your help, I performed the test and found that my ISE samples an old server disconnected and unused, how do I stop sampling this server.
Attaches a picture of the sample results
Thank you very much
[cid:image001.png@01D84AA9.AE647FE0]
Shlomo Itzhak

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2023 12:41 PM
Hi, I am running into the same issue after upgrading from 2.4 to 3.0. I know the problem existed prior to upgrading to 3.0 but we weren't being alerted on the issue. When you ran the test, did the test provide you with the information related to the old server? If not, how did you find that data? I have the same issue with the DNS A/AAAA and DNS SRV record query tests. I have opened a TAC case and I have reached out to our systems team. The test details that ISE is providing are very limited on where to look for the problem.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2023 05:50 PM - edited 01-30-2023 05:50 PM
Hi @Charlie Jones ,
please take a look at ISE - Slow Replication and search for the topic: Active Directory Diagnostic Tool, special attention to the 3x Bug IDs described.
Hope this helps !!!
