What are the privileges that the Admin Account needs to have, after ISE has been integrated with AD? In other words: what are the minimum settings that the Service account, used to log in AD and create the ISE-AD integration, needs to have to continue working (querying AD) after the initial integration, to authenticate 1X or CWA sessions, and query for group membership to work?
Thank you for your time.