cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
648
Views
15
Helpful
4
Replies

ISE AD integration

Tong Zhang
Level 1
Level 1

Hi,

 

Very often, when we integrate ISE with customer AD and try to join ISE into domains, customer will ask what kind of service account they'll create for us to use to join the domain.  Based on Cisco documentation, the service account should allow ISE to read the AD user/machine records, and should also "has sufficient privileges to create and remove machine accounts in the domain, or alter the passwords for previously created machine accounts".  Often, the latter part alerts the customer, and we've been pushed back and asked why.  Based on the normal use cases, seems ISE only need to read the record rather than create account, what is the reason we need the capability to create the machine account?  If the credential not support creating machine account, what's the impact?

 

Many thanks in advance!

Tina

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

When you integrate ISE with AD, one of the things done by the service account (or other account used) is to join the ISE servers themselves to AD.

Once that is done, you could probably remove that particular privilege from the defined account if it's inconsistent with organizational security policy.

(Note that a 1.3 upgrade requires rejoining the ISE nodes so the privilege would need to be reinstated during the post-upgrade rejoin.)

Marvin, Neno,

 

Many thanks for you guys response!

 

Tina

Tina,

You're welcome.

Please take a moment to rate helpful posts.

nspasov
Cisco Employee
Cisco Employee

Hello Tina, Marvin makes a very good point that ISE does not require a "Service Account" like ACS does. With ISE, once the deployment is joined to the domain, the AD account is no longer used so it can be disabled or even deleted. In addition, many of my customers don't even use a "service" account to join ISE. Instead, they use their own account or some other network related account. 

I hope this helps!

 

Thank you for rating helpful posts!

Thank you for rating helpful posts!