cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1194
Views
10
Helpful
4
Replies

ISE and AD integration

My question is, what will happen if we delete the user on the AD that was used at the time of AD integration on the ISE. 

Does the user used at the time of AD integration be part of the AD forever?

 

 

Thanks

shubham

1 Accepted Solution

Accepted Solutions

AKAIK, No this account is only used to join ISE to the domain.  Once the ISE nodes is a member of the domain, it uses its own machine/domain account to authenticate/search the forest.

View solution in original post

4 Replies 4

AKAIK, No this account is only used to join ISE to the domain.  Once the ISE nodes is a member of the domain, it uses its own machine/domain account to authenticate/search the forest.

Hi, Yes you are correct if ISE is joined to domain. But if AD is added as
LDAP source then it uses bind requests through the configured account. I
should have been clear on this.

Thx for highlighting it. +5

***** please remember to rate useful posts

I would say it depends on what you added for profiling. If you will be relying on Active Directory attributes for profiling then you should store the access details on ISE. In that case, if you remove the account you used from the AD that will affect ISE profiling functionality.

Hi,

Yes, AD account should be permanent. ISE uses this AD account for bind
requests to AD when authenticating users. Also, it is used for groups
fetching etc

**** please remember to rate useful posts