01-21-2019 12:18 PM - edited 01-21-2019 12:20 PM
Easy question. After ISE joins the domain, all of the ISE servers (Admin, Monitor, and Policy Nodes) are located in the Computers OU. Can we move these ISE servers to a different OU? Is there documentation stating it is ok, or a recommendation to move these to a different OU?
Solved! Go to Solution.
01-21-2019 01:02 PM
One way to avoid this is to use the following option during join, from the AD join documentation.
Step 7 - (Optional) Check the Specify Organizational Unit checkbox.
You should check this checkbox in case the Cisco ISE node machine account is to be located in a specific Organizational Unit other than CN=Computers,DC=someDomain,DC=someTLD. Cisco ISE creates the machine account under the specified organizational unit or moves it to this location if the machine account already exists. If the organizational unit is not specified, Cisco ISE uses the default location. The value should be specified in full distinguished name (DN) format. The syntax must conform to the Microsoft guidelines. Special reserved characters, such as /'+,;=<> line feed, space, and carriage return must be escaped by a backslash (\). For example, OU=Cisco ISE\,US,OU=IT Servers,OU=Servers\, and Workstations,DC=someDomain,DC=someTLD. If the machine account is already created, you need not check this checkbox. You can also change the location of the machine account after you join to the Active Directory domain.
Now as for moving the machines after the fact, no issue. I can't find it in the documentation but I did just try it in the lab. No issues moving it after joining or with restarting the AD connector, all the lookups I performed passed fine. Another option if it makes you feel better about it. You can create machine accounts in the OU you want prior to joining ISE to AD. Ex, manually create machine accounts in a server OU, join AD, ISE leaves them where they were created.
01-21-2019 01:02 PM
One way to avoid this is to use the following option during join, from the AD join documentation.
Step 7 - (Optional) Check the Specify Organizational Unit checkbox.
You should check this checkbox in case the Cisco ISE node machine account is to be located in a specific Organizational Unit other than CN=Computers,DC=someDomain,DC=someTLD. Cisco ISE creates the machine account under the specified organizational unit or moves it to this location if the machine account already exists. If the organizational unit is not specified, Cisco ISE uses the default location. The value should be specified in full distinguished name (DN) format. The syntax must conform to the Microsoft guidelines. Special reserved characters, such as /'+,;=<> line feed, space, and carriage return must be escaped by a backslash (\). For example, OU=Cisco ISE\,US,OU=IT Servers,OU=Servers\, and Workstations,DC=someDomain,DC=someTLD. If the machine account is already created, you need not check this checkbox. You can also change the location of the machine account after you join to the Active Directory domain.
Now as for moving the machines after the fact, no issue. I can't find it in the documentation but I did just try it in the lab. No issues moving it after joining or with restarting the AD connector, all the lookups I performed passed fine. Another option if it makes you feel better about it. You can create machine accounts in the OU you want prior to joining ISE to AD. Ex, manually create machine accounts in a server OU, join AD, ISE leaves them where they were created.
01-22-2019 06:57 AM
Very precise and thorough answer. I really appreciate your time.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide