cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9644
Views
11
Helpful
2
Replies

ISE Machine Account permissions

jpoaps915
Level 1
Level 1

Hi All,

I am having some issues with command sets and ISE.  In the TACACS live log I receive an error of "ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS " and "The ISE machine account does not have the required privileges to fetch groups." We are running ISE2.0.

Cisco TAC sent this to me:

http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200349-ISE-1-3-AD-Authentications-Fail-with-Err.html

Which I have tried and still failed.

When I do a test user in ISE - I can only retrieve 26 groups max. My question is - how do I go about granting my COMPUTER account in AD the proper permissions (I believe its the tokengroup attribute)? Any input is appreciated.

1 Accepted Solution

Accepted Solutions

Rahul Govindan
VIP Alumni
VIP Alumni

The following document shows you how to add the right permissions for the ISE computer account to retrieve groups:

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200780-Fix-Active-Directory-group-retrieval-iss.html

Can you try the above steps and see if this works?

View solution in original post

2 Replies 2

Rahul Govindan
VIP Alumni
VIP Alumni

The following document shows you how to add the right permissions for the ISE computer account to retrieve groups:

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200780-Fix-Active-Directory-group-retrieval-iss.html

Can you try the above steps and see if this works?

Thanks Rahul...

This worked!