01-09-2017 01:48 PM - edited 03-11-2019 12:20 AM
Hi All,
I am having some issues with command sets and ISE. In the TACACS live log I receive an error of "ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS " and "The ISE machine account does not have the required privileges to fetch groups." We are running ISE2.0.
Cisco TAC sent this to me:
Which I have tried and still failed.
When I do a test user in ISE - I can only retrieve 26 groups max. My question is - how do I go about granting my COMPUTER account in AD the proper permissions (I believe its the tokengroup attribute)? Any input is appreciated.
Solved! Go to Solution.
01-09-2017 05:04 PM
The following document shows you how to add the right permissions for the ISE computer account to retrieve groups:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200780-Fix-Active-Directory-group-retrieval-iss.html
Can you try the above steps and see if this works?
01-09-2017 05:04 PM
The following document shows you how to add the right permissions for the ISE computer account to retrieve groups:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200780-Fix-Active-Directory-group-retrieval-iss.html
Can you try the above steps and see if this works?
01-10-2017 04:50 AM
Thanks Rahul...
This worked!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide