This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
I've inherited an ISE deployment and In our AD there is a ISE service account who is a domain admin.
Going through the ISE guides, I can that the service account need specific permission in AD, and I guess they've used a domain admin (the dirty way).
I want to rectify this by creating a new account with the specific permission, but I can't seem to find where the account is defined within ISE. The only account I can find (but not used in any way), is the AD join account.
So the question is, where do I find the other account in ISE?
Hi Damien
Both nodes are present in AD, and "joined" under External Ident.
I've stepped through the guide again, and under "Set Permissions for Access to WMI Root/CIMv2 Name Space" the account is applied on our Domain controller. But I can't seem to find, where the user is defined in ISE (where the pwd is set)
The WMI thing is for Passive Identity.
Unless you are using that feature, you would not need the user credentials, just like Damien said.
I haven't found the settings for the service account within ISE?