08-10-2017 03:40 PM
I have spent over an hour and I still cannot find out why I cannot delete an AD join point. Yes I know, *somewhere* in that forest of menu options is some little thing that is preventing me. But the application knows there is a problem but it tortures the user unnecessarily.
Can someone please give me an SQL command or something to find out what dependencies my AD Join Point has, to put me out of my misery?
08-10-2017 03:49 PM
If prior to 2.2, you might be hitting CSCva73322. Please engage Cisco TAC on this.
08-10-2017 04:16 PM
this is 2.2 patch 2
I had the TAC engaged yesterday for another issue and we poked around in Oracle a bit. If I knew my way around the schema I'd be running an SQL query to find the dependencies.
In the longer term, having more expressive error messages would be a great thing.
08-10-2017 04:19 PM
I am assuming you checked all the usual spots:
Those are the only spots off the top of my head where it could be referenced. I am sure I am missing some more.
08-10-2017 04:55 PM
Thanks - I have checked those at least three times over - I even clicked into settings I have never touched before, just in case I missed something. The back story is that I had a Join Point called CORP, and then later I added a second join point called RES. RES has AD trust relationship to many other domains (including CORP). So I changed all my config to use RES instead - and this works like a charm. I deleted all the CORP Groups that I had added, and I also managed to Leave CORP domain. I just cannot delete the Join Point.
So far we use AD only for Admin GUI, Sponsor Portal admin groups and TACACS Policy Sets.
08-10-2017 04:22 PM
CSCuc55997 is one such enhancement.
AD can be used also in the sponsor group policy, client provisioning and posture policies.
04-28-2020 04:31 PM
Necro an ancient post! I had the same issue and for anybody else consulting the interwebs for the same problem, I finally find the last vestiges of the old AD join point.
1) Administration --> System --> Admin Access --> Authentication
2) Select the "Authentication Method" tab if not already selected
3) Select the "Password Based" radio button if not already selected
4) Select your identity source and ensure it's not the AD join point you're trying to delete
5) Try again
I also tried the policy export and poured through the XML to no avail. Again, sorry for pulling a necrotic post but want to document this for anybody else in the same boat.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide