08-26-2020 05:49 AM
Dear Expert, i want to ask regarding integrating ISE with Active directory.
Thank You.
Solved! Go to Solution.
08-26-2020 06:02 AM
08-26-2020 06:02 AM
08-26-2020 09:52 AM
Mohammed gave a great detailed answer. The simple answer is joined ISE to AD is identical to joining a Windows server/computer to AD. The ID used to join ISE to AD needs to have join permissions. Once ISE is joined to AD it has its own computer account to interact with AD. The ID used to join ISE to AD is not saved unless you check the box to save it.
08-30-2020 04:41 PM
Hi @mfirdaus
Just to add what @paul mentioned about the saved AD credentials - I have never found a Cisco document that explained why this would be needed/beneficial. It seems obvious at first that you would NOT want to save the admin's credentials in ISE (esp if password changes over time, or just because of plain paranoia).
However, after watching the labminutes.com series he quite causally mentions that the Save credentials is REQUIRED if you are using the ISE AD Probe (Profiling). I have never seen this confirmed anywhere. I have not tested to see if AD probing breaks if I joined AD without saving creds.
It would be nice to have the official statement from Cisco about WHY this option even exists.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide