11-14-2017 01:34 PM - edited 02-21-2020 10:39 AM
Hi everyone. This should be an easy question, but I need quick help.
We are going to deploy ISE in our network and we need to integrate to AD server. I read we need the following user in order to do that:
AD account required for domain access in ISE should have either of these:
So, basically, we could use a domain admin user (I understand we don't store the credentials and we just need someone to enter that user/password once, is that right?) But AD administrators are asking us to explain exactly what is that account going to do, what is it going to read, what accions will be done on the servers. The only thing we know is that a machine account will be created, but we don't know what that account does, what permissions it has, how does it work reading AD Groups and authenticating users, we know nothing. Can someone please explain a little bit about it? They're concerned about security.
Any help appreciated.
Thank you.
Solved! Go to Solution.
11-14-2017 02:25 PM - edited 11-14-2017 02:42 PM
Correct, that account will only be used to join ISE nodes to the domain. By default AD allows even regular non-admin accounts to join computers to the domain. Afterwards that account is not used at all.
ISE AD operations (group lookups, etc) are handled by the computer objects that get created when you join the nodes to the domain. These computer objects behave very much like Windows native computer accounts - they refresh their own passwords with the domain and so on. You can see that activity in the AD Connector operations report from the Reports menu.
11-14-2017 02:25 PM - edited 11-14-2017 02:42 PM
Correct, that account will only be used to join ISE nodes to the domain. By default AD allows even regular non-admin accounts to join computers to the domain. Afterwards that account is not used at all.
ISE AD operations (group lookups, etc) are handled by the computer objects that get created when you join the nodes to the domain. These computer objects behave very much like Windows native computer accounts - they refresh their own passwords with the domain and so on. You can see that activity in the AD Connector operations report from the Reports menu.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: