Security

last person joined: 13 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Why do you need to use a domain account to join Clearpass to a domain?

This thread has been viewed 17 times
  • 1.  Why do you need to use a domain account to join Clearpass to a domain?

    Posted Feb 17, 2015 10:54 AM

    I'm curious as to why the domain admin accont is needed to join clearpass to a domain. By default standard users are abel to join 10 PCs to the domain. I have created an account to use for CP to bind to AD and was planning on using that same account to join it to the domain. I was supprised to see the the join process requres the account to be a domain admin. Does that mean if must actually be the buil-it "Administrator" account or can it be an account that has been added to the domain admins group? 



  • 2.  RE: Why do you need to use a domain account to join Clearpass to a domain?

    EMPLOYEE
    Posted Feb 17, 2015 11:10 AM

    It does require some elevated privileges.  Joining the domain allows CPPM to authenticate 802.1x methods that have MSCHAPv2 as the inner-EAP method such as PEAP.  This join procedure is done ONCE and only ONCE.  We do NOT save or cache the account used to join the node to AD.  

     

    When you are done, you can use a typical service account with a non-expiring password when you ad AD as an authentication source.  This account will not need the same elevated privilege level.  



  • 3.  RE: Why do you need to use a domain account to join Clearpass to a domain?

    Posted Feb 17, 2015 12:25 PM

    Thanks, Seth. I'm fully aware of how the process works, I'm just getting push back from our AD team about granting a user elvated rights to add the box (as Tim pointed out, we do not allow user to add devices tot he domain)... and was looking for a reason for the restriction to pass on to our AD team. 

     

    Thanks for the help.



  • 4.  RE: Why do you need to use a domain account to join Clearpass to a domain?

    EMPLOYEE
    Posted Feb 17, 2015 12:37 PM
    It's a one time thing. Can one of your AD admins just join it to the domain? 


    Thanks, 
    Tim


  • 5.  RE: Why do you need to use a domain account to join Clearpass to a domain?

    EMPLOYEE
    Posted Feb 17, 2015 02:31 PM

    I've run into this a few times.  Get them to add Clearpass to the domain and then show them that the password isn't cached or saved.  They can enter THEIR creds and add the node to the domain.  Once done, just add AD as an auth source using a service account...or some other account setup for CPPM



  • 6.  RE: Why do you need to use a domain account to join Clearpass to a domain?

    Posted Feb 25, 2015 09:10 AM

    Giving the user account rights to add a PC to the domain and add/remove objects to the Computers contianer did not work. I did get it to work by giving the service account "Full Control" of the Computers container.

    Thanks for the help.



  • 7.  RE: Why do you need to use a domain account to join Clearpass to a domain?

    Posted Dec 10, 2018 08:49 PM

    May I know what kind of elevated privileges require for this account to Join Domain controller. My environment very restricted  and my AD team asking me for the exact privileges .I even ask for  grant access admin privilege for 3 minutes to Join domain also not allow. Please someone can help me out ?

     



  • 8.  RE: Why do you need to use a domain account to join Clearpass to a domain?

    EMPLOYEE
    Posted Dec 11, 2018 08:43 AM

    Typically you would need to be able to add and modify computers to the domain, so a user with only add privileges would not work.  Please see here for common reasons why domain adds fail to get an idea of what is needed:  https://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/Common-ClearPass-domain-join-errors/ta-p/192591 and https://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/How-to-join-ClearPass-to-an-Active-Directory-domain/ta-p/187614

     

     



  • 9.  RE: Why do you need to use a domain account to join Clearpass to a domain?

    EMPLOYEE
    Posted Feb 17, 2015 11:22 AM
    If you allow end users to join clients to the domain (most don't), then you
    should be ok to use that account.