Guidelines for AD Deployments with Secure Access Virtual Appliances

  • The Connector account (Cisco_Connector or custom username) must be a member of the following built-in groups on each AD domain:
    • Enterprise Read-only Domain Controllers
    • Event Log Readers

Note: In a parent/child domain scenario, the Enterprise Read-only Domain Controller only exists in the parent domain. In this case, follow the instructions listed here to provide the required permissions for the Connector account. You must add other missing groups.