This document describes how to workaround the problem with Active Directory (AD) group retrieval during authentication, while this error is seen in live logs:
Cisco recommends that you have knowledge of these topics:
Cisco Identity Services Engine
Microsoft Active Directory
This document is not restricted to specific software versions of Identity Services Engine (ISE).
The problem is that user account used to join ISE to AD does not have correct privileges to get tokenGroups. This would not happen if Domain Admin account was used to join ISE to AD. To fix this issue, you have to add ISE node(s) to the user account and provide those permissions to ISE node(s):