tdh1987 Posted March 14, 2014 Posted March 14, 2014 Hi We're in the process of moving over from WPA2 PSK over to WPA2 802.1X. We're using 'User authentication' on our NPS and have selected 'Single sign on type as: preLogon' I'm happy with the way the wireless encryption is working and everyone is able to logon. The authentication is occuring after the user has logged in (as I would expect it too). What about the group policies that would normally be applied before a user is able to log in? Any idea guys. Thanks Tom
plexer Posted March 14, 2014 Posted March 14, 2014 You can setup machine authentication in group policy with user re-authentication if you want and that way the machine connects with it's computer account so those gpo's will apply. Ben
tdh1987 Posted March 17, 2014 Author Posted March 17, 2014 Hi I've set changed the NPS so that it only accepts computer groups and altered the GPO for my wireless security so that we're using 'computer authentication. This doesn't work, none of my GPOs will apply. I've set 'Always wait for the network at computer startup and logon' Any ideas? Thanks Tom
Phake Posted April 4, 2014 Posted April 4, 2014 Hi, Usually you need to have a policy in NPS that has the windows computer groups added as allowed. You can check the NPS logs to see why the client is being denied from the event viewer > custom views > roles in 2k8+ You then have to create the GPO with computer authentication + the valid options. Then you need to make sure you have gpupdated with a valid connection to your domain controller to get this policy change e.g plug in a lan cable or have a wireless SSID that has this access to make it work. If you can add some screenshots of you NPS configuration or PM them to me I can assist. Also what are you using for 802.1x ? EAP-TLS? etc.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now