Jump to content

Recommended Posts

Posted

Hi

 

We're in the process of moving over from WPA2 PSK over to WPA2 802.1X. We're using 'User authentication' on our NPS and have selected 'Single sign on type as: preLogon'

 

I'm happy with the way the wireless encryption is working and everyone is able to logon. The authentication is occuring after the user has logged in (as I would expect it too). What about the group policies that would normally be applied before a user is able to log in?

 

Any idea guys.

 

Thanks

 

Tom

Posted

You can setup machine authentication in group policy with user re-authentication if you want and that way the machine connects with it's computer account so those gpo's will apply.

 

Ben

Posted

Hi

 

I've set changed the NPS so that it only accepts computer groups and altered the GPO for my wireless security so that we're using 'computer authentication.

 

This doesn't work, none of my GPOs will apply.

 

I've set 'Always wait for the network at computer startup and logon'

 

Any ideas?

 

Thanks

 

Tom

  • 2 weeks later...
Posted

Hi,

 

Usually you need to have a policy in NPS that has the windows computer groups added as allowed. You can check the NPS logs to see why the client is being denied from the event viewer > custom views > roles in 2k8+

 

You then have to create the GPO with computer authentication + the valid options. Then you need to make sure you have gpupdated with a valid connection to your domain controller to get this policy change e.g plug in a lan cable or have a wireless SSID that has this access to make it work.

 

If you can add some screenshots of you NPS configuration or PM them to me I can assist.

 

Also what are you using for 802.1x ? EAP-TLS? etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...