CAWJames Posted June 17, 2016 Posted June 17, 2016 Afternoon all, Curently we use a standard student WIFI SSID with WPA-PSK, which was great in its day, but provides no auth other than someone knowing the pass key. Its coming and we will soon if not imminently need to pin point a particular students activity under the PREVENT or other documents/frameworks. All our students have a O365 account, as do Staff. And we have ADSync or whatever they are calling it now, but this only does staff. I dont really want to sync our student populace with our internal AD unless I have to. Is there any way to have a standalone radius server sync with O365 seperately from ADSync? or am I barking up a bad tree and should suck it up and get the students into AD proper? Thanks James
Steve21 Posted June 17, 2016 Posted June 17, 2016 Not really sure what you mean, O365/ADSync and Radius would be separate :s Don't you have students in AD at all currently? Not even for a normal account? Or do you just mean you don't want them sync'd via ADSync? (Or am I totally missing something?) Steve
CAWJames Posted June 17, 2016 Author Posted June 17, 2016 Yep, I want 2 infrastructures, 1 AD Sync to keep my staff synced with AD and O365, and another RADIUS to syn staff AND students from O365. Currently we sync by OU filtering only the staff. no students at all in AD. They automagically get added to O365 by script from our MIS. So basically I want a RADIUS server that will sync with O365 to allow me to use RADIUS & 802.1X on our wireless infrastructure, so staff and students will have to log in with their own credentials to use Wi-Fi. Am I making sense?
Steve21 Posted June 17, 2016 Posted June 17, 2016 Aye you are, but just not sure why you'd want to do it that way. (in regards to no student's locally) How do you query things like who hit firewall/filtering systems if there's no student accounts locally? (in regards to your prevent comment), or you planning to use this for that too? As far as I know you couldn't use 365 direct for Radius unless you're using AD Azure etc as it's not a queryable system, but then why not just have student's locally too? Don't need to use them for anything in AD apart from Radius if that's all you want. Also means no issues with things breaking if 365 has a wobble Steve
CAWJames Posted June 17, 2016 Author Posted June 17, 2016 Yeah, you raise a good point. We are going to have to have students logging in as themselves, but I am digging my nails into the floor boards! So...what you are saying is get them local, get them logging in and use normal infrastucture!
Steve21 Posted June 17, 2016 Posted June 17, 2016 Well I mean I guess it depends how you currently work, going back a stage I "guess" you're BYOD devices site-wide currently? If you have no local logins? If so the other option would be logging a deviceID/MAC to a user (would need to be a one-time process when they want to join wireless etc), and using that as the unique ID you're using rather than a login via AD/365. Then you still know what user is accessing what. Then no radius/AD issues would be there at all But if you want a username against each user you're going to need to have something locally to query, which means accounts/AD (Unless I've missed a new option in 365 anyway). Now from your current setup easiest way would be just setup ADSync etc to pull down student details to AD, and then use that as the login to radius/filtering Steve
CAWJames Posted June 17, 2016 Author Posted June 17, 2016 No real BYOD here, but a lot of user owned deviced and college owned devices. Generic logins on ours, whatever on theirs. We offer a sanitised wifi for them. Obviously going forward we can't have the generic logins otherwise we would have problems following PREVENT, so I think I have to recommend bringing students in the AD infrastructure so they can log in as themselves Thanks for the answers, seems I was trying to solve a problem that would be solved by another decision further down the line!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now