Vstar Posted February 1, 2019 Posted February 1, 2019 Hi all, I'm attempting to set up some Chromebooks on the schools WiFi network. Initially I set them up with the SSID/Password, so they connect automatically to the WiFi, and then (ideally) let the pupils should log into their Google accounts. However, the web filter/proxy we use is designed for Windows and as there is no AD integration in the Chromebook, it pops up a login box (username/password) in the Chrome browser, were it needs the AD credentials (which do match the Google credentials). It then lets them log into their Google accounts (as they are auth'ed on the web filter). This double login is perceived as real issue by staff who have played with the Chromebooks and needs fixing. The solution seems to be WPA2 Enterprise 802.1x logins using PEAP/MS-CHAP V2 (set up on the Google domain & the WiFi controller), a Radius server on the Windows Domain Server and and an accounting feed on the WiFi controller to push the login credentials to the web filter/proxy server. My question though is this - when this is set up, does it genuinely only ask for the login details ONCE? As from what I can see it will ask for the details in the WiFi login (which will ask the Radius server to check with the AD, and feed them to the web Proxy), but will still ask you to log into your Google account? Many thanks!
jmak Posted February 1, 2019 Posted February 1, 2019 You can set Chromebooks up for SSO with Azure AD - which of course can be synchronised with on premises AD. This article is slightly out of date, but gives you the idea: https://blog.theserverlessschool.net/2018/04/sso-from-chromebooks-to-azure-ad.html?m=1 That should give you a solution where you use AD credentials and users only have to enter them once.
_techie_ Posted February 29, 2020 Posted February 29, 2020 Hi, Have you looked into forwarding RADIUS accounting request to a new client (in the form of the internet filter)? Might be possible if you use smoothwall or lightspeed... as they can be configured as RADIUS clients. Other option is join the chromebooks to a wpa-psk network and use a captive portal to login to the filter (again, smoothwall can do this)... 10 ways to skin a cat here, are you using ADFS as well with your on-premise AD, or password sync to G-Suite/Google Classroom?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now