Jump to content

Recommended Posts

Posted

Morning all,

 

We keep all out students in AAD, nicely created by scripts, and all our staff in AD. Has worked well for years, but now we want to bring those student accounts into AD, so we can start using Radius services for Wi-Fi, and allow students to login locally, etc, etc.

 

Seems adsync will work nicely from local to cloud, but they tested the other way about 5 years ago, then removed it.

 

Surely if they want people to go to cloud in the enterprise/education, they should provide some way of doing Radius in AAD, without an uber expensive 3rd party system like JumpCloud/IronWifi or having an Azure server running radius services in the cloud, which requires a higher level of AAD and cost for the server.

 

Anyone done this, and have any tips/tricks?

 

Thanks

James

Posted

Apart from requiring a password reset (Unless you have the proper licenses for AAD), any reason you can't just script them all in? As long as the UPN/proxyaddress etc match up it'll just link those accounts or should do

 

Or is there a specific issue you're thinking about in this?

 

Steve

Posted
I was hoping to avoid a password reset!! But current thinking is export out data, and script it into AD, then sync back, then wait for the inevitable flood of helpdesk tickets from students and the stock reply of "read the banner on the VLE, and the email we sent telling you about a password reset"!!
Posted

Creating an account in AAD and having the account created in AD is coming but not really meant for your use case. You are pushing against the tide.

 

Is it not easier to have tech that can use Azure AD auth? There are WifI setups that support Azure AD. For the radius side of the things there's also the Microsoft NPS externsion

Posted
We are always pushing against the tide ;) that's education for you! What use case would that feature be for then, if not ours? I would love tech that had Azure AD built in, but it is not in tech we have, and I can't see budgets stretching to upgrading to the probably high cost of ripping everything out and going higher end enterprise to get that functionality. What do you mean by MS NPS extension? Thanks
Posted

NPS is a feature of windows server, it's meant to alllow radius connections to flow through to Azure AD to do MFA stuff

 

The goal of the feature I described is to be cloud first, so say in a big firm they use workday HR to provision users, which then creates a new account in Azure AD then an on prem agent creates an AD account (if required). I dont see it mentioned anywhere in public yet anyhow

 

If your really want to do this, and have common passwords, you are going to have to master your accounts in on prem AD, then join it up to azure ad. This feels like a massive backwards step. If these are edu owned devices could you assign machine certs to them and provide auth that way?

Posted
It is a backward step, but so many forms of auth we use rely on 802.11x and AD to function with no option to connect to azure. Wifi(unifi) would be the main use of this, at the moment we have to use WPA2, as we have no function to allow the access points to auth from azure. We also want the students to log in to on-prem AD connected machines, so our Watchguards can track usage and properly log access to blocked websites, again this function is all based on on-prem AD. At the moment we have generic student logins, which is hell for tracking, we an identify the computer, then have to refer to a lecturers seating plan to work out the actual student, as as you can probably gather this is not ideal for reporting or timely nailing down infractions.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...