Jump to content

pantscat

Members
  • Posts

    1,480
  • Joined

  • Last visited

Everything posted by pantscat

  1. Not easily, as far as I am aware.
  2. Ah ok - check your NPS policy - under conditions does it specify "Windows groups" or "Machine groups"?
  3. Yep, it's possible - create a new user account for authenticating the iPads, create a new security group, add the account to the group, then edit the NPS policy to also allow that group access. That's the rough and ready way to do it.
  4. Yep, exactly that. I think @jamesfed's excellent blog post illustrates the group policy setting you need - essentially you need to ensure that your cert server is a trusted root certification authority. That's a little different - as the iPads would be unknown to AD (e.g. they don't have computer accounts here) you could use mac address authentication with Radius... but there is a chance that the mac address could be spoofed, which is fairly easy to do. I understand that you can do cert authentication with iPads, but haven't done it... but should be pretty simple.
  5. Yes, if you're using this method of authentication then you'd need to have already joined the devices to the domain. Not entirely sure what could be causing that issue, do you have a group policy setting to wait for network at logon?
  6. Genericised - RADIUS setup.pdf Have a look at this - it's some handover notes I prepared. Hopefully this makes sense, if not - feel free to ask! Ant
  7. I'm pretty sure I've got some fairly generic setup guides for using NPS. I'll see if I can find it! Certificates are pretty straightforward - the NPS server needs to have a certificate issued to it by your internal cert authority, the clients don't need their own certs - and you should set the certificate server as a trusted authority in group policy. If you were to change certificate servers, then make sure the new one is a trusted authority so the clients are aware of it, then you could issue a new cert to your NPS server. It *shouldn't* cause any issues if done correctly.
  8. I'd say radius is preferred - more secure, and you'll have more granular levels of control. If someone managed to get your WPA2 key then the whole thing is compromised - this is not the case with 802.11x. You can use computer account authentication, NPS will happily do this. Not really any more of an overhead compared with WPA2 in terms of authentication handshaking, with wireless traffic that's completely the thin end of the wedge anyway. I'd strongly recommend using radius as your auth mechanism - further down the line you might want to segregate wireless devices, and radius would allow you to do clever things like dynamic VLAN assignment based on AD group membership... which is nice. Ant
  9. Hey @mrwoberts - you can use the Meraki MDM for free for up to 100 devices, so if you're quite happy with the look and feel of the dashboard, Meraki Systems Manager (their MDM product) is quite similar. Have a look here: https://meraki.cisco.com/products/systems-manager/ I'm aware of a few schools that are using Meraki MDM and it's working very well.
  10. No Windows srv 2012 keys? You might need to have a quick chat with your MS reseller.
  11. That's odd - are other KMS keys listed under Licences | Relationship Summary | Product Keys?
  12. No - ignore that bit, it's inaccurate. Once you've installed the hotfix you can then use the "Windows Srv 2012R2 DataCtr/Std KMS for Windows 10" key in your 2008R2 KMS host.
  13. Follow the link I posted - that'll explain where to find it.
  14. Was it kb3079821 that you installed? This should explain the process for you: https://blog.workinghardinit.work/2015/08/12/find-and-update-your-kms-service-host-key-to-activate-windows-10/
  15. So did you setup DHCP on the admin network? or is the network just not segregated in any way? It's probably that the router IP hasn't been configured properly for the admin default gateway.
  16. Hmm. Shout at it and threaten it with violence. Does your serial port definitely work ok? Can you connect to something else to make sure?
  17. In device manager right-click on the serial port and there should be an option under properties to turn off the buffers - this can sometimes cause problems with serial connections.
  18. Flow control off? Turned off buffers on the serial port?
  19. Nice little 'feature' that...
  20. Apparently this is the process to recover a lost password: How to Recover from a Lost Password You can use a local computer, a computer that connects to the Management Card through the serial port at the Management Card’s UPS or expansion chassis, to access the control console. 1. Select a serial port at the local computer and disable any service which uses that port. 2. Unless an APC smart-signaling cable (940-0024 or 940-1524) is already connected to the selected port, connect the smart-signaling cable that came with the Management Card to the selected port and to the serial port at the Management Card’s UPS or chassis. 3. Run a terminal program (such as HyperTerminal) and configure the selected port for 2400 bps, 8 data bits, no parity, 1 stop bit, and no flow control, and save the changes. 4. Press ENTER to display the User Name prompt. 5. Press the Reset button on the Management Card, which causes the Management Card to restart, a process that typically takes five to ten seconds. 6. Press ENTER as many times as necessary to redisplay the User Name prompt, then use apc for the User Name and Password. (If you take longer than 30 seconds to log on after the User Name prompt is redisplayed, you must repeat steps 4 and 5.) 7. From the Control Console menu, select System, then User Manager. 8. Select Administrator, and change the User Name and Password settings, both of which are now defined as apc. 9. Press CTRL-C and log off. You must perform the entire procedure (log on, change the user name and password, and log off) within two minutes so that you are not logged off for inactivity. If you are logged off automatically, the new settings will not take effect, and you must repeat the entire procedure from the beginning.
  21. I seem to remember APC had a special serial cable that had to be used - a standard 9-pin one wouldn't do the trick.
  22. What type of certificate are you using for Exchange? Is it a proper 3rd party issued cert? or something from your internal Cert server?
  23. How's it all going @TwistedHelixis? Well, I hope!
  24. Is there a roaming or mandatory profile associated with the new account you've created?
×
×
  • Create New...