NAP with machine group condition
hi
i have nap tls solution want put condtion specific copmuter account , problem whenever add machine group or windwos group authentication not happening, remove cient can authenticate without problem can please advice ?
hi, here few hints.
please keep in mind nap enforcement methods not work both "machine" , "user" group conditions. also, term "machine group" , "windows group" misleading. both of these same thing, , correct term "security group." if create security group , make domain users members of group, can use condition in nps policy if enforcement method 802.1x or vpn. cannot use if enforcement method dhcp or ipsec. enforcement methods allow use security group condition if group contains computers only. post indicates using "machine group" assume security group contains computers.
three things check , make sure work correctly are:
1. did reboot client computer after joining security group? required. gpupdate /force not sufficient.
2. execute gpresult or gpresult /r on client computer verify member of security group.
3. verify client nap-capable. fqdn of computer passed in soh. therefore, if there no soh (the client non nap-capable) fail condition requires specific fqdn.
i hope helps,
-greg
Windows Server > Network Access Protection
Comments
Post a Comment