NAP with machine group condition


hi

i have nap tls solution want put condtion specific copmuter account , problem whenever add machine group or windwos group authentication not happening, remove cient can authenticate without problem can please advice ?

hi, here few hints.

please keep in mind nap enforcement methods not work both "machine" , "user" group conditions. also, term "machine group" , "windows group" misleading. both of these same thing, , correct term "security group." if create security group , make domain users members of group, can use condition in nps policy if enforcement method 802.1x or vpn. cannot use if enforcement method dhcp or ipsec. enforcement methods allow use security group condition if group contains computers only. post indicates using "machine group" assume security group contains computers.

three things check , make sure work correctly are:

1. did reboot client computer after joining security group? required. gpupdate /force not sufficient.

2. execute gpresult or gpresult /r on client computer verify member of security group.

3. verify client nap-capable. fqdn of computer passed in soh. therefore, if there no soh (the client non nap-capable) fail condition requires specific fqdn.

i hope helps,

-greg



Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL