Can NPS force computer AND user authentication?


hi,

i have functional 802.1x using cisco wlan microsoft nps.  it capable of domain authentication against security groups on ad.  

on nps have 2 separate network policies, 1 computer , other user.  this fine, policy works sequentially or statement rather , statement.

so @ moment, a device valid user certificate logon can invalid computer. i'm looking ensure user on domain computer in correct security group.

anyone implemented in way machine authentication prerequisite user authentication?

regards
rob

p.s. have setup cisco acs using 'machine access restrictions' feature.

enabling nap give option combine user , machine groups in same policy , statement.



Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2