Can NPS force computer AND user authentication?
i have functional 802.1x using cisco wlan microsoft nps. it capable of domain authentication against security groups on ad.
on nps have 2 separate network policies, 1 computer , other user. this fine, policy works sequentially or statement rather , statement.
so @ moment, a device valid user certificate logon can invalid computer. i'm looking ensure user on domain computer in correct security group.
anyone implemented in way machine authentication prerequisite user authentication?
regards
rob
p.s. have setup cisco acs using 'machine access restrictions' feature.
enabling nap give option combine user , machine groups in same policy , statement.
Windows Server > Network Access Protection
Comments
Post a Comment