Hi all,
You can find information on this link:
https://documentation.meraki.com/MS/Access_Control/MS_Switch_Access_Policies_(802.1X)
Specifically for this post:
Dynamic VLAN Assignment
In lieu of CoA, MS switches can still dynamically assign a VLAN to a device by assigned the VLAN passed in the Tunnel-Pvt-Group-ID attribute. It may be necessary to perform dynamic VLAN assignment on a per computer or per user basis. This can be done on your wired network via 802.1x authentication (RADIUS). In order to do so, the following RADIUS attributes must be configured and passed in the RADIUS Access-Accept message from the RADIUS server.
- Tunnel-Medium-Type: Choose 802 (Includes all 802 media plus Ethernet canonical format) for the Attribute value Commonly used for 802.1X.
- Tunnel-Private-Group-ID: Choose String and enter the VLAN desired (ex. "500"). This string will specify the VLAN ID 500.
- Tunnel-Type: Choose Attribute value Commonly used for 802.1X and select Virtual LANs (VLANs).
Once these attributes are configured on the RADIUS server, client devices can receive their VLAN assignment dynamically.
For more information on how to configure with NPS, visit Microsoft's article on Configuring a Network Policy for VLANs.
Dynamic VLAN Assignment is not supported on the voice VLAN/domain.