Does the machine authentication need to be done in the connection request policy and or network policies on the nps server? For example do I need to modify the conditions and add a machine group? Does it also need to be specified on the GPO object thats being pushed out to the machine as well? In looking over the guide from meraki
It appears that they are using user authentication for the policy on the nps server but machine authentication on the gpo.
If you have users who are mostly using WiFi you need to permit both their computer (I typically allow Domain Computers) and their user account.
Otherwise you get this situation when the machine boots up; it is not connected to the WiFi. The user tries to login, but it can only use cached credentials. If the credentials don't match a newer change then they can actually log into the machine but not attach to the WiFi because the WiFi only knows the new credentials (it is talking to AD).
If you allow machine authentication as well the machine starts up. It can now also do group policy processing. The user goes to log in, but because the machine can now talk to a domain controller it doesn't have to use cached credentials. It actually authenticates directly against the AD controller. If that passes the users logins in, and then re-authenticates to the WiFi using the known good credentials.
So basically I need to modify the connection request policy and the network policies and put in domain users and domain computers?
So nevermind apparently I mispoke. You can only setup user and machine auth on the network policy only on the nps server. The connection request policy doesnt have those options. Im attaching screenshots of what my changes look like. What sort of errors should I be looking for in the event log if something isnt working right? Crossing my fingers!!
Thanks
look
"Connection Request Policies" just say what requests to process localling on "this" server rather than sending them to another server.
You should not need to change the Connect Request Policies. The default policy, which says to process everything localy, is fine.
Hi zfrangi,
Can you please tell me how to get to the screenshot you have listed. I may need to start a new conversation, but were having an issue, in short - we have Meraki setup to use Radius server, however, when a laptop connects, the user is not prompted to enter username and password which we want to happen, but when they connect with their mobile it does have a prompt and the screenshot you have posted I can find anywhere to enable user authentication which may be our issue. Any help appreciated, if I do need to start a new conversation please let me know.
Thank You.