Greetings - I’m following this procedure to enable RADIUS authentication for wireless clients:<\/p>\n
http://community.spiceworks.com/topic/198931-non-domain-devices-on-my-domain-wifi-network<\/a><\/p>\n
The OP follows up saying he can authenticate ANY<\/em> device as long as the user has a domain username/password (here: http://community.spiceworks.com/topic/198931-non-domain-devices-on-my-domain-wifi-network<\/a> ).<\/p>\n I am looking to allow ANY device to connect as long as the user/password is a valid domain user (in certain AD groups - I’m using “Domain Users” for testing). I have a lot of non-domain devices with valid users in this situation.<\/p>\n At this point, I can’t get any<\/em> device to connect and authenticate - even domain-joined devices.<\/p>\n Questions:Can I allow devices to connect if a valid user/password is entered (being a member of groups I specify in the NPS Policy, of course)?<\/p>\n Is a certificate required for any device whether domain-joined or not?<\/p>\n (Also, it seems in Windows 8.1, we can no longer get to the wireless connection properties to manage some of the settings - such as the checkbox to “use Windows user”)<\/p>\n Thanks in advance!<\/p>","upvoteCount":3,"answerCount":3,"datePublished":"2014-02-19T21:59:55.000Z","author":{"@type":"Person","name":"david-kiernan","url":"https://community.spiceworks.com/u/david-kiernan"},"acceptedAnswer":{"@type":"Answer","text":" I actually figured it out, by changing the cipher to TKIP (despite the warning on the link mentioned in OP). The goal is to allow users to authenticate to the wireless network with their domain user and password - whether the device is domain-joined or not (those are the requirements I have to work with on this project - not best practice, I understand, but best practice and decision-makers are often not on the same page).<\/p>\n First, in the Role for Network Policy and Access Services, make sure the RRAS and NPS role services are added.<\/p>\n I added a RADIUS Client for the Ubiquiti AP’s (not the UniFi management station).<\/p>\n In the NPS, I changed the Network Policy to:<\/p>\n Overview:Enabled, Grant Access, Type: unspecified<\/p>\n Conditions:User Groups (specific AD groups)<\/p>\n Constraints (here are the key settings)Authentication: EAP (PEAP), MS-CHAPv2, MS-CHAP, CHAP, PAPNAS Port: Wireless<\/p>\n Settings:No changes (in this network, the wifi clients get DHCP, VLAN on same subnet as wired clients)<\/p>","upvoteCount":0,"datePublished":"2014-02-20T14:04:11.000Z","url":"https://community.spiceworks.com/t/server-2008r2-nps-wireless-via-radius-user-password-only/278810/2","author":{"@type":"Person","name":"david-kiernan","url":"https://community.spiceworks.com/u/david-kiernan"}},"suggestedAnswer":[{"@type":"Answer","text":" Greetings - I’m following this procedure to enable RADIUS authentication for wireless clients:<\/p>\n