Users' access policy - Deny access to Network resources for users who are not part of a domain


hi there,

we have users accessing netwrok resources (internet, web portal, email services) coming non-domain joined system.

can nap policy be used restrict access network resources, although have required credentials, because coming non-domain joined system.

thanks.

raid,

hi raid,

 

thanks posting here.

 

you may consider deploy certificate base computer authentication achieve goal. can first generate , issue certificate domain computers via group policy and  configure network devices support 802.1x evaluate nps determine if computer plug network authorized , need enable port . solution applied both wired or wireless scenario :

 

provide wireless access uses digital certificate client authentication

http://technet.microsoft.com/en-us/library/dd348480(ws.10).aspx

 

provide wired access uses digital certificate client authentication

http://technet.microsoft.com/en-us/library/dd378967(ws.10).aspx

 

regards,

 

tiger li

 

technet subscriber support in forum

if have feedback on our support, please contact  tnmff@microsoft.com.


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

directory stack

After enabling Windows Server 2012 R2 DHCP Failover Getting Packet dropped because of Client ID hash mismatch

WMI Repository 4GB limit - Win 2003 Ent Question