Users' access policy - Deny access to Network resources for users who are not part of a domain


hi there,

we have users accessing netwrok resources (internet, web portal, email services) coming non-domain joined system.

can nap policy be used restrict access network resources, although have required credentials, because coming non-domain joined system.

thanks.

raid,

hi raid,

 

thanks posting here.

 

you may consider deploy certificate base computer authentication achieve goal. can first generate , issue certificate domain computers via group policy and  configure network devices support 802.1x evaluate nps determine if computer plug network authorized , need enable port . solution applied both wired or wireless scenario :

 

provide wireless access uses digital certificate client authentication

http://technet.microsoft.com/en-us/library/dd348480(ws.10).aspx

 

provide wired access uses digital certificate client authentication

http://technet.microsoft.com/en-us/library/dd378967(ws.10).aspx

 

regards,

 

tiger li

 

technet subscriber support in forum

if have feedback on our support, please contact  tnmff@microsoft.com.


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file