Solved

Non-interactive AD account

Posted on 2011-09-23
3
1,329 Views
Last Modified: 2013-12-09
Hi Experts,

Is there a way I can create a non-interactive or 'lowest permission level' account/group for cerain users who require RADIUS access?

Basically, I have a group of users who have an AD account for the purposes of authenticating via wireless via RADIUS using their non-domain member devices (laptops, Andriod devices etc..) and I need their logins to only work for the sole purpose of authenticating via wireless via RADIUS with no interactive logon access to any domain workstation etc...

I currently have these users in the Domain Guests, Guests group and a security group defining wireless access for the NPS policy, however of course they will still be able to login interactively.

I did create another security group for the sole purpose of 'flagging' the user for non-interactive logon by adding that security group to the 'Deny Logon Locally' group policy and having my non-interactive users in that group as well, however this also cut off authentication via wireless via RADIUS :(
0
Comment
Question by:BradyAU
  • 2
3 Comments
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36587070
I would check for that AD LDS instance. It can be used for authentication but cannot be use for user logon. I don't know if it works for that scenario (I've never done this before) But maybe you are interested in this subject and can dig something in the Internet?

For reference please start with this MS article at
http://technet.microsoft.com/pl-pl/library/cc755080%28WS.10%29.aspx

Regards,
Krzysztof
0
 

Accepted Solution

by:
BradyAU earned 0 total points
ID: 36813735
I was more leaning to just putting the user into a group that had limited access rather than using LDS. E.g. now they are in the Guest group + the WIFI security group.
0
 

Author Closing Comment

by:BradyAU
ID: 38144580
Idea worked
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

822 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question