Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Non-interactive AD account

Posted on 2011-09-23
3
Medium Priority
?
1,386 Views
Last Modified: 2013-12-09
Hi Experts,

Is there a way I can create a non-interactive or 'lowest permission level' account/group for cerain users who require RADIUS access?

Basically, I have a group of users who have an AD account for the purposes of authenticating via wireless via RADIUS using their non-domain member devices (laptops, Andriod devices etc..) and I need their logins to only work for the sole purpose of authenticating via wireless via RADIUS with no interactive logon access to any domain workstation etc...

I currently have these users in the Domain Guests, Guests group and a security group defining wireless access for the NPS policy, however of course they will still be able to login interactively.

I did create another security group for the sole purpose of 'flagging' the user for non-interactive logon by adding that security group to the 'Deny Logon Locally' group policy and having my non-interactive users in that group as well, however this also cut off authentication via wireless via RADIUS :(
0
Comment
Question by:BradyAU
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36587070
I would check for that AD LDS instance. It can be used for authentication but cannot be use for user logon. I don't know if it works for that scenario (I've never done this before) But maybe you are interested in this subject and can dig something in the Internet?

For reference please start with this MS article at
http://technet.microsoft.com/pl-pl/library/cc755080%28WS.10%29.aspx

Regards,
Krzysztof
0
 

Accepted Solution

by:
BradyAU earned 0 total points
ID: 36813735
I was more leaning to just putting the user into a group that had limited access rather than using LDS. E.g. now they are in the Guest group + the WIFI security group.
0
 

Author Closing Comment

by:BradyAU
ID: 38144580
Idea worked
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question