Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Group Policy for dot1x

Posted on 2014-03-17
1
Medium Priority
?
668 Views
Last Modified: 2014-03-18
Hello,

Would love some help on some Windows server work for a Cisco guy :)

We are developing a Dot1x solution and will need to push config from Win2008 to about 40-50 domain computers.  We are enabling computer authentication with certificates.  We have developed the GPO piece just fine but are looking for any best practices for deployment.  Here are some particular areas of concern we are facing:

 - Only a certain group of computers need dot1x (all Win7) - is putting this group in the security filter best practice?
 - We only utilize one domain policy currently. Should we develop a separate policy to push out just these few dot1x config items?
 - When does the GPO controller "push" its config out to workstations?
 - For the certificates, can you tell what templates are currently available for a certain group for auto-enroll?
- Lastly, best way to view computers that were successfully updated?


I apologize for the amount of questions stuffed into here but as I mentioned before, I'm a network guy looking for some Windows help.  Thanks.
0
Comment
Question by:L8C
1 Comment
 
LVL 22

Accepted Solution

by:
Jakob Digranes earned 2000 total points
ID: 39936107
* It might be good to filter these by security, OR - even better, create an new OU for Wireless Computers. But both work
* This is no definite answer to, depends on your likings. I'd create a separate policy, either COMPUTERS or WIRELESS and put settings in one of those
* GPO pushed during boot, and if you use GPUPDATE /FORCE in WIndows later on
* You can AUTO-ENROLL more or less all templates as long as you set permissions correct. I'd recommend copying COMPUTER TEMPLATE, call it something like MachineCert and let the wireless group be able ot autoenroll in security. Remember cert need correct intended purpose (client authentication) and Computer Template does
* No easy way in Windows to see this, but there's probably some 3rd party software - but as long as computers reboot they'll get the policy
0

Featured Post

Vote for the Most Valuable Expert

It’s time to recognize experts that go above and beyond with helpful solutions and engagement on site. Choose from the top experts in the Hall of Fame or on the right rail of your favorite topic page. Look for the blue “Nominate” button on their profile to vote.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
This Micro Tutorial will go in depth within Systems and Security in Windows 7 and will go into detail regarding Action Center, Windows Firewall, System, etc. This will be demonstrated using Windows 7 operating system.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

885 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question