![]() Before making changes to the registry, you should back up any valued data on the computer. Please note: Incorrectly editing the registry can severely damage your system. In order to do that, you should firstly enable the MAC authorization in the NAS(network access server), then create the user accounts for each MAC address in the AD(Activeĭirectory Domain server), modify the registry key " User Identity Attribute" under HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy toįor more details, please refer to (WS.10).aspx. Microsoft does not guarantee the accuracy of this information. ![]() Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Please refer to the following articles discuss how MAC-Based Access Control works and provides step-by-stepĬonfiguration instructions for Microsoft NPS. But non work devices (laptops/iphone etc) would need to be mac address filtered.ĭoes anyone have an suggestions on how can I achieve this? My server environment in 2012R2 and my work provided endpoints are Windows 10 Pro or I devicesīased on my knowledge, we can use the method MAC-Based Access Control on NPS to achieve that for preventing unauthorized access to the Wireless LAN. ![]() Company provided laptops don’t need MAC filtering as they are trusted by default (they are in the sec group). I want to implement some form of MAC filtering at the NPS server. I don’t currently have anything in place to filter out non work provided equipment on the user network so in theory anyone could join the user network which has access to all company IT resources. This network is secured via WPA2 Enterprise with an NPS server and a network policy further filtering by Windows AD sec group (users and computers). This network has no access to company resources and just has internet access Guest – non employees use this and is secured by WPA2 shared key. ![]() ![]() I have 2 wireless networks for my company: ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |