Wireless issues when AD password out of sync


hi,  we have following issue happening , wanted see if has security conscious suggestions.

most of our users have laptops (xp/7) configured wireless via peap (user authentication).  users access wireless via ad group, we use funk radius auth.  in our environment, have lot of shared workstations in environment many of same users have use.  sometimes end changing ad password on 1 of these shared machines , creates issue on personal machine since password out of sync.  it leads lockouts since have citrix or outlook running on laptop.  the laptop loses wireless connection, , user unable on network until plug machine in or reboot (pre login wireless auth enabled) refresh cached credentials.

educating users (doctors) on where/how change password not seem work, , using single generic account users wireless access not direction want go into.  any ideas?

 

 

are laptops part of domain or stand alone computers?

if laptops part of domain change wlan authentication computer authentication instead of current user authentication. way users have access domain , able perform both domain logon , correctly process password policies.

another option use certificate based authentication access wlan continue give users access long user account valid , not been locked reasons! option can used regardless computer domain membership.

a third option use smart cards both logon , wlan access , skip password management altogether. option might complicated implement @ same time most convenient for users.

/hasain 



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS