Network Policy Server for Certificate based authentications

Namless Shelter 231 Reputation points
2024-04-21T02:53:47.25+00:00

Dear ppl,

Just wondering if NPS Network Policy Server can only do AD existed devices authentication (CA RootCA certificate based) and User based Authentication to 802.1x Wifi? It won't be able to do certificate-based authentications to any Intune Enrolled (SCEP or PKCS) devices (None Domain Joined iPads and Android etc), might have to look into different Cloud Radius solution?

Thanks a lot

Larry

Windows Network
Windows Network
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.Network: A group of devices that communicate either wirelessly or via a physical connection.
696 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,783 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Mamady CONDE 0 Reputation points
    2024-04-21T03:35:10.2666667+00:00

    Network Policy Server (NPS) primarily integrates with Active Directory for device authentication and supports user-based authentication for 802.1x Wi-Fi. However, if you need certificate-based authentication for non-domain joined devices like iPads and Android devices enrolled in Intune, you might need to explore cloud-based RADIUS solutions that support the integration you require, such as those offered by Intune or other third-party providers.


  2. Crystal-MSFT 45,656 Reputation points Microsoft Vendor
    2024-04-22T02:17:14.28+00:00

    @Namless Shelter, Thanks for posting in Q&A. If you only have an on-premises NPS server and want to perform certificate-based authentication for Intune-enrolled devices, you may need to consider a cloud RADIUS solution.

    Deploying an Intune Certificate Connector for SCEP or PKCS can provide additional security benefits, such as simplifying certificate deployment and management for Intune-enrolled devices. However, it may not be necessary if you only have an on-premises NPS server and cannot perform certificate-based authentication for Intune-enrolled devices without a RADIUS proxy.

    https://video2.skills-academy.com/en-us/windows-server/networking/technologies/nps/nps-best-practices#authentication

    https://video2.skills-academy.com/en-us/windows-server/networking/technologies/nps/nps-plan-server#plan-the-use-of-authentication-methods

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. Jing Zhou 4,745 Reputation points Microsoft Vendor
    2024-04-23T05:53:11.88+00:00

    Hello,

     

    Thank you for posting in Q&A forum.

    NPS Server can work on device that joint on Intune platform. However you will need to configure the network policy on Intune platform.

    For further details, please kindly refer to Microsoft Official Documentation below:

    https://video2.skills-academy.com/en-us/mem/intune/configuration/wi-fi-settings-configure

    To help other customers who may be facing the same issue, please don't forget to vote if the reply is helpful.

    Best regards,

    Jill Zhou

    0 comments No comments