Azure NPS Extension - Conditional Access for 802.1x (Bypass MFA)

Me At Worky 21 Reputation points
2022-01-27T05:44:41.683+00:00

Hi all,

Currently using Azure NPS Extension on a RADIUS server for user based MFA dial-in authentication. We also use RADIUS on another server to authenticate Wireless 802.11 connectivity from corporate devices, without the NPS Extension.

Is it possible to bypass the MFA request on the Azure NPS server for only 802.11 devices (not users) authenticating via PEAP? So that I can consolidate RADIUS to just one server, all that is required.

Ideal Scenario: 1 RADIUS server that handles both user auth (identity verified via MFA communicated to Azure via the NPS extension), and the same server that can auth trusted devices via PEAP without attempting MFA.

Many thanks.

Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Windows for business | Windows Server | User experience | Other
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.