<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1X authentication fails after restricting AD user logon to specific computers in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/802-1x-authentication-fails-after-restricting-ad-user-logon-to/m-p/122209#M2194</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;When ExtremeControl is configured to directly integrate with Active Directory. (LDAP Authentication) it uses an NTLM authentication that is sourced from the Control appliance.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It obtains the users credentials viae 802.1x and authenticates to the domain controller with those credentials.&lt;BR /&gt;&lt;BR /&gt;From the domain Controller's perspective, the user is logging onto the Control appliance, not onto the computer that is authenticating to Control. You'll find that there are logs in the domain controller that indicate the users are all logging onto the Control appliance.&lt;BR /&gt;&lt;BR /&gt;At a minimum, all users MUST have permission to logon to all ExtremeControl appliances. If you remove the ability to logon to the Control appliance, the authentication will be rejected.&lt;BR /&gt;&lt;BR /&gt;Since Control is masking the source computer, I don't think restrictions for logon based on machine is going to work.&lt;BR /&gt;&lt;BR /&gt;If you change Control from an LDAP authentication to a proxy RADIUS configuration and set up NPS on the Domain Controller it should operate the way you want.&amp;nbsp; I can't think of a way to restrict each user to their specific machine using the features within Control that is efficient.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
    <pubDate>Sat, 25 Jul 2026 15:24:16 GMT</pubDate>
    <dc:creator>Ryan_Yacobucci</dc:creator>
    <dc:date>2026-07-25T15:24:16Z</dc:date>
    <item>
      <title>802.1X authentication fails after restricting AD user logon to specific computers</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/802-1x-authentication-fails-after-restricting-ad-user-logon-to/m-p/122161#M2190</link>
      <description>&lt;P class=""&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I would like to ask if anyone has experienced a similar issue while working with &lt;STRONG&gt;ExtremeControl&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Our customer has the following environment:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;2 × ExtremeControl Engines&lt;/LI&gt;&lt;LI&gt;1 × ExtremeCloud IQ Site Engine&lt;/LI&gt;&lt;LI&gt;2 × Wireless LAN Controllers (WLCs)&lt;/LI&gt;&lt;LI&gt;Active Directory used as the authentication source&lt;/LI&gt;&lt;LI&gt;802.1X authentication (PEAP/MSCHAPv2)&lt;/LI&gt;&lt;LI&gt;Dynamic VLAN assignment after successful authentication&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The authentication workflow is the following:&lt;/P&gt;&lt;P&gt;Client&lt;BR /&gt;│&lt;BR /&gt;│ Connects to SSID (802.1X)&lt;BR /&gt;▼&lt;BR /&gt;Wireless AP&lt;BR /&gt;│&lt;BR /&gt;▼&lt;BR /&gt;WLC&lt;BR /&gt;│&lt;BR /&gt;▼&lt;BR /&gt;ExtremeControl (ACE)&lt;BR /&gt;│&lt;BR /&gt;│ RADIUS Authentication&lt;BR /&gt;▼&lt;BR /&gt;Active Directory&lt;BR /&gt;│&lt;BR /&gt;│ User authenticated&lt;BR /&gt;▼&lt;BR /&gt;ExtremeControl returns VLAN&lt;BR /&gt;│&lt;BR /&gt;▼&lt;BR /&gt;Endpoint receives VLAN and network access&lt;/P&gt;&lt;H3&gt;The issue&lt;/H3&gt;&lt;P&gt;At the customer's request, they modified the user's Active Directory account.&lt;/P&gt;&lt;P&gt;In:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Active Directory Users and Computers&lt;/STRONG&gt;&lt;BR /&gt;→ User Properties&lt;BR /&gt;→ &lt;STRONG&gt;Account&lt;/STRONG&gt;&lt;BR /&gt;→ &lt;STRONG&gt;Log On To...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Instead of allowing the user to log on to all computers, they restricted the account to &lt;STRONG&gt;only one specific computer&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;After applying this change, the user is no longer able to authenticate through the 802.1X wireless SSID.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="williamszen666_0-1784564309178.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9442iE3B12A0BF3DC1D66/image-size/medium?v=v2&amp;amp;px=400" role="button" title="williamszen666_0-1784564309178.png" alt="williamszen666_0-1784564309178.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;H3&gt;My questions&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Has anyone encountered this behavior before?&lt;/LI&gt;&lt;LI&gt;Does ExtremeControl (or Windows NPS/LDAP authentication) validate the &lt;STRONG&gt;Log On To&lt;/STRONG&gt; restriction during 802.1X authentication?&lt;/LI&gt;&lt;LI&gt;Is this expected behavior from Active Directory?&lt;/LI&gt;&lt;LI&gt;Is there any recommended approach if the customer wants to restrict interactive Windows logons without affecting wireless 802.1X authentication?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any insights or best practices would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 16:19:01 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/802-1x-authentication-fails-after-restricting-ad-user-logon-to/m-p/122161#M2190</guid>
      <dc:creator>williamszen666</dc:creator>
      <dc:date>2026-07-20T16:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X authentication fails after restricting AD user logon to specific computers</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/802-1x-authentication-fails-after-restricting-ad-user-logon-to/m-p/122166#M2191</link>
      <description>&lt;P&gt;I appreciate the detailed troubleshooting steps. Problems involving AD policies and 802.1X can be difficult to diagnose, so it's great to have a clear explanation of what was happening.&amp;nbsp;&lt;A href="https://www.paylocity.com.co" target="_self"&gt;&lt;SPAN&gt;Paylocity&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2026 08:57:48 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/802-1x-authentication-fails-after-restricting-ad-user-logon-to/m-p/122166#M2191</guid>
      <dc:creator>jerica63figaro</dc:creator>
      <dc:date>2026-07-21T08:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X authentication fails after restricting AD user logon to specific computers</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/802-1x-authentication-fails-after-restricting-ad-user-logon-to/m-p/122209#M2194</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;When ExtremeControl is configured to directly integrate with Active Directory. (LDAP Authentication) it uses an NTLM authentication that is sourced from the Control appliance.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It obtains the users credentials viae 802.1x and authenticates to the domain controller with those credentials.&lt;BR /&gt;&lt;BR /&gt;From the domain Controller's perspective, the user is logging onto the Control appliance, not onto the computer that is authenticating to Control. You'll find that there are logs in the domain controller that indicate the users are all logging onto the Control appliance.&lt;BR /&gt;&lt;BR /&gt;At a minimum, all users MUST have permission to logon to all ExtremeControl appliances. If you remove the ability to logon to the Control appliance, the authentication will be rejected.&lt;BR /&gt;&lt;BR /&gt;Since Control is masking the source computer, I don't think restrictions for logon based on machine is going to work.&lt;BR /&gt;&lt;BR /&gt;If you change Control from an LDAP authentication to a proxy RADIUS configuration and set up NPS on the Domain Controller it should operate the way you want.&amp;nbsp; I can't think of a way to restrict each user to their specific machine using the features within Control that is efficient.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2026 15:24:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/802-1x-authentication-fails-after-restricting-ad-user-logon-to/m-p/122209#M2194</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2026-07-25T15:24:16Z</dc:date>
    </item>
  </channel>
</rss>

