Share via


NPS and local Windows server users

Question

Friday, July 12, 2013 11:13 AM

We need to migrate RADIUS server supporting Cisco VPN server from old FreeBSD server to a new server running Windows Server 2012. I've set up and configured Network Policy Server to support Cisco VPN server as a RADIUS client. Now AD domain users can authenticate successfully and establish VPN connection.

However, to finish migration, we need to transfer 130 or so old user accounts to the new RADIUS server. I don't want to create them in AD. I'd like to store them in local Windows user database. However, if I add local user groups to the network policy allowing to authenticate against RADIUS server, VPN connections with those credentials could not be established. NPS simply does not apply the policy to the local user (in the log I can see that the last policy checked is "Connections to other access servers" which is the last in the policy list).

How could I force NPS to authenticate users against the local user database as well?

All replies (2)

Tuesday, July 16, 2013 3:06 AM âś…Answered

Hi Evgeniy,

We can refer to this article to configure NPS using the local Security Accounts Manager (SAM) database.

Configure NPS to Use the Security Accounts Manager Database

http://technet.microsoft.com/en-us/library/cc771364(v=ws.10).aspx

Hope this helps.

Best Regards Jeremy Wu

Tuesday, July 16, 2013 4:01 AM

Jeremy,

Thank you a lot.