802.1x auth without certificate on clients

npsradiuswindows-server-2012-r2

I'm trying to implement WPA-Enterprise authentication on my UniFi Controller (3.1.10) without the need for certificates on clients.

My RADIUS server will be Windows Server 2012R2 with NPS role installed.

All I want is for my devices (Macs + Android) to auth on the Wi-Fi with an AD account for the person using it.

Could anyone shed any light on this scenario?

Any help is much appreciated,

Cheers!

EDIT
I have attempted to set this up from what @Nathan has mentioned below

Added RADIUS Client http://i.stack.imgur.com/E4R9M.png

Added Network Policy http://i.stack.imgur.com/M1N6r.png

From an NPS view, does this look correct?

Best Answer

I actually have this exact setup on my network. All you need to do is add each AP as a "Trusted RADIUS Client" in NPS and configure the other settings as you see fit. On the UniFi, just add the correct information (IP and secret) for it to start working.

When connecting with Windows clients at least, you'll need to configure each one to not validate the server certificate if you don't have a trusted certificate installed or association will fail.

Related Topic