In our setup we would like to authenticate laptops and users separately. So if the laptop belongs to a particular AD group and the user belongs to a particular AD group then they are allowed to join the hidden WiFi network.
In our current setup this kind of works. We have a group policy that supplies the laptops with the required certificate if they belong to the right AD Group. Then in NPS we have it do user authentication based on the User Group in AD. This does work with one problem, the logon script fails to run 100% of the time.
If we switch modes and use computer authentication, and base it on the Machine group, then the logon script works 100% of the time, however even local users to the laptop have access to the WiFi network, something we do not want.
We have the group policy set to wait for network, we have a dial-up delay set and the scripts are set to run async. Still no luck.
1) Any thoughts on how to get the logon scripts to run? or
2) setup NPS to do computer auth first, then user auth second?