IAS RADIUS auth multiple domains

  • Thread starter Thread starter Chip Greel
  • Start date Start date
C

Chip Greel

I have a PPTP RAS server which does IAS/radius auth to a
domain controller at the top level of our AD domain. It
authenticates users in the parent domain, but not child
domains. Event log on DC reports "access request for
user CORP\chip.greel was discarded". Reason - "the
service does not have sufficient access rights to process
the request". The DC and PPTP servers are listed as
valid RAS and IAS servers in the top level domain abd
child domains. Users from the child domain are able to
use netlogon services from the DC in the parent domain as
well.
 
Fix - Add the IAS server doing the authentication to the
RAS and IAS servers list in each child domain. Found
under "Active Directory Users and Computers - Users - RAS
and IAS Servers".
 
Back
Top