Here’s a quick tip which may save you some time configuring Network Policies on Windows Server 2008 NPS.

It turns out you can’t have a Condition which matches both a User Group and Machine Group in Active Directory.  

The fix?  Add “Windows Groups” as the condition – and add both groups to that!


Simple when you know how – just wish I’d known that two days ago!