Discussion:
Restrict user account to mac address
(too old to reply)
macgyver
2008-06-17 19:34:02 UTC
Permalink
Hi,
I have a client that needs to get rid of all generic login accounts due to
HIPPA requirements. Currently they user wireless barcode handheld scanners
and wireless printers that use a generic login account from AD that are hard
programmed. They are concerned that the user account could become obtained
and used to login to network pc's. Is there a way to restrict a user
account(s) in AD or a remote access policy in IAS that can restrict login it
to a certain mac address? I figure they could create an user account for each
wireless printer and scanner and restrict it to only that device or one
account for a group of mac's.
Just trying to brainstorm.
Thanks.
James McIllece [MS]
2008-06-19 19:03:30 UTC
Permalink
Post by macgyver
Hi,
I have a client that needs to get rid of all generic login accounts
due to HIPPA requirements. Currently they user wireless barcode
handheld scanners and wireless printers that use a generic login
account from AD that are hard programmed. They are concerned that the
user account could become obtained and used to login to network pc's.
Is there a way to restrict a user account(s) in AD or a remote access
policy in IAS that can restrict login it to a certain mac address? I
figure they could create an user account for each wireless printer and
scanner and restrict it to only that device or one account for a group
of mac's. Just trying to brainstorm.
Thanks.
I'm not sure if it would work for you with these devices, but you could try
MAC address authorization.

That is documented in the IAS Technical Reference section "How IAS Works."

IAS Technical Reference:
http://technet2.microsoft.com/WindowsServer/en/library/8f5c89d5-fdaf-430c-
9ef4-318f8c15baf11033.mspx?mfr=true

The only problem with this is that MAC addresses are easily spoofed, so
implementing this doesn't provide any security.
--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
Loading...