# Integrating Windows Active Directory with cnMaestro

**URL:** https://community.cambiumnetworks.com/t/integrating-windows-active-directory-with-cnmaestro/60192
**Category:** Enterprise Wi-Fi Networks
**Created:** [February 8, 2019, 12:31am UTC](https://community.cambiumnetworks.com/t/integrating-windows-active-directory-with-cnmaestro/60192 "2019-02-08T00:31:32Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![nbctcp](https://d10gw3vjmzyp8.cloudfront.net/letter_avatar_proxy/v4/letter/n/c5a1d2/32.png) [@nbctcp](https://community.cambiumnetworks.com/u/nbctcp)
#### Post date: [February 8, 2019, 12:31am UTC](https://community.cambiumnetworks.com/t/integrating-windows-active-directory-with-cnmaestro/60192/1 "2019-02-08T00:31:32Z")

</div>

[https://community.cambiumnetworks.com/t5/cnMaestro/Integrating-Windows-Active-Directory-with-cnMaestro/m-p/84164](https://community.cambiumnetworks.com/t/integrating-windows-active-directory-with-cnmaestro/55048)

I am trying to achieve that link

What I am not clear

1. what are rights differences between Super User, Admin, Operator, Monitor

2. whether user must be member of those groups

what happen when an user not belong to any of those group.

could he/she still login to AP

3. how AD user join to AP. Is it using their AD password and not using WPA2 password?

tq

---

<div class="post-metadata">

### Author: ![TrevorM](https://d10gw3vjmzyp8.cloudfront.net/letter_avatar_proxy/v4/letter/t/3ec8ea/32.png) [@TrevorM](https://community.cambiumnetworks.com/u/TrevorM)
#### Post date: [February 8, 2019, 12:49am UTC](https://community.cambiumnetworks.com/t/integrating-windows-active-directory-with-cnmaestro/60192/2 "2019-02-08T00:49:38Z")

</div>

That link contains instructions to use Active Directory to authentiate login to the on-premises version of cnMaestro using Windows AD. Is that what you're trying to do? Or are you trying to use AD to authenticate users connecting to a WPA2 enterprise wireless LAN?

If it is the latter, those instructions are not applicable. Instead, you need to run a RADIUS server on your windows AD server e.g. by installing and running [Windows Network Policy Server](https://docs.microsoft.com/en-us/windows/desktop/nps/portal). Once you have done that you can then set the authentication mode for the WLAN on the cnPilot AP to WPA2-Enterprise (instead of open or WPA-PSK) and configure the RADIUS server IP and secret on it.&nbsp;The users can then connect to Wi-Fi using their AD username and password.

---

<div class="post-metadata">

### Author: ![mangibr](https://d10gw3vjmzyp8.cloudfront.net/user_avatar/community.cambiumnetworks.com/mangibr/32/25275_2.png) [@mangibr](https://community.cambiumnetworks.com/u/mangibr)
#### Post date: [March 1, 2019, 3:26am UTC](https://community.cambiumnetworks.com/t/integrating-windows-active-directory-with-cnmaestro/60192/3 "2019-03-01T03:26:11Z")

</div>

Hi, I am interested in the latter. i.e, using AD to authenticate users via Radius. We run AD from Windows Server 2012 r2. Can you provided detailed steps on how to achieve that? Thanks in advance.

---

<div class="post-metadata">

### Author: ![nbctcp](https://d10gw3vjmzyp8.cloudfront.net/letter_avatar_proxy/v4/letter/n/c5a1d2/32.png) [@nbctcp](https://community.cambiumnetworks.com/u/nbctcp)
#### Post date: [March 1, 2019, 6:02am UTC](https://community.cambiumnetworks.com/t/integrating-windows-active-directory-with-cnmaestro/60192/4 "2019-03-01T06:02:55Z")

</div>

> * * *
> [@mangibr](https://community.cambiumnetworks.com/u/mangibr/summary)&nbsp;wrote:  
> Hi, I am interested in the latter. i.e, using AD to authenticate users via Radius. We run AD from Windows Server 2012 r2. Can you provided detailed steps on how to achieve that? Thanks in advance.
> * * *

[http://community.cambiumnetworks.com/t5/cnPilot-E-Series-Enterprise-APs/How-to-configure-and-use-Realm-in-cnPilot-E-Series-Enterprise/m-p/87355#M107](https://community.cambiumnetworks.com/t/how-to-configure-and-use-realm-in-cnpilot-e-series-enterprise-aps-and-cnmaestro/56012)
