Hi Charlie, In IAS, try setting up a new custom remote access policy and set the policy condition to match the attribute Windows-Group. When you select it you will get a pop up asking what groups to match, select your group and finish the policy of like normal. Also, I think there is a default microsoft policy which you might want to set to deny if you are not using it. RADIUS should only permit a member now if it is a member of your SSL-USER group. Even though you are matching * in your role mapping policy, it will still be ok as radius will only let users on who match the policy-condition you set through IAS. This works for a simple single group role mapping, if you want to define different roles based on group membership - this bit I am not so sure about sorry. Would be intrested to know how though - I believe that you can do it by forwarding an attribute from ias to the ive but not sure how to do that. Cheers, Gareth
... View more