product icon

How do I set up Network Policy Server (NPS) in Windows Server for LastPass Universal Proxy RADIUS protocol?

    Before you begin:

    The system administrator should specify which network policy uses Universal Proxy as the RADIUS server for authentication. In the following configuration the appropriate network policy should be used.

    About this task: The configuration was tested with the following server versions:
    • Windows Server 2008 R2
    • Windows Server 2019
    Note: This feature requires an account with the LastPass Business + Advanced MFA add-on. How do I upgrade my LastPass Business account with an add-on?

      Configure the network policy:

      1. Open the Server Manager.
      2. Go to Network Policies and open the Connections to other access servers policy.
      3. In the Connections to other access servers Properties window, Overview tab, check the following:
        1. Policy enabled is checked.
        2. Grant access is selected.
        3. Type of network access server is Unspecified.
      4. Select the Constraints tab in the Connections to other access servers Properties window.
      5. Select Authentication Methods in the Constraints group box.
      6. Check the following checkboxes:
        • Encrypted authentication (CHAP)
        • Unencrypted authentication (PAP, SPAP)
      7. Click OK.
        If you use CHAP, set the Store passwords using reversible encryption for your users:
        1. In the Active Users and Computers window, go to Users.
        2. Double-click on the user.
        3. In the Properties pop-up window click the Account tab.

        4. Check the Store passwords using reversible encryption checkbox.
        5. Click OK.
        6. Right-click on the user, select Reset Password...
        7. In the Reset Password pop-up window, enter your current password into the New password and Confirm password fields. It is necessary to re-type the current password in order for the new reversible password encryption option to take effect.
        8. Click OK.

      Configure your VPN server:

      1. Set LastPass Universal Proxy as the RADIUS server for authentication. For this, set the RADIUS server's IP address to the IP address hosting the Universal Proxy service.
      2. Configure LastPass Universal Proxy for RADIUS using the command line interface (CLI).