Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

If a VPN, dial-up, Wi-Fi, or 802.1X user is rejected despite matching an access policy, check the account’s Network Access Permission setting and the NPS policy that processes the request. Modern Windows Server uses Network Policy Server (NPS), the replacement for the older Internet Authentication Service (IAS). The usual centralized-access configuration is to set the user to Control access through NPS Network Policy and authorize access through narrowly scoped NPS network policies. Use Ignore user account dial-in properties only when the matching policy should deliberately bypass all user-level dial-in attributes.

How user dial-in properties affect NPS authorization

Successful authentication does not automatically mean that a user is authorized to connect. Authentication confirms that the credentials are valid; authorization determines whether the user may connect through the particular VPN server, wireless access point, switch, or other RADIUS client under the policy’s conditions.

NPS normally evaluates the matching network policy together with the user account’s dial-in properties. A user-level Deny access setting can therefore reject a request that would otherwise match a policy granting access. Conversely, an explicit Allow access setting can produce results that administrators did not expect when they intended group membership and NPS policy to control access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft documents this behavior in its NPS Access Permission guidance.

User account setting Meaning
Allow access Explicitly permits network access at the account level, subject to the applicable policy and connection requirements.
Deny access Explicitly rejects the user’s network-access request unless the matching NPS policy is configured to ignore user account dial-in properties.
Control access through NPS Network Policy Defers the authorization decision to the applicable NPS network policy.

Older systems use related labels: IAS instead of NPS, Remote Access Policy instead of Network Policy, and Control access through Remote Access Policy instead of the current NPS wording.

Change one user’s Network Access Permission

Use this procedure for an Active Directory user account:

  1. Open Active Directory Users and Computers.
  2. Locate the user, right-click the account, and select Properties.
  3. Open the Dial-in tab.
  4. Under Network Access Permission, select Allow access, Deny access, or Control access through NPS Network Policy.
  5. Select Apply, then OK.

For centrally managed VPN or RADIUS authorization, Control access through NPS Network Policy is normally the appropriate setting. The user must still satisfy the conditions and constraints of a matching NPS policy, such as group membership, authentication method, connection type, and time restrictions.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use Allow access or Deny access as intentional per-user exceptions rather than as a substitute for a consistent group-based policy design. Accounts created in newer environments may default to NPS policy control, but do not assume that value for older, migrated, locally provisioned, or custom-managed accounts.

Rank #2
GigaMediaGroup Server 2025 Standard 16 Core OEM English Version NEW
  • Server 2025 will be delivered by post, FPP version
  • Enterprise Security – Built-in advanced security features including Hotpatching for seamless updates and Credential Guard to protect against unauthorized access.
  • Hybrid Cloud Integration – Connects seamlessly with cloud-based services for efficient management of on-premise and cloud infrastructure
  • Optimized Performance – Enhanced networking and storage capabilities with improved data handling and support for high-performance workloads
  • User-Friendly Interface – A modernized desktop experience with streamlined management tools such as WinGet and Terminal.

Configure NPS to ignore user dial-in properties

The modern NPS equivalent of the old IAS attribute Ignore-User-Dialin-Properties is a setting on an individual network policy:

  1. Open Server Manager.
  2. Select Tools → Network Policy Server.
  3. Expand Policies → Network Policies.
  4. Double-click the policy that should control the request.
  5. On the Overview tab, find Access Permission.
  6. Select Ignore user account dial-in properties.
  7. Select OK.

This is not a global NPS switch. It applies only to the policy being edited, and only when that policy is the one that matches the connection request. NPS uses that policy’s authorization decision instead of the user account’s dial-in properties for the matching request.

Important: “Ignore” means more than ignoring Allow or Deny. It also prevents NPS from using user-level caller ID, callback, static IP address, and static-route settings. Microsoft describes these consequences in its Access Permission documentation.

When should you enable the ignore setting?

Usually appropriate

  • Your organization authorizes access through AD groups and NPS conditions.
  • Legacy user accounts contain inconsistent Allow or Deny values.
  • The connection type does not use traditional dial-in attributes, as is common with some wireless and switch-authentication deployments.
  • You want a particular policy to provide one centrally managed authorization decision.

Use caution

  • Caller ID: the user’s caller-ID restriction will not be applied.
  • Callback: user-level callback configuration will not be used.
  • Static IP addresses: the account’s assigned address will not be applied.
  • Static routes: user-level route attributes will not be applied.
  • Mixed environments: VPN, dial-up, Wi-Fi, wired 802.1X, and switch access may require different policies and attributes.

For a traditional dial-up or VPN deployment that relies on any of these settings, leaving user dial-in properties active may be necessary. For wireless or wired 802.1X, a separate policy that ignores irrelevant dial-in attributes can avoid sending unsupported attributes to the access device. Microsoft notes that some wireless devices may disconnect a client when they receive unsupported dial-in attributes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How NPS chooses the policy

NPS processes network policies from top to bottom:

  1. It evaluates the first policy’s conditions against the request.
  2. If the conditions do not match, it evaluates the next policy.
  3. The first matching policy handles the request.
  4. That policy’s access decision and constraints determine whether NPS returns an Access-Accept or Access-Reject response.

Policy order is therefore part of authorization, not just an organizational preference. Place specific or restrictive policies above broader policies when necessary. A broad grant policy placed first may prevent a later restrictive policy from being evaluated; a broad deny policy placed too high may block intended users.

Rank #3
Windows Server 2025 User CAL 5 pack
  • Offers quick and easy installation on PC
  • The software is licensed for 5 User CAL

Check the policy’s network connection method or NAS type as well. A policy restricted to VPN or dial-up may not match a wireless or wired 802.1X request. Microsoft’s network-policy configuration guidance covers policy conditions, order, and access permission.

Historical IAS and Windows Server 2003 procedure

The original procedure dates to the IAS and Windows Server 2003 era. On a legacy IAS server, administrators opened the relevant remote access policy, selected Profile → Advanced, added Ignore-User-Dialin-Properties, and set its Boolean value to True. The change had to be repeated for every policy that should ignore user-level dial-in properties.

Do not treat IAS terminology as the current Windows Server interface. NPS is installed through the Network Policy and Access Services (NPAS) role on supported modern Windows Server releases, including Windows Server 2016, 2019, 2022, and 2025. See Microsoft’s NPS overview for the role and supported access scenarios.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Legacy scripting example

Microsoft documents the following legacy Setdialincallback syntax for changing dial-in settings:

Setdialincallback /user:<username> /server:<server> /dialin:<ALLOW|DENY|RAS> /number:<NONE|"number">

The values mean ALLOW for Allow access, DENY for Deny access, and RAS for control through the remote-access policy. The current interface calls the third option Control access through NPS Network Policy. Treat this as a legacy scripting example; use a tested, version-appropriate automation method for new deployments. The documented reference is Microsoft’s Changing Dial-In Settings page.

Prerequisites and directory permissions

  • Editing NPS policies requires administrative rights or equivalent delegated permissions.
  • Creating network policies through Microsoft’s documented procedure requires appropriate domain administrative rights or equivalent delegation.
  • When NPS reads user dial-in properties from AD DS, add the NPS computer account to the RAS and NPSs group in each relevant domain, as required by Microsoft’s NPS guidance.
  • For local accounts, manage account properties through Local Users and Groups, not Active Directory Users and Computers.

These permissions and account-database distinctions matter when the Dial-in tab is missing, values cannot be changed, or NPS cannot read the expected directory attributes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot a policy that grants access but the user is denied

Work through the following sequence and change one setting at a time:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Identify the access path: RRAS VPN, dial-up, wireless 802.1X, wired 802.1X, switch, or another RADIUS client.
  2. Identify the processing NPS server: verify which server receives the request rather than editing a different NPS instance.
  3. Separate authentication from authorization: confirm that credentials, certificates, VPN negotiation, and other authentication steps succeed.
  4. Inspect the user’s Dial-in tab: look for an unintended Deny access or Allow access value.
  5. Find the first policy that should match: check policy order, enabled state, user or group conditions, and NAS type.
  6. Check access permission: verify whether the policy grants or denies access and whether Ignore user account dial-in properties is enabled on that exact policy.
  7. Check constraints: review authentication method, encryption, tunnel type, time restrictions, and other policy requirements.
  8. Check directory access: confirm the NPS server can read the account and required group membership from AD DS.
  9. Check for proxying: a connection request policy may forward the request to another RADIUS server, making the remote server the final authorization authority.
  10. Review logs: inspect NPS accounting and security logs for the selected policy, rejection reason, and returned RADIUS result.
  11. Retest: reproduce the request after each deliberate change.

Enabling the ignore option should not be the first diagnostic step. It can conceal a directory-account configuration problem and remove legitimate user-specific restrictions. Microsoft explains local processing and forwarding through its Connection Request Policies documentation.

If the ignore option does not fix the rejection

That setting only affects a request after it matches the policy where it is enabled. Continued rejection usually means one of the following:

  • The request matches a different policy.
  • A preceding policy handles or denies the request.
  • The intended policy is disabled or has the wrong NAS type.
  • A group, authentication, time, encryption, or tunnel constraint fails.
  • Authentication fails before authorization is evaluated.
  • The request is proxied to another RADIUS server.
  • NPS cannot read the required AD DS information.

Similarly, changing the Dial-in tab will not repair a VPN tunnel-negotiation failure, certificate problem, bad RADIUS shared secret, or invalid password.

How to reverse the change

To restore user-level behavior, edit the affected NPS network policy and clear Ignore user account dial-in properties. Then set each account intentionally to Allow access, Deny access, or Control access through NPS Network Policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a centralized design, restore users to Control access through NPS Network Policy and keep authorization in narrowly scoped policies. If the ignore option was enabled to solve a mixed-environment problem, consider separate policies for VPN, dial-up, wireless, and wired access instead of applying one broad policy to every connection type.

Recommended design

For most current AD DS and NPS deployments, use group-based authorization: set ordinary accounts to Control access through NPS Network Policy, create policies for the required access types, place restrictive policies appropriately, and test each NAS category.

Enable Ignore user account dial-in properties only when you have confirmed that the policy should bypass not just Allow/Deny but also caller ID, callback, static IP, and static-route attributes. Keep explicit per-user Allow or Deny settings for documented exceptions, break-glass controls, or deployments that genuinely depend on those dial-in properties.

NPS is generally sufficient when an organization already uses on-premises AD DS and needs straightforward Windows-based RADIUS authorization. A firewall/VPN platform or cloud RADIUS and identity service may be more appropriate when the strategic requirement is an integrated remote-access gateway, endpoint posture, certificate management, device-aware access, or reduced dependence on on-premises infrastructure. Those are platform decisions, not necessary fixes for a single incorrect Dial-in setting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
Bestseller No. 2
GigaMediaGroup Server 2025 Standard 16 Core OEM English Version NEW
GigaMediaGroup Server 2025 Standard 16 Core OEM English Version NEW
Server 2025 will be delivered by post, FPP version
$109.99
Bestseller No. 3
Windows Server 2025 User CAL 5 pack
Windows Server 2025 User CAL 5 pack
Offers quick and easy installation on PC; The software is licensed for 5 User CAL
$252.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.