To keep in mind: Use the same AGDLP group for authenticating on both Wired – and – Wireless configs in your NPS Radius Server.
Mixed results because of different memberships, can cause many issues in regards to connectivity, depending on your robust infrastructure.
Create a - Domain Local - Security Group - NPS_VLAN_0200_CLIENTS In that group you place a
Global - Security Group - Windows_Client_Department_HR
and so forth.
You can add addtional Global Security Groups in the Domain Local Security Group.
And for each VLAN you create a seperated - Domein Local - Security Group.