How does IAS perform authentication?
The IAS server receives the user credentials from the NAS in the RADIUS Access-Request message. If there is a domain included in the user credentials, then IAS will look up the user’s account in that domain. The domain must be either a trusted domain or the domain in which the IAS server is a member. Otherwise, the connection attempt is rejected. If the user credentials do not specify a domain, the IAS server determines the default domain from the registry. If the default domain is not specified in the registry, the IAS server uses the domain of which it is a member. If the IAS server is not a member of a domain, it attempts to authenticate the user credentials through the local SAM.