Hi, > I've tried doing the following to have a "continue on fail" > > authenticate{ > ... > Auth-Type LDAP{ > ldap > if(reject){ > ntlm_auth > } > } try...something like.... Auth-Type LDAP { group { ldap { reject = 1 ok = return } ntlm_auth { reject = 1 ok = return } } } alan