Hi everyone,
Thanks for your replys. I was under the impression that the AD integration was as simple as joining the controller to AD, then doing some sort of map between local and AD groups and WPA2 enterprise with SSO would just work.
After spending the whole weekend messing around with this, I discovered that although its not hard, its by no means a straight forward setup.
What I ended up doing is creating a new AD server with 2008 Enterprise (because all my servers were standard, and standard 2008 cannot sign an RAS/NPS certificate,,, apparently this is supported in 2008 R2), then I configured NPS for MSCHAPV2 with EAP, auto enroled my wireless devices and setup the default domain policy for Vista and 7 desktops to auto connect as machines, then configured the controller for Authentication and Access control. I pointed it towards my NPS server in the RADIUS section, and the VSC uses 802.1X as remote radius, not AD.
Less elegant than I had expected, but the end result is a beautiful thing! I can push GPO's before startup to deploy settings, software, etc, over encrypted wireless. What more could you ask for. Well, maybe the setup to be simpler, haha!
Cheers,