We're running through some testing with our RADIUS policies but thought I'd ask here in case anyone has successfully implemented a solution for this.
We run a mixture of certificate and radius based authentication for our wireless clients.
So...if a user comes to the logon screen and needs to unlock/reset their account/password, they click the GINA client button...and as they are not authenticated cannot get a network connection, so obviously the ADSSP webpage does not load.
For ~90% of our users this won't be an issue, but it's obviously important for us to try and catch all cases, and undoubtedly the 10% is going to include some of the VIPs because they all like to have their fancy mobile devices..
The only solution I can think of at present is to use the mobile app so they can unlock it that way, but this is not an option for us.