We recently attempted to set our NPA policies to our "Domain Users" (in our case "corp.alfacompanies.com/Users/Domain Users") group rather than leaving the "source/user=" field empty so it applies to All Users.
After the policies had time to simmer, we began noticing problems with
- file shares (likely a DNS or Domain Controller conflict)
- lost access to the file shares
- Windows Security prompts asking for credentials
- gpupdate /force
- failed almost immediately due to failure to connect
- Forticlient EMS
- status failed over to "not reachable"
After changing our NPA policies related to domain controllers and DNS back to user=all users (aka empty) and allowing time for the settings to propagate , access returned to normal.
That begged the question, why would setting the policy to "Domain Users" create such an adverse issue. In your experiences, if all domain users need access, do you typically leave the "source/user=" field empty?