---
title: Kron PAM Server Configurations
slug: kronpam-reference-guide-3-5-0/kron-pam-server-configurations
description: Learn how to efficiently set up and configure the Kron PAM system with this comprehensive step-by-step guide. From creating user and device groups to configuring RADIUS 802.1x and setting up Active Directory for MSCHAPv2, this document covers all the nece
docTags: 
createdAt: 2022-08-01T13:11:44.000Z
---

The Kron PAM admin should follow these steps:

1. Create a user and a user group. (See section [User Group Creation](docId:0PFGx1fLkALdk66bckpWJ))
2. Create a device group and add the new device to the device group. (See [Device Management](docId\:taoj_F-rCmBoLEzYvCI_X))
3. Create a **Device Group Realm** with the user group defined in step 2 and the device group defined in step 3. (See [Device Management](docId\:adWPW6z8hh1jE67rihAtN))
4. Define the authenticating secret key as **globalSecretKey** in the device group properties.&#x20;
5. Navigate to **Administration&#x20;**> **RADIUS 802.1x Config**.
6. Choose an EAP Type (currently, only PEAP is available)
7. Fill in the Certificate Authority PEM, Certificate Private Key PEM, and Certificate Private Key Password fields (This information does not have to be accurate)

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/vByUzbFE3R8Q5O-cTEAiL_image.png "802.1x Configuration")

- Toggle the **Add Kron PAM Server to Active Directory** option and fill in the necessary fields.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/B5t-aIzjtE1bRe8INLmzB_image.png" size="64" width="549" height="470" position="center" caption="Active Directory Configuration for MSCHAPv2" showCaption="true"}

