- Create two Active Directory security groups. One group with users who are token authenticated, for example, Defender Auth, and the other group with users who require Active Directory password, for example, Defender AD Password.
- Assign the Token policy to the Defender Auth group.
- Assign the Active Directory password policy to the Defender AD Password group.
- Configure an access node for your access device (NAS), adding both AD groups to the members tab without assigning any policy on the access node. 
Users in the Defender Auth security group authenticate with tokens and users in the Defender AD Password group authenticate with Active Directory Passwords. When the users of Defender AD Password group are assigned a token, the administrator has to move users to the Defender Auth group and ensure they are removed from the Defender AD Password group. 
