<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: windows 10 credential Guard issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3831455#M505031</link>
    <description>I recommend a posting in the anyconnect community&lt;BR /&gt;</description>
    <pubDate>Wed, 03 Apr 2019 13:56:56 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-04-03T13:56:56Z</dc:date>
    <item>
      <title>windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602356#M505022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Hi all &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Customer with predominately windows 10 install base .., current Auth schema is EAP-MSCHAPv2 &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; Their standard policy requires &lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&lt;STRONG&gt;Credential Guard&lt;/STRONG&gt; to be on by default on the win 10 desktops , from what i have found this seems to disable the ability to use EAP-MSCHAv2 and forces EAP-TLS ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;Other than disabling &lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;Credential Guard , is there a way to get this to work ? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #000000; font-size: 14.6667px; font-family: Calibri, sans-serif;"&gt;This article explains the issue : &lt;A href="http://www.iphase.dk/2017/08/14/windows-10-credential-guard-and-cisco-ise-conflicts/" title="http://www.iphase.dk/2017/08/14/windows-10-credential-guard-and-cisco-ise-conflicts/"&gt;http://www.iphase.dk/2017/08/14/windows-10-credential-guard-and-cisco-ise-conflicts/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;More : &lt;A href="http://www.neighborgeek.net/2016/08/windows-10-credential-guard-breaks-wifi.html" title="http://www.neighborgeek.net/2016/08/windows-10-credential-guard-breaks-wifi.html"&gt;http://www.neighborgeek.net/2016/08/windows-10-credential-guard-breaks-wifi.html&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Thx&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 07:11:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602356#M505022</guid>
      <dc:creator>ggriesse@cisco.com</dc:creator>
      <dc:date>2018-05-14T07:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602357#M505023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Disable Credential Guard&lt;/P&gt;&lt;P&gt;On the host operating system, click Start &amp;gt; Run, type gpedit.msc, and click Ok. The Local group Policy Editor opens.&lt;/P&gt;&lt;P&gt;Go to Local Computer Policy &amp;gt; Computer Configuration &amp;gt; Administrative Templates &amp;gt; System &amp;gt; Device Guard &amp;gt; Turn on Virtualization Based Security.&lt;/P&gt;&lt;P&gt;Select Disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Use AnyConnect NAM instead of Windows 10&amp;nbsp; 802.1x supplicant&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 08:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602357#M505023</guid>
      <dc:creator>nir-r</dc:creator>
      <dc:date>2018-05-14T08:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602358#M505024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So Disabling Credential guard is probably out for the customer .. the see it as a risk &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we go with Anyconnect NAM will it allow Eap-MSchapv2 EVEN with CG enabled on OS ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 14:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602358#M505024</guid>
      <dc:creator>ggriesse@cisco.com</dc:creator>
      <dc:date>2018-05-14T14:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602359#M505025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You &lt;STRONG&gt;cannot&lt;/STRONG&gt; do EAP-PEAP with Credential Guard enabled.&amp;nbsp; We have a growing Windows10 implementation, and have switched to using machine/user certificates for authentication using EAP-TLS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 14:45:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602359#M505025</guid>
      <dc:creator>ccubeman</dc:creator>
      <dc:date>2018-05-14T14:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602360#M505026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not believe NAM able to use password-based auth under the circumstance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 14:46:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602360#M505026</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-14T14:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602361#M505027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is working for me with EAP-FAST (EAP-MSCHAPv2)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 15:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602361#M505027</guid>
      <dc:creator>nir-r</dc:creator>
      <dc:date>2018-05-14T15:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602362#M505028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think it will depend where the credentials are stored. If fetched from Windows store, then expect same challenge as native supplicant with PEAP-EAP-MSCHAPv2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding "So Disabling Credential guard is probably out for the customer .. the see it as a risk", make sure customer understands this is NOT a Cisco ISE limitation but due to security feature that impacts Microsoft's own native supplicant.&amp;nbsp; Certainly the more common workaround for customers wishing to keep Credential Guard is to implement EAP-TLS with certs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 21:05:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602362#M505028</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-14T21:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602363#M505029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This was my experience.&amp;nbsp;&amp;nbsp; EAP-PEAP with MSCHAPv2 is right out.&amp;nbsp; EAP-TLS with machine/user certs was the only manageable method.&amp;nbsp; I will note we use the native supplicant and not NAM.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 21:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3602363#M505029</guid>
      <dc:creator>ccubeman</dc:creator>
      <dc:date>2018-05-14T21:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3831184#M505030</link>
      <description>&lt;P&gt;Thanks Craig for the response, my only concern moving to EAP-TLS is using computer + user certificates&lt;/P&gt;&lt;P&gt;how can you provision user certs when first logon on the computer ?&lt;/P&gt;&lt;P&gt;we would like to have user certs for user based auth (like using anyconnect ISE posture)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- pre-provisionning user certs is not possible before user logs in&lt;/P&gt;&lt;P&gt;- when using "shared" computers with each person login =&amp;gt; then this "first logon" use case will be very common, and should not force to have a special process to get user cert on computer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1/ Does Anyconnect NAM have some advantages over microsoft native supplicant for this particular issue ?&lt;/P&gt;&lt;P&gt;2/ What does Cisco recommend as workaround to microsoft "credential guard" feature (which i understand is not Cisco's responsability), do you have a "straight" response to that issue customers are facing ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Guillaume&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 07:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3831184#M505030</guid>
      <dc:creator>Guillaume BARBEROT</dc:creator>
      <dc:date>2019-04-03T07:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3831455#M505031</link>
      <description>I recommend a posting in the anyconnect community&lt;BR /&gt;</description>
      <pubDate>Wed, 03 Apr 2019 13:56:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3831455#M505031</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-04-03T13:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 credential Guard issue</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3835191#M505032</link>
      <description>&lt;P&gt;hello Guill&lt;/P&gt;&lt;P&gt;in case it's still actual for u, just fallback to "Microsoft: SmartCard or other blah-blah" on the client. It will effectively turn PC to request EAP-TLS-only authentication. Meantime configuring ISE for EAP-TLS only is quite straitforward.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 16:24:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-credential-guard-issue/m-p/3835191#M505032</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2019-04-09T16:24:21Z</dc:date>
    </item>
  </channel>
</rss>

