<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DOT1x Authentication failed with error user password expired in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-failed-with-error-user-password-expired/m-p/4916756#M583880</link>
    <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;Thanks for your reply .&lt;/P&gt;&lt;P&gt;So on the &lt;SPAN&gt;supplicant&amp;nbsp;i need to allow&amp;nbsp;computer authentication .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also what excatly do you mean by "&amp;nbsp;the authorization provided in the Computer state must allow the necessary connectivity to the domain." ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you mean i need a new policy on the ISE to allow my computers with MAB and allow them to reach&amp;nbsp; AD ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And will the computer get IP from DHCP server or APIPA ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks again .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards ,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 03 Sep 2023 19:40:35 GMT</pubDate>
    <dc:creator>MED Amine MB</dc:creator>
    <dc:date>2023-09-03T19:40:35Z</dc:date>
    <item>
      <title>DOT1x Authentication failed with error user password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-failed-with-error-user-password-expired/m-p/4915699#M583820</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm using ise 2.7 and started facing problems with authentication when the users are asked to change their AD password :&lt;/P&gt;&lt;P&gt;-The first one : user is asked to change password and if the password matches the criteria the new password is accepted, and he is authenticated, but ones he gane access to his machine he is presented with APIPA and can't perform any network related action.&lt;/P&gt;&lt;P&gt;-The second one : the user is either not able to change the password or is presented with a message saying he is no longer on the company Domain and is not able to change the password.&lt;/P&gt;&lt;P&gt;I'm currently using PEAP authentication on all my machines generated with GPO.&lt;/P&gt;&lt;P&gt;Did anyone ever find a solution for these problems ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 20:54:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-failed-with-error-user-password-expired/m-p/4915699#M583820</guid>
      <dc:creator>MED Amine MB</dc:creator>
      <dc:date>2023-08-31T20:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: DOT1x Authentication failed with error user password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-failed-with-error-user-password-expired/m-p/4915748#M583824</link>
      <description>&lt;P&gt;I believe this discussion is related to the same question but, without more detail on how your ISE policy and switch are configured (are you using a Low Impact Mode or Closed Mode model, etc), it's difficult to speculate about the domain/IP address issues.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/td-p/3456698" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/td-p/3456698&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In general, 802.1x using PEAP(MSCHAPv2) will allow the user to be prompted to change their password at login. However, the PC must have connectivity to the domain to facilitate the password change. In this scenario, the password change happens in the Computer state before the transition to the User state, so the supplicant must be configured to authenticate the Computer (either 'User or computer authentication' or 'Computer authentication') and the authorization provided in the Computer state must allow the necessary connectivity to the domain.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 23:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-failed-with-error-user-password-expired/m-p/4915748#M583824</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-08-31T23:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: DOT1x Authentication failed with error user password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-failed-with-error-user-password-expired/m-p/4916756#M583880</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;Thanks for your reply .&lt;/P&gt;&lt;P&gt;So on the &lt;SPAN&gt;supplicant&amp;nbsp;i need to allow&amp;nbsp;computer authentication .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also what excatly do you mean by "&amp;nbsp;the authorization provided in the Computer state must allow the necessary connectivity to the domain." ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you mean i need a new policy on the ISE to allow my computers with MAB and allow them to reach&amp;nbsp; AD ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And will the computer get IP from DHCP server or APIPA ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks again .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards ,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Sep 2023 19:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-failed-with-error-user-password-expired/m-p/4916756#M583880</guid>
      <dc:creator>MED Amine MB</dc:creator>
      <dc:date>2023-09-03T19:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: DOT1x Authentication failed with error user password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-failed-with-error-user-password-expired/m-p/4916802#M583882</link>
      <description>&lt;P&gt;I describe the order of operations for 802.1x Computer and User authentication in this document.&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635#toc-hId-296059835" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635#toc-hId-296059835&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You will need an authorization policy in ISE that will permit connectivity to the necessary systems like DHCP, DNS, and Active Directory when Windows is in the Computer state.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Sep 2023 22:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-failed-with-error-user-password-expired/m-p/4916802#M583882</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-09-03T22:49:11Z</dc:date>
    </item>
  </channel>
</rss>

