<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1X connection problem between Windows 11 and ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027789#M587744</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I hope I can find some help here.&lt;/P&gt;&lt;P&gt;Explanations:&lt;/P&gt;&lt;P&gt;We have a fleet of Windows 10 laptops. For wifi authentication we use radius authentication via an ISE server. The laptops are authenticated using the PC name. The PC name is in a specific group in the AD.&lt;/P&gt;&lt;P&gt;We have just upgraded a new PC to Windows 11 but the authentication no longer works.&lt;BR /&gt;On the ISE logs we can see the PC arriving, but it arrives with Username instead of the machine name. As a result, it doesn't match our ISE security rules and authentication doesn't work.&lt;/P&gt;&lt;P&gt;It's the same thing with cable, we use NAC on our 9300 switches and Windows 11 doesn't connect.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Do you know where this could be coming from?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank very much&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Feb 2024 16:33:39 GMT</pubDate>
    <dc:creator>mickael-France-64</dc:creator>
    <dc:date>2024-02-28T16:33:39Z</dc:date>
    <item>
      <title>802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027789#M587744</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I hope I can find some help here.&lt;/P&gt;&lt;P&gt;Explanations:&lt;/P&gt;&lt;P&gt;We have a fleet of Windows 10 laptops. For wifi authentication we use radius authentication via an ISE server. The laptops are authenticated using the PC name. The PC name is in a specific group in the AD.&lt;/P&gt;&lt;P&gt;We have just upgraded a new PC to Windows 11 but the authentication no longer works.&lt;BR /&gt;On the ISE logs we can see the PC arriving, but it arrives with Username instead of the machine name. As a result, it doesn't match our ISE security rules and authentication doesn't work.&lt;/P&gt;&lt;P&gt;It's the same thing with cable, we use NAC on our 9300 switches and Windows 11 doesn't connect.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Do you know where this could be coming from?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank very much&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 16:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027789#M587744</guid>
      <dc:creator>mickael-France-64</dc:creator>
      <dc:date>2024-02-28T16:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027793#M587745</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1622023"&gt;@mickael-France-64&lt;/a&gt; I assume you mean the username of the authenticated user? If so, it sounds like the Windows 11 laptops supplicant is mis-configured and is using "user authentication" instead of "computer authentication". The windows clients authentication mode need to be modified, example: &lt;A href="https://integratingit.wordpress.com/2019/07/13/configuring-windows-gpo-for-802-1x-authentication/" target="_blank"&gt;https://integratingit.wordpress.com/2019/07/13/configuring-windows-gpo-for-802-1x-authentication/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Or change ISE to authenticate the users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 16:36:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027793#M587745</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-02-28T16:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027815#M587746</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;We do indeed use the machine name for authentication on the ISE.&lt;/P&gt;&lt;P&gt;I've just looked at the settings you gave me, which are deployed by GPO. And we do have 'Computer authentication'.&lt;/P&gt;&lt;P&gt;I think it's OK on this side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 16:50:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027815#M587746</guid>
      <dc:creator>mickael-France-64</dc:creator>
      <dc:date>2024-02-28T16:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027900#M587749</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1622023"&gt;@mickael-France-64&lt;/a&gt; what username is sent then? Please provide the ISE Live log information.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 17:46:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027900#M587749</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-02-28T17:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027965#M587750</link>
      <description>&lt;P&gt;We use the name of the machine as Username&lt;BR /&gt;As you can see from the screenshots, in Windows 10 we get the machine name and in Windows 11 we just get 'Username'.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 18:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5027965#M587750</guid>
      <dc:creator>mickael-France-64</dc:creator>
      <dc:date>2024-02-28T18:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5028138#M587753</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1622023"&gt;@mickael-France-64&lt;/a&gt; go to Administration &amp;gt; System &amp;gt; Settings &amp;gt; Security Settings and select "Disclose invalid usernames" - that will display the username instead of "USERNAME"&lt;/P&gt;
&lt;P&gt;Anyway it looks like its failing because of certificates. Do the new computers have the Root CA certificates of the ISE EAP certificate? Check the local machine certificate store.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 19:42:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5028138#M587753</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-02-28T19:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5028290#M587769</link>
      <description>&lt;P&gt;The screenshot mentions that ISE is offering EAP-TLS in the initial negotiations, which the supplicant rejects and asks for PEAP instead. So the supplicant is not using EAP-TLS (cert auth).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Windows 11 + PEAP == disaster (Credential Guard) - I think there is a registry setting to disable Credential Guard but it's not advisable. Microsoft (and the rest of the IT world) is trying their best to kill off Username/password authentication.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 22:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5028290#M587769</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-02-28T22:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5115693#M589614</link>
      <description>&lt;P&gt;Hi chaps,&lt;/P&gt;
&lt;P&gt;I'm working on the same scenario, with Win11 22H2 and 23H2, wireless profile set to WPA3-Ent 128bit, and security using EAP-TLS where I manually specify the certificate to present from the client side (setting the root and intermmediate to the corporate ones), and the client to validate RADIUS server cert (at this moment the one been presented is issued from Sectigo with root CA USERTrust, the one I'm checking), finally I'm setting the authentication piece to be username and NOT machine.&lt;/P&gt;
&lt;P&gt;Weel under taht sceanrio Win10 works all the time, but none of the Win11 laptops are authenticated and I see that "USERNAME" in the ISE logs. I've managed to fix this with&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;recommendation to enable&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;Administration &amp;gt; System &amp;gt; Settings &amp;gt; Security&lt;/EM&gt; &lt;EM&gt;Settings&lt;/EM&gt; &amp;gt; "&lt;EM&gt;Disclose invalid usernames&lt;/EM&gt;&lt;/SPAN&gt;".&lt;/P&gt;
&lt;P&gt;However, I've managed to make Win11 to be authenticated sometimes in 1-2 laptops, but then when trying to log into the network back again, I receive an Access-Reject. (Without modifying anything from the pervious day!!!!)&lt;/P&gt;
&lt;P&gt;I have a support case open with MS about this so I will update this thread with the Win11 defects or ISE workarounds.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 14:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5115693#M589614</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-05-24T14:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5154102#M590987</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Were you able to get any workarounds ?&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 14:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5154102#M590987</guid>
      <dc:creator>CharlesNjora9180</dc:creator>
      <dc:date>2024-07-31T14:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5154395#M591014</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We didn't find a solution with Windows 11.&lt;BR /&gt;We had to work around the problem. We used certificate authentication.&lt;BR /&gt;Since then, everything has worked correctly.&lt;/P&gt;&lt;P&gt;Mickael&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 07:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5154395#M591014</guid>
      <dc:creator>mickael-France-64</dc:creator>
      <dc:date>2024-08-01T07:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5155390#M591045</link>
      <description>&lt;P&gt;For Win11 to use PEAP with either machine name or user name, you must disable Credentials Guard:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=intune#disable-credential-guard" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=intune#disable-credential-guard&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 22:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5155390#M591045</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-08-02T22:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5157462#M591134</link>
      <description>&lt;P&gt;Hi everyone:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The problem I have is because the check is NOT applied when entering the computer with Windows 11 into the AD (Image attached) The bad thing is that a model of a certain brand of equipment does work and in other models of equipment of the same brand Windows 11 does not work with the ISE.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I think it has to do with some blocking of the computer's mainboard.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAVYLU_0-1723073261706.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/225689i7240E3FCE78AFEE2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JAVYLU_0-1723073261706.png" alt="JAVYLU_0-1723073261706.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Has anyone already solved this problem?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 23:31:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5157462#M591134</guid>
      <dc:creator>JAVYLU</dc:creator>
      <dc:date>2024-08-07T23:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X connection problem between Windows 11 and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5157598#M591142</link>
      <description>&lt;P&gt;There are some differences in Windows supplicant between versions, even between Windows 11 minor versions.&lt;/P&gt;
&lt;P&gt;Try the simple way to disable "validate server certificate" and update all Windows devices to the same version, and drivers to the latest version from any vendor.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 07:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-connection-problem-between-windows-11-and-ise/m-p/5157598#M591142</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-08-08T07:04:20Z</dc:date>
    </item>
  </channel>
</rss>

