<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP-TEAP: First time user login/chicken &amp;amp; egg scenario in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5255076#M594680</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1711599"&gt;@icarimo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have used this flow with TEAP(EAP-TLS) and the 'User failed and computer succeeded' EAP Chaining result for both Wired and Wireless use cases to permit access based on the initial Computer certificate authentication and a missing or expired User certificate multiple times.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2025 21:57:25 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2025-01-30T21:57:25Z</dc:date>
    <item>
      <title>EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4475351#M569972</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does EAP-TEAP solve the first time user login scenario when using EAP-TLS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, you image a new Windows PC, it gets the machine certificate and always authenticates fine. Then, a new user is given that device that's authenticated successfully and tries to login. The authentication fails because the User certificate isn't downloaded before network access is taken away.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know you can put an ISE chaining policy with 'user failed, machine successful'. Will the device keep this access when the user auth fails so the certificate can be downloaded? And if the certificate has downloaded, will it attempt another User authentication so that SGTs/ACLs can be applied? Or would they need to log off/have the 'user failed, machine successful' policy force re-authentication?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 08:59:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4475351#M569972</guid>
      <dc:creator>DanMN</dc:creator>
      <dc:date>2021-09-28T08:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4475498#M569990</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Yes, with chaining the user should logout and in to trigger CoA and get new&lt;BR /&gt;dacls or wait for reauthenticate timer.&lt;BR /&gt;</description>
      <pubDate>Tue, 28 Sep 2021 12:08:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4475498#M569990</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-09-28T12:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4475500#M569991</link>
      <description>&lt;P&gt;Thank you for clearing that up. It's kind of frustrating that this is the best option we have for this sort of thing at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What alternative is there that would mean the user doesn't need to relogin/have a very short reauthentication timer on Machine only auths? Use MS-CHAPv2 for the User authentication and EAP-TLS for the computer? I don't think MS-CHAPv2 is generally recommended anymore?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 12:12:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4475500#M569991</guid>
      <dc:creator>DanMN</dc:creator>
      <dc:date>2021-09-28T12:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4486707#M570428</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1253092"&gt;@DanMN&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I know and have tested, if the native Windows supplicant is set to user or machine auth, and EAP-TLS is used (certificate based auth) then Windows doesn't perform a network authentication when a user logs in at the locked screen. AFAIK this actually only work with EAP-PEAP (AD machine account used at bootup and logoff, and user AD account used at login)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not yet tried EAP-TEAP but I believe that cert based auth can be used for both user and machine auth.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 06:03:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4486707#M570428</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-10-15T06:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4487592#M570455</link>
      <description>&lt;P&gt;From the testing I've done with TEAP-EAP-TLS and the 'user or computer' setting with expired/missing user certs, you can use the 'user failed and machine succeeded' chaining result to provide access when the user cert is not enrolled. After the certificate is enrolled, however, the native supplicant does not automatically trigger another authentication event. I have not tried pushing a short reauth period in that state, but it might be tricky as the cert is enrolled via GPO which uses it's own timers.&lt;/P&gt;
&lt;P&gt;You might have a look at what windows logs trigger in this scenario to see if there is a specific event or set of events you could use to force a GPO update and cert enrollment, then force a restart of the Wired AutoConfig service.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 21:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4487592#M570455</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-10-17T21:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4549406#M572708</link>
      <description>&lt;P&gt;Hey seen this thread. I would be interested to see your Authorization policy that allows a certain user in a AD group to get an SGT and to get authorized while using eap-chaining and teap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im trying to figure out the best Autz policy to create to authorize a user and push and SGT for that particular AD group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any help appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 09:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4549406#M572708</guid>
      <dc:creator>x00008037</dc:creator>
      <dc:date>2022-02-10T09:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4549928#M572729</link>
      <description>&lt;P&gt;This is the AuthZ Policy for my TEAP use case described earlier. I'm just using the top-level Domain Computers and Domain Users, but you could use more specific AD group matches if you prefer.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-02-11 at 8.47.37 am.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/143539iD3CCD5C3C6CA5530/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-02-11 at 8.47.37 am.png" alt="Screen Shot 2022-02-11 at 8.47.37 am.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 21:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4549928#M572729</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-02-10T21:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4550006#M572735</link>
      <description>&lt;P&gt;thanks for that Greg that clears it up. I wasn't sure how particular you could get with the AD groups. As we will be pushing an SGT to a user , based on their AD group. The machine will do cert based authentication&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 00:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4550006#M572735</guid>
      <dc:creator>x00008037</dc:creator>
      <dc:date>2022-02-11T00:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4844576#M581994</link>
      <description>&lt;P&gt;Hello DanMN,&lt;/P&gt;&lt;P&gt;Could you please specify if you find some solution to solve chicken-egg issue for the first user's login?&lt;/P&gt;&lt;P&gt;I am stuck with the same issue and wondering if we have any good/effective solution to manage it...&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 09:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4844576#M581994</guid>
      <dc:creator>nlyubchak@aligntech.com</dc:creator>
      <dc:date>2023-05-29T09:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5254663#M594641</link>
      <description>&lt;P&gt;Hello Greg,&lt;BR /&gt;&lt;BR /&gt;Thank you for the reply.&lt;BR /&gt;&lt;BR /&gt;I don´t if this will work in my scnerario, because, as soon as the computer perfoms the first logins, the device tries to connect to Wi-Fi using a user certificate, however the computer do not initiate the wif-fi authentication, so no packet will reach the Cisco ISE.&lt;BR /&gt;&lt;BR /&gt;Since the computer do not have any user certificate, it does not initiate the wifi connection&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 09:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5254663#M594641</guid>
      <dc:creator>icarimo</dc:creator>
      <dc:date>2025-01-30T09:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5255076#M594680</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1711599"&gt;@icarimo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have used this flow with TEAP(EAP-TLS) and the 'User failed and computer succeeded' EAP Chaining result for both Wired and Wireless use cases to permit access based on the initial Computer certificate authentication and a missing or expired User certificate multiple times.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 21:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5255076#M594680</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-01-30T21:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5545364#M600239</link>
      <description>&lt;P&gt;i have a problem as per attached when I remove &lt;STRONG&gt;user cert&lt;/STRONG&gt; from a device's user cert store just to mimic the scenario of "&lt;U&gt;no user cert"&lt;/U&gt;.&lt;/P&gt;&lt;P&gt;I can see it matches the AuthZ named - "TEAP Entra Joined Device" when device boot up and but when user logs in Authz session does not change as per ISE log.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when a device has a User Cert stored, it perfectly matches another AuthZ Policy which is for user and devices &lt;SPAN&gt;succeeded&lt;/SPAN&gt; for Eap Chaining Result.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note that i have reauthentication timer setup for "TEAP Entra User Failed" AuthZ policy so that it can reauthenticate again assuming user cert will be downloaded before the reauth timer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest any clue.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Image_Policy.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280505iD386FCEEE1FC5D58/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_Policy.png" alt="Image_Policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 21:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5545364#M600239</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2026-04-14T21:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5545369#M600240</link>
      <description>&lt;P&gt;ISE version, patch?&lt;BR /&gt;Endpoint OS, version, configuration?&lt;BR /&gt;What do the log details look like for the session?&lt;BR /&gt;What does the EAP Chaining Result reflect in the logs?&lt;BR /&gt;Have you searched for any bugs related to this issue?&lt;BR /&gt;What other troubleshooting have you done?&lt;BR /&gt;&lt;BR /&gt;This is the kind of information you should provide for any posts in order for community to provide any meaningful help. If you need urgent assistance, call TAC.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 22:31:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5545369#M600240</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2026-04-14T22:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5545375#M600242</link>
      <description>&lt;P&gt;&lt;SPAN&gt;ISE version, patch? - 3.5 patch 2&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Endpoint OS, version, configuration? - Windows 11 , Supplicant Config set as TEAP with EAP-TLS for both primary and secondary auth and auth mode is user or computer authentication.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What do the log details look like for the session? - Log still shows identity as machine name it ( ISE log )&amp;nbsp; does not change when user logs in to the machine.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What does the EAP Chaining Result reflect in the logs? - it shows -&amp;nbsp;EapChainingResult User failed and machine succeeded&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have you searched for any bugs related to this issue? - not yet&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What other troubleshooting have you done? - if I set reauth timer for authZ Policy -&amp;nbsp;TEAP Entra Joined Device it gets reauthenticated within the set timer and if cert is downloaded before that it matches the eap chain result with both user and machine succeeded.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 23:01:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5545375#M600242</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2026-04-14T23:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5545650#M600253</link>
      <description>&lt;P&gt;I had another look at your AuthZ Policy screenshot.&lt;/P&gt;&lt;P&gt;You're matching on the User group lookup condition (Cisco_xxx_EntraID) instead of a device lookup condition (Cisco_xxx_EntraIDDevice) in that rule. You're not getting user identity, so that condition will not match. You need to either remove that condition or change it to one that matches on the device.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 22:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5545650#M600253</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2026-04-15T22:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TEAP: First time user login/chicken &amp; egg scenario</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5546015#M600266</link>
      <description>&lt;P&gt;Hello Greg,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to follow as you suggested. I removed&amp;nbsp;&lt;SPAN&gt;User group lookup condition from AuthZ Rule - " TEAP Entra User Failed."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When device is powered on it matches&amp;nbsp;" TEAP Entra User Failed." and when user is logged in if there is no user cert it still stays on this AuthZ Rule -&amp;nbsp;" TEAP Entra User Failed."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if I bring rule 2 - "TEAP Entra Joined Device" before&amp;nbsp;" TEAP Entra User Failed." it matches&amp;nbsp;"TEAP Entra Joined Device" rule.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tshoot1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280656iDBD7B9373F236398/image-size/large?v=v2&amp;amp;px=999" role="button" title="Tshoot1.jpg" alt="Tshoot1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 03:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/5546015#M600266</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2026-04-17T03:02:17Z</dc:date>
    </item>
  </channel>
</rss>

