<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Windows 11 issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373774#M599929</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317927"&gt;@Maurice Ball&lt;/a&gt;&amp;nbsp;I assume the computers are still in the same OU in the domain and getting the GPO settings with the correct wired 802.1x authentication being applied?&lt;/P&gt;
&lt;P&gt;What do the ISE logs give as the reason for failing to authenticate?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Mar 2026 09:05:36 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2026-03-02T09:05:36Z</dc:date>
    <item>
      <title>ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373765#M599926</link>
      <description>&lt;P&gt;I have an issue I hope someone could help me with. I am having an issue with 802.1x authentication on ISE. They are using PEAP with certificate computer only authentication and everything appears to be configured correctly but authentication continues to fail on Windows 11 wired clients. Note: They are using&amp;nbsp; the same setup with Windows 10 clients and it works without any issues but with Windows 11 clients it fails on the wired connection but is successful with Windows 11 clients on the wireless connection. Basically it works everywhere correctly with the exception of the Windows 11 wired clients. Do you have any idea of what could be causing the issue?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 08:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373765#M599926</guid>
      <dc:creator>Maurice Ball</dc:creator>
      <dc:date>2026-03-02T08:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373766#M599927</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317927"&gt;@Maurice Ball&lt;/a&gt;&amp;nbsp;Windows 11 credentials guard is likely causing the problem as PEAP is insecure and blocked, you'd need to move to certificate authentication EAP-TLS or PEAP-TLS&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 08:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373766#M599927</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-03-02T08:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373773#M599928</link>
      <description>&lt;P&gt;Thanks for the quick reply but the credential guard looks to be disabled. The system account also has full access to the certificate's private key and Windows 11 fast startup is disabled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 08:55:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373773#M599928</guid>
      <dc:creator>Maurice Ball</dc:creator>
      <dc:date>2026-03-02T08:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373774#M599929</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317927"&gt;@Maurice Ball&lt;/a&gt;&amp;nbsp;I assume the computers are still in the same OU in the domain and getting the GPO settings with the correct wired 802.1x authentication being applied?&lt;/P&gt;
&lt;P&gt;What do the ISE logs give as the reason for failing to authenticate?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 09:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373774#M599929</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-03-02T09:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373776#M599930</link>
      <description>&lt;P&gt;Correct. I am getting a 5440 error on ISE but it is showing that the handshake was successful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 09:11:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373776#M599930</guid>
      <dc:creator>Maurice Ball</dc:creator>
      <dc:date>2026-03-02T09:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373779#M599931</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317927"&gt;@Maurice Ball&lt;/a&gt;&amp;nbsp;usually an endpoint issue, take packet captures and run debugs on the switch.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 09:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373779#M599931</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-03-02T09:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373863#M599933</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Have you had a look at this thread regarding Windows 11 using TLS 1.3? It has a link to another thread showing how to disable this on windows 11 clients&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-3-3-802-1x-eap-tls-tls1-3/td-p/5354087" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-3-3-802-1x-eap-tls-tls1-3/td-p/5354087&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 16:18:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373863#M599933</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2026-03-02T16:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373867#M599934</link>
      <description>&lt;P&gt;To add to what others have said, take a look at the endpoint logs, they can often direct you into the right direction.&lt;/P&gt;
&lt;P&gt;One item I'd like to point out, is that in windows11 there were some changes regarding the server validation.&lt;BR /&gt;In win10 and earlier, it used to be enough to have the CA in the trust store if you had server validation enabled/checked, but in some win11 update it became required to specifically select which CA you were going to trust.&lt;BR /&gt;One of the signs that people were running into this were that win11 clients failed where older clients worked.&lt;/P&gt;
&lt;P&gt;Is it possible that this might be your case, and this might be correctly configured in your wifi GPO but not in the wired group policy?&lt;/P&gt;
&lt;P&gt;Again, check the endpoints logs in the event viewer, they can be very valuable in determining why the authentication fails if it's the client refusing to continue the process.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 16:37:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5373867#M599934</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2026-03-02T16:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5374055#M599941</link>
      <description>&lt;P&gt;I have not checked this so thanks for the information.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 07:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5374055#M599941</guid>
      <dc:creator>Maurice Ball</dc:creator>
      <dc:date>2026-03-03T07:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Windows 11 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5374056#M599942</link>
      <description>&lt;P&gt;Ok, thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 07:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-windows-11-issue/m-p/5374056#M599942</guid>
      <dc:creator>Maurice Ball</dc:creator>
      <dc:date>2026-03-03T07:56:48Z</dc:date>
    </item>
  </channel>
</rss>

