cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
282
Views
1
Helpful
3
Replies

802.1x with native windows supplicant.

hs08
VIP
VIP

I'm lokking 802.1x protocol that use native windows supplicant and based on Entra ID, previously i try using EAP-TTLS but now work.

Open case to microsoft then they said that EAP-TTLS is not supported by windows 11 and must use 3rd praty supplicant installed on the machine. 

If i use EAP-TLS this will autenticate based on the certificate ant not use Entra ID. With this situation, anyone here know what 802.1x that will use native supplicant from windows and authentication based on Entra ID?

3 Replies 3

PSM
Level 1
Level 1

Hi, You can do EAP_TLS authentication using the  certificates and further check some attributes from Entra ID. Machines can't perform authentication against Entra ID just like traditional AD. Instead you can use some attributes from Entra ID in authorization profiles. Refer this link for more details:Cisco ISE with Microsoft Active Directory, Entra ID, and Intune - Cisco Community

thomas
Cisco Employee
Cisco Employee

Windows supports 802.1X with EAP-TTLS.
See EAP-TTLS Client Configuration > Windows 10/11