02-07-2025 04:16 AM
Hi all, I just wanted some advice.
When implementing ISE, what is thre recommended authentication method for clients? Is it EAP-TLS or MSCHAPv2?
02-07-2025 04:29 AM - edited 02-07-2025 04:55 AM
@alliasneo1 EAP-TLS is the recommended authentication method nowadays. If you use EAP-TLS for machine and user authentication you can use TEAP to provide EAP Chaining and make authentication more secure.
PEAP/MSCHAPv2 does not work when credential guard is enabled on Windows 10/11 devices, thus Microsoft recommends EAP-TLS https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues
02-07-2025 04:31 AM
They are complementary. You need both at the end of the day.
EAP-TLS buids the encrypted tunnel between the supplicant and the authenticator and t" (MS-CHAPv2) is a password-based authentication protocol that verifies a user's identity when connecting to a network"
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide