cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1354
Views
0
Helpful
4
Replies

Windows 10 Credential Guard with 802.1x

fpm2007cisco
Level 1
Level 1

Dear Group,

Is a Cisco ISE required to get Windows 10 Credential Guard working with 802.1x? or a CA Server with Radius is enough?

Any suggested minimum requirements will be really appreciated.

 

Thanks,

2 Accepted Solutions

Accepted Solutions

@fpm2007cisco - there is no hard requirement to use Cisco ISE. Any RADIUS server will do the job. Of course we'd love you to use ISE because this is a Cisco forum ... but if you have a Windows Server available then take a look at the NPS - it's built into Windows Server and will also do a good job. It's not the best tool to monitor and troubleshoot though. If you set it up correctly then you can just leave it running and it will do its job.

View solution in original post

Bier,

Once again, thank you for your reply. I would love to use ISE. The reason why we can't is our Network is Airgap. So, we don't have access to the Internet for the ISE to call home (Licensing) and our Managers do not want us to stand up a Cisco Server for registration.

Anyway, thanks again.

View solution in original post

4 Replies 4

Arne Bier
VIP
VIP

Hello @fpm2007cisco 

There was a discussion about this a few years back - I hope it's still relevant.

Yes, I read their discussion, but it didn't answer my question. My question is about the minimum equipment requirement to setup a Windows 10 Network with Credential Guard and 802.1x using CA. Reading their comments, Apparently this is the only way to get it working. But, their discussions is on the line of using an ISE. At this moment, we don't have an ISE.

But, thank you for replying.

@fpm2007cisco - there is no hard requirement to use Cisco ISE. Any RADIUS server will do the job. Of course we'd love you to use ISE because this is a Cisco forum ... but if you have a Windows Server available then take a look at the NPS - it's built into Windows Server and will also do a good job. It's not the best tool to monitor and troubleshoot though. If you set it up correctly then you can just leave it running and it will do its job.

Bier,

Once again, thank you for your reply. I would love to use ISE. The reason why we can't is our Network is Airgap. So, we don't have access to the Internet for the ISE to call home (Licensing) and our Managers do not want us to stand up a Cisco Server for registration.

Anyway, thanks again.