My organization is working on migration path to Win11 (Entra joined), with hybrid user accounts. According to the below posting, it was mentioned that TEAP (EAP-TLS) is not supported for Computer authentication or EAP-Chaining.
Cisco ISE with Microsoft Active Directory, Azure AD, and Intune
I have two questions about this;
- Is this a limitation of ISE or with Windows11 being Entra joined? If ISE, could you please explain why EAP-Chaining and computer authentication are not supported?
- We are currently using TEAP to solve the "chick and egg" problem outlined in the below posting. If TEAP cannot be used in an Entra joined environment, then what options are available to ensure that a user logging into a computer for the first time is able to build a user profile with certificate issuance, for user authentication?
EAP-TEAP: First time user login/chicken & egg scenario
@Greg Gibbs