06-10-2025 01:25 PM
We are looking to implement trusted access on our wireless network. One question I've not been able to find the answer to is will wireless access stop working if your user account in Microsoft Entra is disabled? Or, will you have access until your certificate expires.
Solved! Go to Solution.
06-10-2025 01:58 PM
It is my understanding that when a user leaves the company and their Microsoft Sign-in account is deactivated, the device will still have Wi-Fi access until the certificate expires. This is because authentication is based on the certificate installed on the device, not the current status of the user's account.
I believe that one option to revoke access immediately is to manually revoke the certificate in the Meraki Dashboard. This will prevent the device from authenticating to the network, even if the certificate is still valid.
06-10-2025 01:31 PM
Maybe it will help you.
Re: Trusted Access - How do I onboard user? - The Meraki Community
06-10-2025 01:38 PM
Thanks for the articles, but not really what I'm looking for. I've got MS intra integration done and it all works just fine. My question is what happens when a user is no long with the company and his or her Entra account is disabled? Does the device still have WIFI access until the certificate expires?
06-10-2025 01:58 PM
It is my understanding that when a user leaves the company and their Microsoft Sign-in account is deactivated, the device will still have Wi-Fi access until the certificate expires. This is because authentication is based on the certificate installed on the device, not the current status of the user's account.
I believe that one option to revoke access immediately is to manually revoke the certificate in the Meraki Dashboard. This will prevent the device from authenticating to the network, even if the certificate is still valid.
06-11-2025 12:28 PM
I wish I could test this for you, but I'm currently unable to get this part working due to bugs.
This is how it is meant to work:
Access is not granted simply because you have a certificate.
There is an alternative authentication system, not using Meraki Access Manager, called "Local Auth," that works this way.
06-11-2025 02:17 PM
Thanks for the information. We have thousands of employee's across the state and we are trying to find an easy way to keep access secure levering Meraki and our Microsoft Entra installation. I can't find a clear answer on the subject. If a user's account is disabled in Entra, will they still be granted WiFi access if they have a valid certificate? We currently have our certificates set to 90 days.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide