Theldron Posted March 25, 2025 Posted March 25, 2025 Hi all, hope you are well Just started installing Windows 11 on some school laptops. It is installing but I can get it to connect to the schools devices Wi-Fi. Windows 10 is fine, but Windows 11 not happy. I can connect to the Guest Wi-Fi, but the 802.11 Wi-Fi through GPO, its not happy. Any ideas would be appreciated. Thanks
MatthewL Posted March 25, 2025 Posted March 25, 2025 Are the devices in the same OU's or security groups to the other devies you have? One that might apply the radius settings? 1
Theldron Posted March 25, 2025 Author Posted March 25, 2025 2 minutes ago, MatthewL said: Are the devices in the same OU's or security groups to the other devies you have? One that might apply the radius settings? Hi, yeah I have checked they are part of the same security group. The Windows 10 laptops are fine, but the Windows 11 machines in the same OUs are playing up. This is happening to Dell and Fujitsu laptops.
Theldron Posted March 25, 2025 Author Posted March 25, 2025 2 minutes ago, Primus said: Is this due to credential guard? Hiya, I haven't enabled that policy yet, as I know it can cause issues.
Theldron Posted March 25, 2025 Author Posted March 25, 2025 I am wondering if its a certificate issue. I assume a certificate is assigned to a device to allow connection?
MatthewL Posted March 25, 2025 Posted March 25, 2025 Plug in on a cable, do a full reboot and gpupdate and see if it then works, also check your GPO's are applying. 1
Primus Posted March 25, 2025 Posted March 25, 2025 26 minutes ago, Theldron said: Hiya, I haven't enabled that policy yet, as I know it can cause issues. Have you checked it's not on by default? 1
psydii Posted March 25, 2025 Posted March 25, 2025 Windows 11 credential guard is on by default. This breaks EAP-CHAPv2 if you are using EAP, you likely already have NPS and a CA from where you can automatically deploy machine based certificates. For us it was trivial to tweak the config to light-up the eap-TLS option and push out an updated gpo for the new authentication scheme. 3
Theldron Posted April 1, 2025 Author Posted April 1, 2025 Hi thanks for the help with this didn't realise Credential Guard was enabled by default now. Have had to disable it for now via GPO. Yeah we use NPS and a CA, so will look at how to sort the config for that. Thanks again all.
CHiLL Posted April 1, 2025 Posted April 1, 2025 While I have a combination of Windows 10 and Windows 11 clients, I created a new NPS policy for Windows 11 clients, that way I can keep credential guard enabled. The Windows 10 policy uses PEAP with CA certificates and device group membership whereas our Windows 11 policy uses EAP with CA certificates and a different group membership and I just put the Windows 11 policy higher in the processing order, so it takes precedence.
notnio0 Posted July 9, 2025 Posted July 9, 2025 I don't know if you have managed to resolve it but if you haven't try this. This is how I managed to get the 802.1x working with the wireless clients. Do not ask me how I found it but create a GPO to disable Virtualisation Based Security (VBS).There is a way to disable it through BIOS as well but easy to deploy using GPO. Go to: Computer Configuration>Policies>Administrative Template>System/Device Guard>Turn On Virtualisation Based Security to Disable. This method might not work for you or you might have already found a workaround for it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now