Jump to content

Recommended Posts

Posted

Hello,

 

Sometimes when we image a machine to our network on Windows 11, they fail to connect properly to our wireless.

We have our main wireless, and then a second wireless that is essentially a visitor one. You can connect the laptop to the second one with no issues (need to input a password), but when trying to connect it to the main one (should just authenticate without a password if imaged), it says 'unable to connect to this network'. We push the certificate out through GPO, and  as I've mentioned, it does it intermittently on different devices so we don't feel it is a problem with the GPO itself?

- we're just wondering if anyone else has had similar issues and if they have managed to get around them?

Posted

On freshly imaged computers? I seem to recall that the initial certificate request/deployment has to occour over a wired connection if using  windows 2000 era gpo settings. I don’t recall seeing reference to this in the last decade so maybe it not a thing anymore, but it  seems to match your scenrio from what you have shared.

 

 

Perhaps you are pivoting the device to wireless before it has picked up it’s certificate?

  • Like 1
Posted (edited)

Oh wait. You need to upgrade your configuration to eap-TLS. eap-peap is not supported in windows 11 anymore.

 

all your devices will also need their own certificate.

 

 

Edited by psydii
  • Like 1
Posted

Thanks for connecting me to the above thread. Yes we're using EAP-PEAP so this probably explains where we are going wrong.

In reply to your first post, our image does typically pick it up from the wired connection first, and then we restart/gp update etc and then unplug them to see if they auto connect to the wireless.

Posted
36 minutes ago, jymmywil said:

We had the same problem after image on some Win 11 laptops. In our case, it was a timing problem: the certificate was not yet applied at the time of connection. Forcing a gpupdate /force and restarting was often enough.

I wish this was it for us! We gpupdate them about 3 times before taking them off the wired connection to test, and they still don't pick it up.

Posted

Check that you've got your root CA/subordinate CA ticked in the "Trusted Root Certificate Authorities" section of the WiFi GPO.  In Windows 10 if there were no CAs ticked it treated it as "all of these are fine to use".  In Windows 11, if no CAs are ticked it treats it as "don't trust any of these".  (See screenshot - we have N+1 CAs for cross-trust auth).

 

Also check that the computer certs being handed out to the clients are being generated from a recent cert template (2016 compatibility or better).

 

WiFiGPOSettings-TrustedRootCAscopy.thumb.png.2353e6c1579eb274be4a73f0b2a07159.png

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...