Jump to content

Recommended Posts

Posted

Hi all, bit of a bind trying to figure this issue out since this morning.

 

We have a NPS server running on Server 2025 which authenticates our BYOD users via our Cambium Wi-Fi Network and this has been running without any issues for the past few years since it was setup and configured by Redway Networks.

 

I only need to renew the GoDaddy certificate installed on it every year, update the config with the New Cert and then it hums along quite happily.  The system as a whole works well and have been really happy with it - nearly 100 APs dotted around the site.

 

Mid morning today, we get reports of BYOD Users, Students and Staff not being able to connect to the Wi-Fi using their AD Credentials.  Sure enough, my own mobile once I disconnect and try reconnecting won't play ball.  Event logs are showing

Quote

'An error occurred during the Network Policy Server use of the Extensible Authentication Protocol (EAP).  Check EAP log files for EAP errors.' - Reason Code: 23.

 

Nothing has changed on the config, but some guides point to re-issuing the certificate may help.  So, I re-key the server certificate and get the new certificate installed and apply this to the NPS Server (Protected EAP Constraints) and it does appear to resolve the issue..... or so I thought.  My phone, being an Android connects quite happily and so do others, but iPhones do NOT.  Also notice my Intune Laptop running Windows 11 also refuses to connect to the BYOD network with my credentials.

 

Needless to say, our Sixth Form students are getting impatient of not having Wi-Fi but I'm not sure what to do next?  EAPHost log shows errors: 

Quote

Skipping: Unable to add EAP Method.  Friendly name not present.

 

I fear my Google Fu is leading me down all sorts of rabbit holes, and wondering if something that Microsoft and Apple have 'switched off' at a specific point that now refuses to work with these devices?  (eg.  Should be set up with EAP-TLS and not just EAP???  But, don't want to jump to conclusions on that one just yet).

 

Appreciate any help to get resolved quickly to stop my phone ringing.


TIA

 

Pete

 

 

 

Posted

Just to add - digging deeper, also noticing an error: 

 

Quote

The Extensible Authenication Protocol service terminated unexpectedly.  It has done this 4 time(s).

 

Might be more of a server issue as a whole which is a little worrying!  Although, not since I've re-issued the Certificate.

  

Pete

Posted

I'm having similar issues with a Server 2025 NPS. Now thinking it might be a recent update? Will let you know if I find anything or indeed if you find a solution, please share. Thanks

  • Like 1
Posted

Have you checked if the entire certificate chain is valid? Is the root and intermediate installed in the trusted locations?

Posted
20 hours ago, FN-GM said:

Have you checked if the entire certificate chain is valid? Is the root and intermediate installed in the trusted locations?

Yes - the entire chain is valid.  

 

Thanks to @andyfield - that is very interesting about the update and I'm going to visit that now.

 

Pete

Posted

Well, blow me down with a Microsoft Update!  Removing this update has resulted in quieter logs and would appear no issues connecting with the devices I've tested so far. 

 

So, again, thanks @andyfield for the heads up.

 

This is now has me concerned.... was this a flawed update that will be fixed in a later update?  Or is this tightening down of the RADIUS process to push users towards a better/secure method?    Still need to be able to update a server after all!

 

Pete

 

Posted
On 08/01/2026 at 15:10, synaesthesia said:

would that have been related to the update which made 2025 unusable as a DC?

 

Don't believe it is - I'm not touching 2025 as a DC, but every thing else I've upgraded to 2025 without any major issues until this.

 

I know of two other schools that have hit this issue but I'm not really finding much about it as a known issue overall.  Some obscure AI generated response from Google hint at know issues but I can't find anything too concrete.   It did lead me down the rabbit hole that this may be the 'strengthening' of how certificates are presented to the DC but it's not really making much sense and has got me concerned that we may need to come up with another way if this a change by Microsoft and not just a crappy update.

 

Pete

 

Posted

Aye, I've set up our new hyperV host as 2025 as well as a couple of other servers (file server & impero hosts) and they seem OK but I keep seeing these niggles with, as you say, no concrete information to go on!

  • Like 1
Posted

There's some discussion in the patch Tuesday mega thread from last month on Reddit regarding RADIUS issues. Hopefully patch Tuesday tomorrow there might be a fix.

 

 

  • Like 1
  • 1 month later...
Posted

Have been doing my round of updates this half term, and let our NSP/RADIUS server pull down the latest updates (after creating a checkpoint, backup, etc).  I'm pleased to say this issue now seems resolved with the limited testing I've done this morning.  

 

Pete

 

Posted

Have you got any more information on this please? Am just setting up new 2025 NPS Servers, and enabling 802.1X EAP-TLS auth for the wired side for this site, and experiencing issues - but have done this plenty of times over the years in the past, so am sure I've got the config side right.

I am seeing the exact same errors you mentioned.

Posted

I did an upgrade over Christmas which included KB5072033 that borked RADIUS authentication.  Details in my first post.  Completely erratic joining the Wi-Fi using WPA Enterprise.  Some users could connect, but a lot couldn't.  Varied on different APs.  Once I removed that upgrade all was well again.  Just ran through the updates again this half term and updated with the latest offerings and it 'appears' to be working ok; I walked around our site disconnecting and reconnecting my phone with no issues.  But, there is only a handful of staff connecting to this on-site at the moment, and it may go all 'Pete Tong' when all the users come back next week.   I made a point of taking a full backup of the server before doing this process, so will restore back to that if I can't remove the update applied this week.

 

Pete

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...