FragglePete Posted January 6 Posted January 6 Hi all, bit of a bind trying to figure this issue out since this morning. We have a NPS server running on Server 2025 which authenticates our BYOD users via our Cambium Wi-Fi Network and this has been running without any issues for the past few years since it was setup and configured by Redway Networks. I only need to renew the GoDaddy certificate installed on it every year, update the config with the New Cert and then it hums along quite happily. The system as a whole works well and have been really happy with it - nearly 100 APs dotted around the site. Mid morning today, we get reports of BYOD Users, Students and Staff not being able to connect to the Wi-Fi using their AD Credentials. Sure enough, my own mobile once I disconnect and try reconnecting won't play ball. Event logs are showing Quote 'An error occurred during the Network Policy Server use of the Extensible Authentication Protocol (EAP). Check EAP log files for EAP errors.' - Reason Code: 23. Nothing has changed on the config, but some guides point to re-issuing the certificate may help. So, I re-key the server certificate and get the new certificate installed and apply this to the NPS Server (Protected EAP Constraints) and it does appear to resolve the issue..... or so I thought. My phone, being an Android connects quite happily and so do others, but iPhones do NOT. Also notice my Intune Laptop running Windows 11 also refuses to connect to the BYOD network with my credentials. Needless to say, our Sixth Form students are getting impatient of not having Wi-Fi but I'm not sure what to do next? EAPHost log shows errors: Quote Skipping: Unable to add EAP Method. Friendly name not present. I fear my Google Fu is leading me down all sorts of rabbit holes, and wondering if something that Microsoft and Apple have 'switched off' at a specific point that now refuses to work with these devices? (eg. Should be set up with EAP-TLS and not just EAP??? But, don't want to jump to conclusions on that one just yet). Appreciate any help to get resolved quickly to stop my phone ringing. TIA Pete
FragglePete Posted January 6 Author Posted January 6 Just to add - digging deeper, also noticing an error: Quote The Extensible Authenication Protocol service terminated unexpectedly. It has done this 4 time(s). Might be more of a server issue as a whole which is a little worrying! Although, not since I've re-issued the Certificate. Pete
andyfield Posted January 7 Posted January 7 I'm having similar issues with a Server 2025 NPS. Now thinking it might be a recent update? Will let you know if I find anything or indeed if you find a solution, please share. Thanks 1
FN-GM Posted January 7 Posted January 7 Have you checked if the entire certificate chain is valid? Is the root and intermediate installed in the trusted locations?
andyfield Posted January 7 Posted January 7 I've currently removed KB5072033 and monitoring. Currently haven't seen the same errors on the logs 1
FragglePete Posted January 8 Author Posted January 8 20 hours ago, FN-GM said: Have you checked if the entire certificate chain is valid? Is the root and intermediate installed in the trusted locations? Yes - the entire chain is valid. Thanks to @andyfield - that is very interesting about the update and I'm going to visit that now. Pete
FragglePete Posted January 8 Author Posted January 8 Well, blow me down with a Microsoft Update! Removing this update has resulted in quieter logs and would appear no issues connecting with the devices I've tested so far. So, again, thanks @andyfield for the heads up. This is now has me concerned.... was this a flawed update that will be fixed in a later update? Or is this tightening down of the RADIUS process to push users towards a better/secure method? Still need to be able to update a server after all! Pete
synaesthesia Posted January 8 Posted January 8 would that have been related to the update which made 2025 unusable as a DC?
FragglePete Posted January 12 Author Posted January 12 On 08/01/2026 at 15:10, synaesthesia said: would that have been related to the update which made 2025 unusable as a DC? Don't believe it is - I'm not touching 2025 as a DC, but every thing else I've upgraded to 2025 without any major issues until this. I know of two other schools that have hit this issue but I'm not really finding much about it as a known issue overall. Some obscure AI generated response from Google hint at know issues but I can't find anything too concrete. It did lead me down the rabbit hole that this may be the 'strengthening' of how certificates are presented to the DC but it's not really making much sense and has got me concerned that we may need to come up with another way if this a change by Microsoft and not just a crappy update. Pete
synaesthesia Posted January 12 Posted January 12 Aye, I've set up our new hyperV host as 2025 as well as a couple of other servers (file server & impero hosts) and they seem OK but I keep seeing these niggles with, as you say, no concrete information to go on! 1
Noxid_w Posted January 12 Posted January 12 There's some discussion in the patch Tuesday mega thread from last month on Reddit regarding RADIUS issues. Hopefully patch Tuesday tomorrow there might be a fix. 1
FragglePete Posted February 17 Author Posted February 17 Have been doing my round of updates this half term, and let our NSP/RADIUS server pull down the latest updates (after creating a checkpoint, backup, etc). I'm pleased to say this issue now seems resolved with the limited testing I've done this morning. Pete
StephenPink Posted February 18 Posted February 18 Have you got any more information on this please? Am just setting up new 2025 NPS Servers, and enabling 802.1X EAP-TLS auth for the wired side for this site, and experiencing issues - but have done this plenty of times over the years in the past, so am sure I've got the config side right. I am seeing the exact same errors you mentioned.
FragglePete Posted February 18 Author Posted February 18 I did an upgrade over Christmas which included KB5072033 that borked RADIUS authentication. Details in my first post. Completely erratic joining the Wi-Fi using WPA Enterprise. Some users could connect, but a lot couldn't. Varied on different APs. Once I removed that upgrade all was well again. Just ran through the updates again this half term and updated with the latest offerings and it 'appears' to be working ok; I walked around our site disconnecting and reconnecting my phone with no issues. But, there is only a handful of staff connecting to this on-site at the moment, and it may go all 'Pete Tong' when all the users come back next week. I made a point of taking a full backup of the server before doing this process, so will restore back to that if I can't remove the update applied this week. Pete
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now