Windows 11 22H2 has discontinued the authentication of my MSCHAPv2 WiFi and wired connections with RADIUS.
Héritier Kandolo, ITIL?
Responsable Infrastructure Informatique chez Castel Afrique | ITIL? | MVP?
This is a heads up - a big problem that is going to affect a huge number of WiFi networks. Windows 11 22H2 enable crendential Guard by default - Which disables MSCHAPv2 by default for SSO. many companies use MSCHAPv2 for authentication to Wifi and Wire Connections.
When you enable Credential Guard, you can no longer use classic NTLM authentication for single sign-on. You'll be required to enter your credentials to use these protocols and won't be able to save credentials for later use.
If you're using Wi-Fi and VPN endpoints based on MS-CHAPv2, they are susceptible to similar attacks as those targeting NTLMv1.
Source : Learn Article Security
微软 Recommends for Wi-Fi and VPN connections, replacing MSCHAPv2 connection (such as PEAP-MSCHAPv2 and EAP-MSCHAPv2) with certificate-based authentication (for example, PEAP-TLS or EAP-TLS).
This is super cool, the solution with EAP-TLS certificate for RADIUS authentication.
On the menu:
And best of all, I can reach my 1 Gbps speed...
Network engineer || IT System || CCNA switching & Routing || MS-365 || Cybersecurity professionnal ll PCI DSS || NSE 3 inprogress || passionate about reading || continuous improvement ||
6 个月Une avancée technologique ??
What a beautiful day!
6 个月Insightful!
Network Eng. || Tech. Sales || Azure || Security Eng. || Cloud Eng. || Technical Cybersec || CompTIA Security+|| MS-365 || CCST Cybersec || CCST Networking || PMP Trainee
6 个月Very insightfull