Forum Discussion
rajeshkhanikar
Dec 11, 2018Brass Contributor
WiFi WPA2 Enterprise seamless sign-on
WPA2 Enterprise setup in intune requires the on-premise domain-joined NDES server and certificate issued by internal CA. WPA2 Enterprise seamless authentication will not work if the device is not joi...
- Mar 11, 2019
Forgot to update this.
Short answer: If the computer is only joined to Azure AD, WPA2 Enterprise seamless authentication is not possible.
As of now (March 2019) it is not possible to have seamless (users are not prompted for authentication) WPA2 Enterprise authentication when the computers (Windows 10) are not joined to an on-premise AD (only joined to Azure AD). This is because winlogon credentials contains a cloud user which will not be allowed to authenticate automatically on RADIUS (radius is using the on-premise AD).
Jenu Jose
Dec 14, 2018Copper Contributor
Ah I see. In that case, NDES should hand out the client certificate to your Azure AD joined computer. And then you will need to make sure the Azure AD joined computer has the root certificate as well. Have you confirmed that NDES is handing out the client certificate and that the root certificate is being deployed to your computers?
Jenu Jose
Dec 14, 2018Copper Contributor
You might also want to follow this thread; sounds like a similar problem to yours.
- rajeshkhanikarJan 04, 2019Brass Contributor
We have registered a case with Microsoft, looks like there are some issues with intune in our tenant. Wifi profiles fails to apply.
- SRoachJan 07, 2019Brass ContributorPlease keep us posted. I'd be interested to know if you make any headway with Microsoft as I have a case open with them for a similar issue on iOS.