Windows
Last updated
Last updated
Log in to Microsoft Intune
Navigate to Devices and subsequently Configuration profiles
Then click Create > New policy
As Platform select Windows 10 and later
Search the Profile type templates for Wired network and select it
Click Create and provide a descriptive name and optional Description
fill out the Configuration settings as it suits your environment
Configure the Authentication Method to User if you want to use user-type certificates for authentication or Machine if you would like to use device-type certificates for authentication.
Under 802.1X make sure, that Do not enforce is selected. This way your network adapter will continue to work in environments (e.g. home office), where 802.1X is not available.
For EAP Type choose EAP-TLS
Next, as Certificate server names add the
Subject Alernative Name (SAN)
and Common Name (CN)
of your active RADIUS Server Certificate. Those properties can be found by expanding the active server certificate and copying the relevant values. Please consider, that the common name is case-sensitive.
For the Root certificates for server validation select the Trusted certificate profile you have previously created for the RADIUS Server Certificate.
Under Client Authentication select SCEP certificate as Authentication method
Finally, Client certificate for client authentication (Identity certificate) select the SCEP profile you would like to use for authentication.
All other settings can be configured according to your own needs and preferences.