cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
618
Views
3
Helpful
4
Replies

ISE TEAP - Combine User and Computer Authentication Win10 CredGuard

Nils 86
Level 1
Level 1

hi, 

i am searching for a way to combine computer certificate (eap-tls) and user authentication (mschapv2) in one session. with EAP-TEAP this should be possible, but i have a problem with the user authentication. if the windows 10 feature credential guard is active the username/password cant be used for the mschapv2 part. is this right or a misunderstanding or has anyone a solution for this problem?

i hope any one can help me

best regards nils

1 Accepted Solution

Accepted Solutions

No my understanding is Credential Guard prevents the account credentials from being used directly across the OS.  Certificate based auth methods are much preferred.

View solution in original post

4 Replies 4

This is correct.  Why not use user certificates instead?  You can also disable credential guard.

hi, completely disabling credential guard is not a good idea becaus of security reasons.

if the user certificate is the only other option, i will try it! thank you

are there any other option with the cisco secure client NAM Module? 

regards Nils

No my understanding is Credential Guard prevents the account credentials from being used directly across the OS.  Certificate based auth methods are much preferred.

In my opinion TEAP would be a better option comparing to AnyConnect NAM because it is native and doesn't require any additional licenses.