Skip to main content
mradhika22
Staff
Staff
April 7, 2025

Troubleshooting Tip: Windows 11 version 22H2 devices failed to connect to SSIDs with WPA2-PEAP authentication

  • April 7, 2025
  • 0 replies
  • 1518 views
Description This article describes a scenario where Windows 11 22H2 client devices fail to connect to SSIDs with MSCHAPv2-based authentication (like PEAP-MSCHAPv2 and EAP-MSCHAPv2).
Scope FortiAP (all versions), Windows 11 22H2.
Solution

Description:

  • As Windows 10 is approaching the End of Life, more client devices are upgraded or migrated to Windows 11.
  • Credential Guard is On/enabled by default in Windows 11 22H2 models and breaks PEAP authentication on enterprise WiFi SSID.
  • New 22H2 uses TLS 1.3 for EAP authentication, whereas this was TLS 1.2 in previous versions.

 

More details on Credential Guard are in the link below:

How Credential Guard works 

 

Resolution : 
For the Windows 11 22H2 client devices to connect to the WPA2-PEAP SSID, the Credential Guard needs to be disabled.

If Credential Guard needs to be enabled for security reasons, then certificate authentication (like PEAP-TLS or EAP-TLS)

needs to be implemented.

 

Related document:
Known issues

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!