FortiAP
FortiAP devices are thin wireless access points (AP) supporting the latest Wi-Fi technologies (multi-user MIMO 802.11ac Wave 1 and Wave 2, 4x4), as well as 802.11n, 802.11AX , and the demand for plug and play deployment.
mradhika22
Staff
Staff
Article Id 386577
Description This article describes a scenario where Windows 11 22H2 client devices fail to connect to SSIDs with MSCHAPv2-based authentication (like PEAP-MSCHAPv2 and EAP-MSCHAPv2).
Scope FortiAP (all versions), Windows 11 22H2.
Solution

Description:

  • As Windows 10 is approaching the End of Life, more client devices are upgraded or migrated to Windows 11.
  • Credential Guard is On/enabled by default in Windows 11 22H2 models and breaks PEAP authentication on enterprise WiFi SSID.
  • New 22H2 uses TLS 1.3 for EAP authentication, whereas this was TLS 1.2 in previous versions.

 

More details on Credential Guard are in the link below:

How Credential Guard works 

 

Resolution : 
For the Windows 11 22H2 client devices to connect to the WPA2-PEAP SSID, the Credential Guard needs to be disabled.

If Credential Guard needs to be enabled for security reasons, then certificate authentication (like PEAP-TLS or EAP-TLS)

needs to be implemented.

 

Related document:
Known issues