Hello alemabrahao,
Thanks for your answer. We had the feeling something changed.
Do you know where we can find detailed documentation about the changes?
What we do not understand is:
UpN in our EntraID are in the format name.surname@company.com
Our SCEP certificate CN is name.surname
The certificate Identity in Meraki is set to CN.
Since yesterday, in the Session logs we started seeing lots of failing clients showing in the "Username" column name.surname@domain.com
A very small percentage of clients instead still connects successfully, and they show as username only name.surname (Which is what we would expect, given our certificate configuration, and what used to work until today).
This sounds like Meraki is not constantly sourcing the CN from the certificates anymore, but rather is often passing the email, which contains the domain too.
Even more strange, the emails should exactly match our UpNs, but the authentication fails (code 23).
We are testing with a new certificate containing more alternate names populated with UpN and email, I will report back if we find a working configuration.