Hello all,
For this setup, there are 2 SSIDs (Guest and internal) being deployed to 7 sites in the US. I have a setup where the Internal SSID is using EMM/Meraki SM Sentry enrollment and enforcing on iOS and Android devices (we use a separate product for OS X and Windows), authentication is through an on site Windows Radius server and Active Directory accounts. All is well for new users or people when they first join the wifi. The AD password policy is fairly aggressive where passwords are changed every 90 days. Users are of course prompted to change their password on their Windows PC (Email or etc.) but they are not prompted on their mobile device to change the password and, if left unchanged, will lock their AD account and disrupt their PC, Email, etc. temporarily (15 minute reset) continually until the device is updated. So I'm trying to find a solution to either automate updating the saved credentials on the mobile device, implement some kind of notification system so the users get a notification that they need to change it, or force the device off the wifi so that they will need to re-enter the wifi settings and not lock their account out. Right now I have an Windows Event log forward that lets me know what account is being locked out, but won't provide the device name (if it's empty, we assume it's an iOS, Android, or Blackberry device) but some users have one or multiple iPads, iPhones, or personal Android devices so narrowing down the device can be difficult at time.
Thanks for your help!
Jason J.