We've been caught out by a recent change in Android 11 which means Android phones can no longer connect to our WPA2-Enterprise SSID using the user's AD username and password. We use Microsoft NPS as our RADIUS server and this is an internal server on an internal domain having a certificate supplied by our internal AD Certificate Services PKI infrastructure.
We understand that the change that has been made is such that Android can no longer use the "Do not validate" setting, but we find that even if we install our AD CS CA certificate on an affected Android 11 device, it is still unable to connect.
It has been suggested that we can resolve the issue by obtaining an externally trusted certificate for our NPS server, but this would not appear to be possible as it does not have an external IP address and is not located on an externally valid domain / does not have an externally valid FQDN.
I realise this is not strictly a Meraki issue but I did see that other users in this forum had posted threads in relation to NPS, if anyone could point me in the right direction that would be really helpful.
Thanks,
Dan Jackson (Senior ITServices Technician)
Long Road Sixth Form College
Cambridge, UK.