Wireless 802.1x with minimum auth infrastructure on MR

Solved
RichardChen1
Getting noticed

Wireless 802.1x with minimum auth infrastructure on MR

Current state: MR33 with psk. All corp computers are enrolled with Microsoft Intune with SCEP.

 

New requirement: How can we make this so that staff can move around the offices freely and not have to remember or enter a password for a registered device?

 

Questions: 

- Can Meraki talk to Intune directly? I can't find any info, mostly likely not?

- Radius server is a must?

- Is "Trusted acess" a solution that can scale not only on mobile but also windows computers?

 

Any suggestion is appreciated.

 

Thanks in advance.

1 Accepted Solution
PhilipDAth
Kind of a big deal
Kind of a big deal

Microsoft makes this quite a complicated setup.

 

You have to must have an on-premise certificate server, and have Intune issue certificates from that using NDES.  You then need an on-premise NPS server, and you perform authentication against that using RADIUS.

 

A RADIUS server is a must.

 

 

Trusted Access does not support Windows to the best of my knowledge.

 

 

View solution in original post

3 Replies 3
PhilipDAth
Kind of a big deal
Kind of a big deal

Microsoft makes this quite a complicated setup.

 

You have to must have an on-premise certificate server, and have Intune issue certificates from that using NDES.  You then need an on-premise NPS server, and you perform authentication against that using RADIUS.

 

A RADIUS server is a must.

 

 

Trusted Access does not support Windows to the best of my knowledge.

 

 

RichardChen1
Getting noticed

I thought so. Thanks for your feedback. 

ITzhak
Getting noticed

Hi Richard,

Did you get this working? 
I'm trying to do this with Jamf as the MDM to connect to the Meraki Wireless using Microsoft SCEP

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels