Meraki updated Access Manager documentation on October 14, 2025, introducing refinements to identity mapping and certificate-based authentication (EAP-TLS) with Entra ID integration. Key changes include: Stricter identity reconciliation between the client certificate and the user identity stored in Meraki’s local database (synced from Entra ID). Certificate validation logic now checks for: Matching identity attributes (e.g., username, UPN, device name). Valid certificate chain (no duplicates, disabled signers). Presence of synchronized user attributes from Entra ID. This means that if the certificate subject or SAN does not match the expected identity format or if there's a mismatch with Entra ID records, authentication may fail, even if the certificate is technically valid. Access Manager - Cisco Meraki Documentation
... View more