Categories
802.1x Active Directory Cisco ISE

Enable Wired 802.1x – Group Policy

In my lab environment I have a ‘Lab Users’ OU that I will apply this group policy to.

Open Group Policy Management and right click the ‘Lab Users’ Group, select ‘Create GPO in this domain, and Link it here…’.

Create new GPO
Create new GPO

Give it a name, e.g. ‘802.1x Group Policy’, and then navigate to ‘Computer Configuration -> Policies -> Windows Settings -> Security Settings -> System Services’ and enable the ‘Wired AutoConfig’ service. Without enabling the ‘Wired AutoConfig’ service it will not be possible to configure 802.1x on wired interfaces.

Wired AutoConfig
Wired AutoConfig

Next browse to ‘Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Wired Network’ and create a policy called ‘Wired 802.1x’ policy.

Wired 802.1x Policy
Wired 802.1x Policy

On the ‘Security’ tab select ‘Smart Card or tother certificate’ , ‘user or computer authentication’, and ensure ‘Max Authentication Failures’ is set to 3 (this fixes a ‘user logging into a machine for the first time so no certificate exists’ scenario).

Wired 802.1x Settings
Wired 802.1x Settings

Leave a Reply

Your email address will not be published. Required fields are marked *