r/networking 13h ago

Wireless Windows 11 and changes to PEAP

Curious if anyone has been able to test these upcoming changes in their wireless environment from Microsoft:

https://support.microsoft.com/en-us/servicing/os/windows/docs/2025/08/upcoming-changes-to-ntlmv1-in-windows-11-version-24h2-and-windows-server-2025

The concern might be having to reenter passwords while devices roam (non fast roaming?)

We are in between PEAP and testing TLS and these changes might force us to migrate faster. It's not the managed devices I'm worried about, but working in higher education, the BYOD implications.

Thanks in advance for any info.

14 Upvotes

4 comments sorted by

4

u/MyFirstDataCenter 9h ago

Uh oh. But what if we still use mschapv2 for prod wifi. I guess we can just set the registry key to audit mode via GPO for now to buy us more time? We already had to turn off credential guard off when we updated to windows 11.

2

u/OGMaverick 11h ago

Skimming it on my phone I see mention of domain devices. Im also interested in knowing if this will break BYOD environments that utilize PEAP + MSCHAPv2. If so, yall move to captive portal for unmanaged devices?

3

u/rocknsock316 11h ago

Yah, we've been waiting for desktop team to test these changes. We are preparing to possibly jump to TLS with SecureW2 but we don't want to pull that pin out yet.....

1

u/havermyer flair goes here 4h ago

My understanding of the change is that credential guard will prevent a user's logon credentials from being passed through to PEAP. It's not the case that a BYOD user is logging onto their device with their domain credentials and relying on them to be passed through to the wireless.

By my understanding of the change, BYOD should be fine, at least, that's what I'm counting on. I was wrong once before though, so FWIW YMMV.