802.1X Windows EAP-TLS

GPO deployment, auto-enrollment

Category

SECURITY

Status

Active

Premise

Seamless certificate-based auth for Windows

Goals

  • Certificate auto-enrollment via AD CS or Vault

  • GPO-deployed wired/wireless profiles

  • Computer + user authentication

Current State

Testing with manual certificate deployment

Next Steps

  • Configure GPO for 802.1X profiles

  • Test Vault PKI integration with certreq

Architecture Notes

GPO → Cert Store → NativeSupplicant → ISE