Windows 11 EAP-TEAP "Action Needed" to Sign in

Shrimpy 0 Reputation points
2025-06-25T16:15:55.2466667+00:00

Main Issue: 

Using EAP-TEAP GPO (Windows Server 2022) for Windows 11 devices, clients are able to use the machine cert to auth with no issues. Once the user logs into windows, the user gets a notification that "Network Action needed'. That action basically requires you to navigate to settings > Network & Internet > Ethernet > Click the Sign on button. Once you do that, windows prompt for a pin (because it's using your external smart card user cert). Once the pin is good, the device is able to do all the stuff and things and is happily connected to the network using the machine/user cert. The big deal is that action of 'action needed' and requiring users to auth to the network instead of it just prompting for a pin. This happens with both wired and wireless. Pics will be attached of the prompt and where the sign in button is located. 

 

However, when we did this with a windows 10 machine, the user logs into windows, and after a minute they just get a pin prompt, then they are able to connect to the network (using EAP-TEAP machine&user cert)

 

I can't figure out how to make this action prompt go away and just connect without having the user to do the whole settings, ethernet, click sign in. I just want a pin prompt and connect. 

 

Main GPO Setting details:

Computer configuration > Policies > Windows Settings > Security Settings > Wired Network 

Using IEEE 802.1x auth for network access

Netowrk Auth Method: 'EAP TEAP'

Auth mode: 'User or Computer auth'

     Inner Method: Primary Auth

    EAP-TLS (smartcard or other certificate)

Use my smart card

use simple cert selection (from PKI root ca)

certificate must contain Smart Card Logon 

Validate ISE Server cert with our dc ca cert

Inner Method: Secondary Auth

    EAP-TLS (smartcard or other certificate)

Use a cert on this compute

use simple cert selection 

Cert must be issues by our dc02 cert (EKU all purpose and client auth)

Validate ISE Server cert with our dc ca cert

Advanced Settings:

Enforce advanced 802.1x settings

transmit per IEEE 802.1x

Enable Single Sign On for this network

Perform immediately before User logon 

 

***There is also a wireless GPO and pretty much is the same as wired just has the BSSID and always connect to this network 

 

Machine cert is issued from Active Directory We are using a physical smart card that has 4 certs, 1 is for user smart card login. does require a pin Login to windows/workstation requires to have a smart card, using that same cert i want to user for 802.1x eap-teap.

 

Workstation is a Windows 11 version 23H2 Domian is a windows server 2022, that's where the GPO was configured.  I've seen things about credential guard, making sure the CA certs are selected, I've tried with and without the trusted server FQDN (with case matching). I saw something about win10 vs 10 eap-teap profile .xml sha hash, but to me that's with trusted the radius server and that's not an issue. Everything works, cert auto select works, just i have to sign in to the network each time through that prompt and going into settings, ethernet sign in. and for some reason any command with netsh does not run. could be some policy issue but i do see our computers complete eap-teap in ISE of course after i do the whole prompt sign in process. 

also, the ISE cert and is from our local CA, it's selected and trusted. the smart card cert if from a different public CA, that's trusted on ISE. Again, it works, just getting that prompt

image

image

Thanks for your time, I'll try to keep update things i have done as well as any possible suggestions i receive. 

Windows for business | Windows Client for IT Pros | User experience | Other

3 answers

Sort by: Newest
  1. shabeeb kunhipocker 0 Reputation points
    2026-09-20T17:54:25.05+00:00

    I am facing issue with the same setup. I want to use computer authentication (using the machine certificate) and user authentication (using smart card). What should I choose in the Primary EAP method and Secondary EAP method?. I selected smart card in the primary eap method and "use certificate on this computer" in the secondary eap method. But the authentication is failing. Anyone managed to get it working?.

    Was this answer helpful?

    0 comments No comments

  2. Alain IKULA 0 Reputation points
    2026-03-05T19:42:20.21+00:00

    I had the same issue. It was resolved by selecting all the CAs in the certificate chain of RADIUS server, including the root CA

    Was this answer helpful?

    0 comments No comments

  3. Chen Tran 13,190 Reputation points Independent Advisor
    2025-06-27T10:28:12.8266667+00:00

    Hello,

    Thank you for posting question on Microsoft Windows Forum.
    
    Based on your query of Windows 11 users being required to manually navigate to network settings and click "Sign on" to authenticate for network access using EAP-TEAP, despite having the correct Group Policy settings that work for Windows 10 (which only prompts for a PIN) and expectation to eliminate the manual step and have Windows 11 automatically prompt for the PIN.
    

    The differences between Windows 10 and 11 behavior suggest that there might be a change in how network authentication is handled post-login. You can try the following suggestions for this issue.

    **1.**Single Sign-On (SSO) Configuration

    • Adjust Single Sign-On (SSO) Timing:
    1. Current Setting: "Perform immediately before User logon"
    2. Change to: "Perform immediately after User logon"
    3. This might better suit the scenario where the user is already logged in and the network authentication can use the user's credentials (smart card) without requiring manual sign-in.

    2.Enable "Maximize Compatibility" for SSO:

    • Check the box for "Maximize compatibility for Single Sign On" in the same Advanced Settings menu.

    **3.**Check for Windows Updates:

    • Ensure that the Windows 11 devices are fully updated, especially with the latest cumulative updates which might address known issues with EAP-TEAP.

    **4.**Temporarily Disable Credential Guard for (testing purpose):

    • To test if Credential Guard is the issue, you can disable it temporarily by setting the Group Policy by navigating to following path.
    • Computer Configuration > Administrative Templates > System > Device Guard > Turn On Virtualization Based Security > Disabled.
    • Reboot and test.

    **5.**Using Event Viewer for Diagnostics:

    • Check the Event Viewer on the Windows 11 machine for any related errors in:
    • Applications and Services Logs > Microsoft > Windows > Wired-AutoConfig > Operational
    • Applications and Services Logs > Microsoft > Windows > WLAN-AutoConfig > Operational
    • Look for events that indicate why the authentication is failing to trigger automatic.

    You can refer to below article for more information about what changes in Windows 11 for EAP.

    Hope the above information is helpful!

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.