Configure EAP-TEAP Authentication for a Windows Device
To secure your network, follow these steps to configure a client device for EAP-TEAP (Tunneled Extensible Authentication Protocol) authentication.
Tunneled Extensible Authentication Protocol (TEAP) is a tunnel-based EAP method that enables secure communication between a peer and a server by using the Transport Layer Security (TLS) protocol to establish a mutually authenticated tunnel. Within the tunnel, TLV objects are used to convey authentication-related data between the EAP peer and the EAP server. (RFC 7170 - Tunnel Extensible Authentication Protocol )
Juniper Mist Access Assurance supports EAP-TEAP with EAP-TLS as the authentication method for both machine and user authentication.
By default, Windows authenticates the machine at startup and does not automatically re-authenticate using user credentials after a user signs in. To enable automatic user authentication, configure Wireless 802.1X Single Sign-On (SSO)—either pre-logon or post-logon—in the Wi-Fi profile through a Group Policy, an MDM, or an XML profile. If SSO is not enabled, user authentication typically occurs only after the wireless connection is manually disconnected and then reconnected. See Single Sign-On profile sample.
Currently TEAP support is available for Windows 10 Version and above.
You can configure wireless and wired profile with TEAP manually or through scripts, which can be distributed using MDM or GPO. Current MDM solutions do not provide out-of-the box support for TEAP configuration.
To configure wireless EAP-TEAP on a Windows device:









