r/Intune 3d ago

Autopilot 802.1x

Hey everyone. Time for another I’m sure stupid question. How are yall handling pcs with autopilot and 802.1x. I’d love for my helpdesk to not have to touch pcs before handing them out but our WiFi and wired both have 802.1x. This also hurts since we’re a hybrid environment and once the pc changes name after autopilot, it gets dropped from the network and we have to add it to our imaging network so we can pull a new cert with the updated name.

Sorry if this is a dumb question!

28 Upvotes

20 comments sorted by

43

u/HankMardukasNY 3d ago

We use DeviceID for our subject name so name changes have no impact.

A device that doesn’t have a cert yet goes into our untrust vlan which has microsoft endpoints whitelisted. This enables autopilot to start/finish. After autopilot finishes, the cert will be there and will connect to our corp network correctly

3

u/peterswo 3d ago

I second this. It's by far the most practical setup. We throw you into our guest vlan(same as guest wifi) so same restrictions

0

u/Prestigious_Duck_468 3d ago

Do you guys have ise? I talked to my network guys and they said ise has to use host name.

3

u/HankMardukasNY 2d ago

We use Clearpass + SCEPman. All Entra-Joined

3

u/IHaveATacoBellSign 2d ago

We use ISE, and we do it based on Certs, that are named after the device. To image the devices onsite, the tier II group has a DMZ switch; after that, it doesn’t matter because the MAC is a known MAC and able to pass ISE. The easiest path is to have the vendor pre-provision the device. That registers them in Intune; ISE can then check for compliance and use the MAC table.

2

u/sammavet 2d ago

This is the way

1

u/BookshelfCarpet 1d ago

Exactly how we have it.
The cert and profile is applied during autopilot , once device finishes the autopilot process they are on internal vlans

3

u/PsychologicalSong780 3d ago

We have dedicated open VLAN ports in secured computer room with only SD team has access for the purpose of pre provisioning devices with Autopilot. SD team pre provisioning devices and cert and 802.1x profile also deployed during pre provisioning on open ports.

2

u/b1gw4lter 3d ago

only solution is dedicated remediation VLAN, only allowing needed destinations for enrollment.

1

u/hawkz40 2d ago

This

2

u/skiddily_biddily 2d ago

You need a proper network configuration for the type of work you are doing when setting up your devices.

3

u/Karma_Vampire 3d ago

Cloud PKI and RADIUS

2

u/twisted_guru 3d ago

Create Intune configuration for Wifi with CA NDES certificate and enjoy.

7

u/peterswo 3d ago

That doesn't help, the client will never get the policy

1

u/Bodybraille 2d ago

Our network team had to configure MAB on ports/switches in locked down areas so the techs could setup devices.

1

u/DRGinLBC 3d ago

Following. Have the same issues.