Windows 11 Credential Guard Update: Impact on EAP-PEAP Network Authentication
By Phil Wightman.
Microsoft has introduced enhanced credential protection in Windows 11 Enterprise and Education through Windows Defender Credential Guard, which is now enabled by default. While this security improvement helps protect user identities, it may impact network authentication for organizations using EAP-PEAP. This article explains who is affected, what the risks are, and the recommended steps to maintain secure and reliable network connectivity.
What Is Credential Guard?
Microsoft Windows operating systems are a critical component in today’s business environment, making security essential for both protection and continuity. Microsoft has introduced enhanced credential protection through Windows Defender Credential Guard, a security feature designed to help protect user credentials from theft and misuse.
Microsoft has recently released enhanced security for domain-joined computers to help keep user credentials safe. This security feature, called Windows Defender Credential Guard, is automatically enabled in Windows 11 Enterprise and Windows 11 Education devices beginning with version 22H2.
Why This Matters.
This new security enhancement will impact the ability for Windows computers to successfully authenticate to your wireless or wired network. Proactive action needs to be taken to ensure you do not lose connectivity to your network after 22H2 is applied.
Organizations using 802.1X network authentication methods such as EAP-PEAP should review their environment before broad deployment of Windows 11 22H2 devices.
Who Is Affected?
You may be affected if your organization uses:
- EAP-PEAP or PEAP-MSCHAPv2 authentication
- Domain-joined Windows 11 Enterprise devices
- Domain-joined Windows 11 Education devices
- Microsoft NPS for RADIUS authentication
- Aruba ClearPass for network access control
- Wired or wireless 802.1X authentication
If these technologies are part of your environment, we recommend reviewing your authentication strategy before broad deployment of Windows 11 22H2 and newer devices.
How Credential Guard Affects Network Authentication.
Because of the security changes introduced by Credential Guard, some authentication methods that rely on user credentials may no longer function as expected. Organizations using EAP-PEAP for wired or wireless network authentication should evaluate their environment before deploying Windows 11 version 22H2 and later.
Recommended Actions
For those affected, to mitigate the issues, you will need to take one of two actions.
Option 1: Migrate to EAP-TLS (Recommended)
Laketec’s recommendation is to migrate your network authentication protocol from EAP-PEAP to EAP-TLS.
Benefits of EAP-TLS:
- Maintains Credential Guard protection
- Uses certificate-based authentication
- Improves security
- No additional Microsoft licensing required
- Already supported by Active Directory and Windows clients
Option 2: Disable Credential Guard
Alternatively, Credential Guard can be disabled as outlined in Microsoft’s documentation below.
How Laketec Can Help.
Laketec can help assess whether your environment is impacted and develop a plan that minimizes risk and disruption.
Our team can assist with:
- Determining whether your environment is affected
- Planning and implementing EAP-TLS authentication
- Reviewing Microsoft NPS policies
- Reviewing Aruba ClearPass configurations
- Validating network authentication before deployment
- Ensuring a smooth transition from EAP-PEAP to EAP-TLS
Our goal is to help organizations maintain secure and reliable network access while taking advantage of Microsoft’s latest security enhancements.
Additional Considerations.
In addition to network authentication, Credential Guard may also impact Remote Desktop connections and other authentication-related services. Be sure to review Microsoft’s documentation and test critical workflows before broad deployment.
Frequently Asked Questions
Does Credential Guard affect Wi-Fi authentication?
It can. Organizations using PEAP-MSCHAPv2-based Wi-Fi authentication may experience authentication issues after Credential Guard is enabled.
Does this affect wired network authentication?
Yes. Both wired and wireless 802.1X authentication deployments may be impacted.
What is the recommended replacement for EAP-PEAP?
Microsoft recommends certificate-based authentication methods such as EAP-TLS or PEAP-TLS.
Do I need additional Microsoft licensing for EAP-TLS?
Most organizations already have the foundational Active Directory and Windows capabilities required to support EAP-TLS authentication.
Additional Resources.
This insight was originally published in 2023.
Ready to Connect?
Contact Us Today
Laketec's culture is built on ownership, integrity and collaboration, shaping how we work with each other and how we deliver lasting results for our clients.
With teams supporting customers across Cleveland, Dayton, Cincinnati, Columbus, Detroit, and surrounding communities, we're close enough to understand your environment and responsive when support matters most.




