Windows - EAP-PEAP Configuration
Configure Windows devices to connect securely to IronWifi WPA-Enterprise wireless networks using EAP-PEAP authentication. This widely supported method protects username and password credentials within an encrypted TLS tunnel, providing strong security for Windows environments.
Overview
EAP-PEAP is a widely supported authentication method that creates a secure TLS tunnel to protect user credentials. Windows 7 and later versions include built-in support for EAP-PEAP.
Prerequisites
- Windows 7, 8, 10, or 11
- Valid IronWifi user credentials (username and password)
- Wireless network configured with WPA2-Enterprise
Configuration Steps
Windows 10/11
- Click the Wi-Fi icon in the system tray
- Select your enterprise wireless network
- Click Connect
- When prompted for credentials:
- Username: Your IronWifi username (usually email address)
- Password: Your IronWifi password
- If prompted about the server certificate, click Connect to accept
Advanced Configuration
For more control over the connection settings:
- Open Settings > Network & Internet > Wi-Fi
- Click Manage known networks
- Click Add a new network
- Enter the following settings:
- Network name: Your SSID
- Security type: WPA2-Enterprise
- EAP method: PEAP
- Authentication method: EAP-MSCHAPv2
Certificate Validation
For enhanced security, configure certificate validation:
- Open Control Panel > Network and Sharing Center
- Click Set up a new connection or network
- Select Manually connect to a wireless network
- Configure the network and click Next
- Click Change connection settings
- Go to the Security tab
- Click Settings next to the EAP type
- Check Verify the server's identity by validating the certificate
- Select Trusted Root Certification Authorities
Group Policy Deployment
For enterprise deployment via Group Policy:
Computer Configuration > Policies > Windows Settings > Security Settings > Wireless Network (IEEE 802.11) Policies
Create a new policy with:
- SSID: Your network name
- Authentication: WPA2-Enterprise
- Encryption: AES
- EAP type: Microsoft: Protected EAP (PEAP)
Troubleshooting
Connection Fails
- Verify your username and password are correct
- Ensure the wireless network is within range
- Check that your account is active in the IronWifi console
Certificate Errors
If you receive certificate warnings:
- The server certificate may not be trusted
- Contact your administrator to verify the RADIUS server certificate
- Temporarily disable certificate validation to test (not recommended for production)
Cannot See Network
- Ensure the SSID is being broadcast
- Verify your wireless adapter supports WPA2-Enterprise
- Update wireless adapter drivers
Related Topics
- Windows - EAP-TLS - Certificate-based authentication
- Windows - TTLS + PAP - Alternative authentication method
- Azure AD Authentication - SSO integration