CSP Policy - Authentication/AllowEAPCertSSO

Tomas Koukal 1 Reputation point
2020-11-29T18:25:24.483+00:00

Hello,

I am implementing Windows 10 native VPN (ikev2) with cert-based authentication to on-premise (gw is fortigate)

When VPN connects, it will add *Session cert-based credentials to Credential Manager, so it is trying to enforce this type of authentication also for on-premise resources.

But some resources support only NTLM (SSO) - Only option how to disable of enforcing cert-based authentication for on-premise resources and be able to authenticate via NTLM is registry key MACHINE\System\CurrentControlSet\Control\Lsa\DisableDomainCreds which disable Credential Manager from caching credentials.

I also found CSP Policy Authentication/AllowEAPCertSSO which should do what I need but it has no effect.

Does anybody know more information about the purpose of this policy ?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,921 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.