Network disconnected while RDP login on Windows 11

Jero Cheng 140 Reputation points
2023-03-29T02:20:16.2733333+00:00

Dear all

My domain environment contain Windows 10 and 11 laptops. ADMX are updated to 22h2 and the GPO on both Windows 10/11 are same. NIC setting are same.

On our LAN network we have Cisco ISE for 802.1x Authentication and method is MSCHAPv2.

2023-03-29 09_06_00-Window

2023-03-29 09_06_08-Window

2023-03-29 09_06_12-Window

2023-03-29 09_06_18-Window

2023-03-29 09_06_24-Window

I Google for the solution and I found that the new feature in Windows 11 "Credential Guard " break the MSCHAPv2.

https://github.com/MicrosoftDocs/windows-itpro-docs/blob/public/windows/security/identity-protection/credential-guard/credential-guard-known-issues.md

I follow the instruction from MS ,disable the whole "Virtualization-Based Security" in Windows level and BIOS level and I confirm the "Credential Guard " is not running.Event viewer didn't show any "Credential Guard " event after "Virtualization-Based Security" disabled.

But problem didn't solve.

I do some test flow like below:
Physically login a laptop>ISE pass,network connected>RDP from another computer>insert password >show login screen for 1-2 seconds >disconnected.

And then I found that the laptop is totally disconnected from network, I need to physically login the laptop again ,wait for the authentication then network connected.

But after I test the flow many times, sometime its works! RDP successfully,just sometime......it make me headache.

And,if the laptop connects with Wifi or LAN (without ISE) ,the RDP is working fine.

Anyone having the same problem like me?Is there any solution if we stay with MSCHAPv2 password authentication?

Thanks everyone.

Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,573 questions
Windows Network
Windows Network
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.Network: A group of devices that communicate either wirelessly or via a physical connection.
759 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
9,724 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. risolis 8,721 Reputation points
    2023-03-29T03:04:25.6566667+00:00

    Hello @Jero Cheng

    Thank you for posting this concern on this community space.

    I have read your whole case scenario description and I cannot deny that you really did a huge troubleshooting on this so, I just wanted to share my 2 cents on this by sharing the following links down below:

    https://community.cisco.com/t5/network-access-control/the-windows-user-remotes-into-a-workstation-with-rds-remote/td-p/4020395

    https://www.reddit.com/r/networking/comments/lim1ne/ise_8021x_and_rdp/

    I hope that works for you.

    Looking forward to your feedback,

    Cheers,

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.