Wifi profile PEAP

Killerbe 50 Reputation points
2023-09-14T11:24:59.1333333+00:00

We have a wifi network which is secured with PEAP. We have rolled out the root Cert from our CA, as it is the issuer of the certificate used to protect the PEAP wifi connection.

We created a trusted root certificate configuration profile and applied it to all our android devices. We can see that the configuration is deployed to the majority of our Android clients.

However android devices still fail to connect to the Wifi network.

Then we created a Wifi configuration profile for that network, and pushed this configuration to a test group. The Configuration is not be applied, with error 942518331.

I have checked the OMADMLog files, but i do not find anything useful.

The only thing that is missing, which i think might be the issue is the OCSP. I guess although android has the enterprise root cert deployed, it cannot validate the cert as it fails to retrieve the CRL's (published only in AD). Therefore it fails to validate the CA's cert, and therefore fails to trust the PEAP Certificate.

Still no idea why the wifi configuration profile is failing.

Microsoft Intune Android
Microsoft Intune Android
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Android: An open-source mobile platform based on the Linux kernel, developed by Google, and maintained by the Open Handset Alliance.
266 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Lu Dai-MSFT 28,366 Reputation points
    2023-09-15T02:05:46.0266667+00:00

    @Killerbe Thanks for posting in our Q&A. To clarify this issue, did you add the root certificate to this wifi profile?

    Based on my research, I find that someone has this similar issue.

    https://learn.microsoft.com/en-us/answers/questions/1279976/android-wifi-policy-giving-error-0xc7d24fc5-and-94?page=1#answers

    If this issue still exists, it is needed to check more logs from backend. With Q&A limitation, Q&A is not the good channel for such log analysis case. So, it is suggested to create an online support ticket to get more help. Here is the support link:

    https://docs.microsoft.com/en-us/mem/intune/fundamentals/get-support

    Thanks for your understanding.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Killerbe 50 Reputation points
    2023-09-15T07:03:26.7933333+00:00

    Yes, the root certificate is added in the profile, as well as the DNS name of the NPS server (which is also represented in the certificate of the NPS server).

    0 comments No comments

  3. Killerbe 50 Reputation points
    2023-09-15T07:04:08.67+00:00

    Yes, the root certificate is added in the profile, as well as the DNS name of the NPS server (which is also represented in the certificate of the NPS server).