Understanding 802.1X configuration / modes for Mac Flashcards
Understanding 802.1X configurations/modes for Mac
You can use WPA/WPA2/WPA3 Enterprise authentication at the login window of macOS,
so that the user logs in to authenticate to the network. The macOS Setup Assistant also
supports 802.1X authentication with user name and password credentials using TTLS or PEAP.
For more information, see the Apple Support article Use Login Window Mode for 802.1X authentication to a network
The types of 802.1X configurations are: 1 of 5 (4 configs one Note)
User Mode: This mode, the simplest to configure, is used when a user joins the network from the Wi-Fi menu and authenticates when prompted. The user must accept the RADIUS server’s X.509 certificate and trust for the Wi-Fi connection.
The types of 802.1X configurations are: 2 of 5 (4 configs one Note)
System Mode: System Mode is used for computer authentication. Authentication using System mode occurs before a user logs in to the computer. System Mode is commonly configured to provide authentication with the computer’s X.509 certificate (EAP-TLS) issued by a local certificate authority.
The types of 802.1X configurations are: 3 of 5 (4 configs one Note)
System+User Mode: A System+User configuration is often part of a one-to-one
deployment where the computer is authenticated with its X.509 certificate (EAP-TLS). After the user is logged in to the computer, they can join the Wi-Fi network from the Wi-Fi menu and enter their credentials. User credentials might be a user name and passphrase (EAP-PEAP, EAP-TTLS) or a user certificate (EAP-TLS). After the user has connected to the network, their credentials are stored in the login keychain and used to join the network on future connections.
The types of 802.1X configurations are: 4 of 5 (4 configs one Note)
Login Window Mode: This mode is used when the computer is bound to an on-premise local directory service such as Active Directory. When Login Window
Mode is configured and a user enters their user name and passphrase at the login window, the user is authenticated to the computer and then to the network using 802.1X authentication. Login Window Mode passes the user name and password
credentials only when the Login Window first appears. If the Mac goes to sleep and the WLAN controller idle session time expires, a Mac configured only with Login Window Mode must be restarted or the user must log out. The user can then enter
their user name and password again.
The types of 802.1X configurations are: 5 of 5 (4 configs one Note)
Note: System Mode, System+User Mode (required for the System Mode configuration), and
Login Window Mode require configuration by an MDM solution. Configure the Network payload
settings with the desired Wi-Fi network settings, and apply in-scope to a device or device group
for System Mode.