Hey there. Interesting predicament, and just wondering if anyone else has experienced this and how you managed a workaround.
We have a RADIUS network that we encourage all users to log into using their OneLogin/AD credentials. However, we do not domain-join our macOS machines, therefore their OneLogin/AD password isn't reset until after they log into their MacBook, navigate to OneLogin, enter their first time "onboarding password," and are then prompted to reset it. Obviously they cannot do this from the RADIUS network, so all first time users are temporarily on a simple password protected WPA2 network. However, this just adds another unnecessary (and confusing) step for new employees on their first day --- "forget" the WPA2 network and sign into the RADIUS network with their new OneLogin/AD password.
Annoying, right? Anyone else experience this less-than-ideal flow before? Anyone have any brilliant solutions or workarounds?