Need some assistance with 802.1x authentication, AD password change and NoMAD

nachiket_s
New Contributor III

Hi 

We have 802.1x authentication for the MacBooks using PulseSecure Agents. We are also using NoMAD to sync AD passwords on local system, and I am facing following challenge and need some guidance for the same.

We have WIFI configuration profile pushed through JAMF on new devices. post enrollment. The profile installation is done manually by user  as we want use to input the AD credentials and avoid using a common pre shared key for the SSID authentication

When user tries to connect to a specific SSID, first they receive authentication prompt for the WIFI ( unless the existing working credentials are stored during profile installation). Once they are connected to SSID, user receive the authentication prompt from the NAC agent and they get connected once the compliance checks are passed.

Problem: Recently we have started facing challenges on some MacBooks where the Use changes AD password ( password renewal after expiry or some other issue) and then the user is unable to connect back. The workaround for this is to remove the saved SSID from the settings and try to reconnect and users receives the authentication prompt again and get connected with new password.

I would like to know if there is any way we can pick up the new password / kerberos token since NoMAD is already in place or is there a better way to handle this scenario.

0 REPLIES 0