{"id":338,"date":"2024-01-09T15:52:00","date_gmt":"2024-01-09T14:52:00","guid":{"rendered":"https:\/\/networkjon.fr\/blog\/?p=338"},"modified":"2025-01-09T16:07:32","modified_gmt":"2025-01-09T15:07:32","slug":"fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2","status":"publish","type":"post","link":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/","title":{"rendered":"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ?"},"content":{"rendered":"\n<p>Dans cette note d\u2019information, je souhaite vous partager un sujet d\u2019actualit\u00e9 qui peut avoir un impact \u00e0 court terme sur les infrastructures Wi-Fi et filaires 802.1x.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"qu\u2019est-ce-que-credential-guard\">Qu\u2019est-ce que Credential Guard ?<\/h2>\n\n\n\n<p>Windows Defender Credential Guard est une fonctionnalit\u00e9 de s\u00e9curit\u00e9 introduit par Microsoft pour la premi\u00e8re fois sur Windows 10 et Windows 2016 Server. Elle permet de prot\u00e9ger les informations d\u2019identification de domaine. Avant Credential Guard, les identifiants de connexion d\u2019un ordinateur Windows \u00e9taient stock\u00e9es dans la RAM directement. De ce fait, ils \u00e9taient accessibles par n\u2019importe quel utilisateur du poste, qu\u2019il soit administrateur du poste ou non. Avec Credential Guard, ces identifiants sont d\u00e9sormais stock\u00e9s dans un conteneur virtuel s\u00e9curis\u00e9 auquel le syst\u00e8me d\u2019exploitation ne peut pas directement acc\u00e9der. L\u2019int\u00e9r\u00eat de cette fonctionnalit\u00e9 est de s\u00e9curiser l\u2019acc\u00e8s \u00e0 ces donn\u00e9es critiques qui pouvaient auparavant \u00eatre obtenues facilement par un attaquant (via l\u2019utilisation <a href=\"http:\/\/woshub.com\/how-to-get-plain-text-passwords-of-windows-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">d\u2019outil comme Mimikatz<\/a> par exemple). Le sch\u00e9ma ci-dessous illustre le fonctionnement de Credentials Guard et on y voit le conteneur s\u00e9curis\u00e9 dans lequel les identifiants \u00ab\u00a0single sign-on\u00a0\u00bb (les identifiants d\u2019ouverture de session) sont d\u00e9sormais stock\u00e9s :<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"782\" height=\"347\" src=\"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png\" alt=\"\" class=\"wp-image-339\" srcset=\"https:\/\/www.networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png 782w, https:\/\/www.networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1-300x133.png 300w, https:\/\/www.networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1-768x341.png 768w\" sizes=\"auto, (max-width: 782px) 100vw, 782px\" \/><figcaption class=\"wp-element-caption\">Conteneurs Windows<\/figcaption><\/figure>\n<\/div>\n\n\n<p>Microsoft a acc\u00e9l\u00e9r\u00e9 l\u2019adoption de cette fonctionnalit\u00e9. Ainsi, <strong>\u00e0 partir de la version Windows 11 22H2<\/strong> (20 septembre 2022)<strong>, Credential Guard est d\u00e9sormais activ\u00e9 par d\u00e9faut<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Quels probl\u00e8mes Credential Guard pose-t-il pour nos infrastructures 802.1x Wi-Fi et filaire\u00a0?<\/h2>\n\n\n\n<p>Cette fonctionnalit\u00e9 a pour effet de \u00ab\u00a0casser\u00a0\u00bb la connexion automatique des machines Windows en 802.1x lorsqu\u2019elles utilisent une authentification par utilisateur et mot de passe. Plus pr\u00e9cis\u00e9ment, on parle dans ce cas des authentifications en EAP-PEAP MS-CHAPv2 (ou protocoles de s\u00e9curit\u00e9 inf\u00e9rieures) qui utilisent le compte utilisateur ou le compte machine. Apr\u00e8s l\u2019ouverture de session, Credential Guard emp\u00eache Windows d\u2019acc\u00e9der aux identifiants \u00ab\u00a0single sign-on\u00a0\u00bb stock\u00e9s d\u00e9sormais dans le conteneur virtualis\u00e9, <strong>for\u00e7ant ainsi l\u2019utilisateur \u00e0 saisir manuellement son identifiant et mot de passe<\/strong> lorsqu\u2019il souhaite se connecter au r\u00e9seau Wi-Fi (ou filaire) s\u00e9curis\u00e9 par 802.1x.<\/p>\n\n\n\n<p>M\u00eame si EAP-PEAP MS-CHAPv2 n\u2019est pas l\u2019authentification la plus s\u00e9curis\u00e9e qui existe, elle est encore largement utilis\u00e9e dans de nombreux r\u00e9seaux. La g\u00e9n\u00e9ralisation de Credential Guard va donc entrainer des probl\u00e8mes de connexion pour les utilisateurs sur ces r\u00e9seaux.<\/p>\n\n\n\n<p>Notons que les authentifications plus s\u00e9curis\u00e9es comme EAP-TLS (authentification par certificat) ne sont pas affect\u00e9es par l\u2019activation de Credential Guard.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Comment pr\u00e9venir et corriger ce probl\u00e8me\u00a0?<\/h2>\n\n\n\n<p>Avec l\u2019activation par d\u00e9faut de Credential Device \u00e0 partir de la version Windows 11 22H2, la vision de Microsoft est claire\u00a0: il souhaite voir disparaitre les m\u00e9thodes d\u2019authentification moins s\u00e9curis\u00e9es au profit des m\u00e9thodes plus s\u00e9curis\u00e9es comme l\u2019authentification par certificat avec EAP-TLS. D\u2019un point de vue s\u00e9curit\u00e9, la vision de Microsoft est la bonne car EAP-TLS a plusieurs avantages :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>L\u2019authentification par certificat utilisateur est bien plus robuste qu\u2019une authentification par utilisateur\/mot de passe.<\/li>\n\n\n\n<li>Gr\u00e2ce \u00e0 l\u2019utilisation de certificats, les \u00e9quipements autoris\u00e9s \u00e0 se connecter sur un r\u00e9seau sont bien mieux maitris\u00e9s par les administrateurs. En effet, pour les utilisateurs finaux, il est beaucoup plus complexe de partager un certificat plut\u00f4t qu\u2019un couple identifiant\/mot de passe. L\u2019int\u00e9r\u00eat est donc d\u2019\u00e9viter que les utilisateurs puissent connecter n\u2019importe quel type de terminal sur le r\u00e9seau.<\/li>\n\n\n\n<li>EAP-TLS est une m\u00e9thode d\u2019authentification s\u00fbre alors que MS-CHAPv2 est connu pour \u00eatre vuln\u00e9rable \u00e0 certaines attaques.<\/li>\n<\/ul>\n\n\n\n<p>La vision court\/moyen terme est donc de migrer les authentifications EAP-PEAP MS-CHAPv2 vers EAP-TLS. Pr\u00e9cisons que ce type d\u2019authentification n\u00e9cessite l\u2019utilisation d\u2019une PKI (pour g\u00e9n\u00e9rer et g\u00e9rer les certificats utilis\u00e9s lors de l\u2019authentification) et d\u2019un syst\u00e8me de configuration centralis\u00e9 (pour pousser ces certificats sur les terminaux\u00a0; une GPO ou un MDM par exemple). Sur une infrastructure Microsoft, une PKI AD CS (Active Directory Certificate Services) est g\u00e9n\u00e9ralement pr\u00e9conis\u00e9e pour permettre un d\u00e9ploiement plut\u00f4t facile et rapide d\u2019EAP-TLS. Il existe \u00e9galement d&#8217;autres solutions de CA (Certification Authority) h\u00e9berg\u00e9es dans le cloud comme SCEPman ou Microsoft Cloud PKI.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Existe-t-il tout de m\u00eame une solution temporaire pour contourner Credential Guard lorsque l\u2019infrastructure n\u2019est pas pr\u00eate \u00e0 migrer vers EAP-TLS\u00a0?<\/h2>\n\n\n\n<p>Oui, Microsoft a publi\u00e9 <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/security\/identity-protection\/credential-guard\/configure?tabs=intune\" target=\"_blank\" rel=\"noreferrer noopener\">un article pour d\u00e9sactiver Credential Guard<\/a> sur les machines Windows, via deux solutions\u00a0: soit par GPO soit en modifiant quelques cl\u00e9s de registre.<\/p>\n\n\n\n<p>N\u00e9anmoins, la solution \u00e0 court\/moyen terme est de migrer l&#8217;authentification EAP-PEAP MS-CHAPv2 des postes Windows vers EAP-TLS.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>L\u2019activation par d\u00e9faut de Credential Guard sur les derni\u00e8res versions de Windows 11 nous montre clairement la vision de Microsoft sur ce sujet. Plut\u00f4t que de subir les probl\u00e8mes engendr\u00e9s par la d\u00e9pr\u00e9ciation de l\u2019authentification par utilisateur\/mot de passe, nous devons anticiper et migrer les environnements utilisateurs Windows vers de l\u2019authentification EAP-TLS. Ces projets sont \u00e9galement l\u2019occasion d\u2019accroitre la s\u00e9curit\u00e9 de nos infrastructures Wi-Fi et filaires, tout en profitant du d\u00e9ploiement d\u2019une PKI pour \u00e9tendre ces bonnes pratiques de s\u00e9curit\u00e9 au-del\u00e0 des seuls terminaux Windows.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">R\u00e9f\u00e9rences sur le m\u00eame sujet<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Documentation officielle Windows sur Credential Guard : <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/security\/identity-protection\/credential-guard\/credential-guard-how-it-works\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/learn.microsoft.com\/en-us\/windows\/security\/identity-protection\/credential-guard\/credential-guard-how-it-works<\/a><\/li>\n\n\n\n<li>Post sur communaut\u00e9 Cisco : <a href=\"https:\/\/community.cisco.com\/t5\/network-access-control\/windows-11-22h2-credential-guard-enforcement\/td-p\/4695655\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/community.cisco.com\/t5\/network-access-control\/windows-11-22h2-credential-guard-enforcement\/td-p\/4695655<\/a><\/li>\n\n\n\n<li>Article Extreme\u00a0Networks : <a href=\"https:\/\/extremeportal.force.com\/ExtrArticleDetail?an=000100238\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/extremeportal.force.com\/ExtrArticleDetail?an=000100238<\/a><\/li>\n\n\n\n<li>Post sur communaut\u00e9 Reddit : <a href=\"https:\/\/eur01.safelinks.protection.outlook.com\/?url=https:\/\/www.reddit.com\/r\/sysadmin\/comments\/xju508\/windows_11_22h2_credential_guard_default\/&amp;data=05%7c01%7cJonathan.RAMBEAU%40axians.com%7ca7dd5e5fa2894b669a9c08dab1ed929a%7ccae7d06108f340dd80c33c0b8889224a%7c0%7c0%7c638017931159511939%7cUnknown%7cTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7c3000%7c%7c%7c&amp;sdata=KoCTnd%2BpGtDrVoAPuhQQGJzzctqWUzTUmbEdg\/genw4%3D&amp;reserved=0\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.reddit.com\/r\/sysadmin\/comments\/xju508\/windows_11_22h2_credential_guard_default\/<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Dans cette note d\u2019information, je souhaite vous partager un sujet d\u2019actualit\u00e9 qui peut avoir un impact \u00e0 court terme sur les infrastructures Wi-Fi et filaires 802.1x. Qu\u2019est-ce que Credential Guard ? Windows Defender Credential Guard est une fonctionnalit\u00e9 de s\u00e9curit\u00e9 introduit par Microsoft pour la premi\u00e8re fois sur Windows 10 et Windows 2016 Server. Elle [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-338","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ? - Network Jon<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ? - Network Jon\" \/>\n<meta property=\"og:description\" content=\"Dans cette note d\u2019information, je souhaite vous partager un sujet d\u2019actualit\u00e9 qui peut avoir un impact \u00e0 court terme sur les infrastructures Wi-Fi et filaires 802.1x. Qu\u2019est-ce que Credential Guard ? Windows Defender Credential Guard est une fonctionnalit\u00e9 de s\u00e9curit\u00e9 introduit par Microsoft pour la premi\u00e8re fois sur Windows 10 et Windows 2016 Server. Elle [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/\" \/>\n<meta property=\"og:site_name\" content=\"Network Jon\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-09T14:52:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-01-09T15:07:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png\" \/>\n<meta name=\"author\" content=\"Jonathan Rambeau\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jonathan Rambeau\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/\"},\"author\":{\"name\":\"Jonathan Rambeau\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#\/schema\/person\/afb31b920aeee6f10a46f51943c789f3\"},\"headline\":\"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ?\",\"datePublished\":\"2024-01-09T14:52:00+00:00\",\"dateModified\":\"2025-01-09T15:07:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/\"},\"wordCount\":980,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png\",\"articleSection\":[\"Uncategorized\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/\",\"url\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/\",\"name\":\"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ? - Network Jon\",\"isPartOf\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png\",\"datePublished\":\"2024-01-09T14:52:00+00:00\",\"dateModified\":\"2025-01-09T15:07:32+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#primaryimage\",\"url\":\"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png\",\"contentUrl\":\"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.networkjon.fr\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#website\",\"url\":\"https:\/\/www.networkjon.fr\/blog\/\",\"name\":\"Network Jon\",\"description\":\"A blog about Wi-Fi, 802.11, networking and automation... mostly in English... et parfois en Fran\u00e7ais... by Jonathan Rambeau\",\"publisher\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.networkjon.fr\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#organization\",\"name\":\"Network Jon\",\"url\":\"https:\/\/www.networkjon.fr\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.networkjon.fr\/blog\/wp-content\/uploads\/2024\/11\/cropped-logo-networkjon-1-1.jpg\",\"contentUrl\":\"https:\/\/www.networkjon.fr\/blog\/wp-content\/uploads\/2024\/11\/cropped-logo-networkjon-1-1.jpg\",\"width\":1024,\"height\":1024,\"caption\":\"Network Jon\"},\"image\":{\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/jonathan-rambeau-987a58225\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#\/schema\/person\/afb31b920aeee6f10a46f51943c789f3\",\"name\":\"Jonathan Rambeau\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.networkjon.fr\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/88f9b026f1a082206693533f8a10b031ac2c51ee4d5f96a6427b54044b37fbc6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/88f9b026f1a082206693533f8a10b031ac2c51ee4d5f96a6427b54044b37fbc6?s=96&d=mm&r=g\",\"caption\":\"Jonathan Rambeau\"},\"sameAs\":[\"http:\/\/networkjon.fr\/blog\"],\"url\":\"https:\/\/www.networkjon.fr\/blog\/author\/jram\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ? - Network Jon","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/","og_locale":"en_GB","og_type":"article","og_title":"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ? - Network Jon","og_description":"Dans cette note d\u2019information, je souhaite vous partager un sujet d\u2019actualit\u00e9 qui peut avoir un impact \u00e0 court terme sur les infrastructures Wi-Fi et filaires 802.1x. Qu\u2019est-ce que Credential Guard ? Windows Defender Credential Guard est une fonctionnalit\u00e9 de s\u00e9curit\u00e9 introduit par Microsoft pour la premi\u00e8re fois sur Windows 10 et Windows 2016 Server. Elle [&hellip;]","og_url":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/","og_site_name":"Network Jon","article_published_time":"2024-01-09T14:52:00+00:00","article_modified_time":"2025-01-09T15:07:32+00:00","og_image":[{"url":"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png","type":"","width":"","height":""}],"author":"Jonathan Rambeau","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jonathan Rambeau","Estimated reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#article","isPartOf":{"@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/"},"author":{"name":"Jonathan Rambeau","@id":"https:\/\/www.networkjon.fr\/blog\/#\/schema\/person\/afb31b920aeee6f10a46f51943c789f3"},"headline":"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ?","datePublished":"2024-01-09T14:52:00+00:00","dateModified":"2025-01-09T15:07:32+00:00","mainEntityOfPage":{"@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/"},"wordCount":980,"commentCount":0,"publisher":{"@id":"https:\/\/www.networkjon.fr\/blog\/#organization"},"image":{"@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#primaryimage"},"thumbnailUrl":"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png","articleSection":["Uncategorized"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/","url":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/","name":"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ? - Network Jon","isPartOf":{"@id":"https:\/\/www.networkjon.fr\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#primaryimage"},"image":{"@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#primaryimage"},"thumbnailUrl":"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png","datePublished":"2024-01-09T14:52:00+00:00","dateModified":"2025-01-09T15:07:32+00:00","breadcrumb":{"@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#primaryimage","url":"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png","contentUrl":"https:\/\/networkjon.fr\/blog\/wp-content\/uploads\/2025\/01\/content-1.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.networkjon.fr\/blog\/fr-windows-credential-guard-vers-une-disparition-de-eap-peap-mschapv2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.networkjon.fr\/blog\/"},{"@type":"ListItem","position":2,"name":"[FR] Windows Credential Guard : vers une disparition de EAP-PEAP MSCHAPv2 ?"}]},{"@type":"WebSite","@id":"https:\/\/www.networkjon.fr\/blog\/#website","url":"https:\/\/www.networkjon.fr\/blog\/","name":"Network Jon","description":"A blog about Wi-Fi, 802.11, networking and automation... mostly in English... et parfois en Fran\u00e7ais... by Jonathan Rambeau","publisher":{"@id":"https:\/\/www.networkjon.fr\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.networkjon.fr\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.networkjon.fr\/blog\/#organization","name":"Network Jon","url":"https:\/\/www.networkjon.fr\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.networkjon.fr\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.networkjon.fr\/blog\/wp-content\/uploads\/2024\/11\/cropped-logo-networkjon-1-1.jpg","contentUrl":"https:\/\/www.networkjon.fr\/blog\/wp-content\/uploads\/2024\/11\/cropped-logo-networkjon-1-1.jpg","width":1024,"height":1024,"caption":"Network Jon"},"image":{"@id":"https:\/\/www.networkjon.fr\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/in\/jonathan-rambeau-987a58225\/"]},{"@type":"Person","@id":"https:\/\/www.networkjon.fr\/blog\/#\/schema\/person\/afb31b920aeee6f10a46f51943c789f3","name":"Jonathan Rambeau","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.networkjon.fr\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/88f9b026f1a082206693533f8a10b031ac2c51ee4d5f96a6427b54044b37fbc6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/88f9b026f1a082206693533f8a10b031ac2c51ee4d5f96a6427b54044b37fbc6?s=96&d=mm&r=g","caption":"Jonathan Rambeau"},"sameAs":["http:\/\/networkjon.fr\/blog"],"url":"https:\/\/www.networkjon.fr\/blog\/author\/jram\/"}]}},"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/posts\/338","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/comments?post=338"}],"version-history":[{"count":2,"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/posts\/338\/revisions"}],"predecessor-version":[{"id":341,"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/posts\/338\/revisions\/341"}],"wp:attachment":[{"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/media?parent=338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/categories?post=338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.networkjon.fr\/blog\/wp-json\/wp\/v2\/tags?post=338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}